hooldurmanaged opsFree audit →

The AI-staffed IT department for vibe-coded apps

Keep building.
We’ll keep it running.

You shipped a real app with AI - and now real people depend on it. Hooldur audits what you built and tells you the truth about it - read-only, on the accounts you already own - then asks one question: what should your IT department take off your plate next?

Start the free audit →See a sample reportFree · read-only · no migration, ever
01

You bring a live app

Built with Claude Code, Cursor, or Lovable. Real users, or about to have them.

02

Connect, read-only

GitHub, Supabase, and your domain. We only ever read - nothing changes, ever.

03

Your crew scans it

Reads the code like a staff engineer - secrets, access rules, backups, costs.

04

Plain-English report

Graded worst-thing-first. “A stranger can read your users today,” not jargon.

05

Fix it, run it again

Every finding ends in a fix and an effort estimate. Audit daily until it's clean.

The front door · free, instant

An audit that tells you the truth

Eleven checks on the things that actually burn vibe-coded apps, graded by what could happen to you - not by jargon. Worst thing first, and every finding ends in a fix.

hooldur.com/audit/leadloop/reportSample report
F

Production readiness · leadloop.app

4 critical · 2 high · 3 medium

Do not leave as-is

The one thing to know

Right now, anyone who opens your site can read every row of your customer table - names, emails, and the notes your users typed - straight from the browser. No login required.

Critical

Your database has no access rules

Two tables (profiles, orders) are wide open - the public key in your app can read and write them. This is how the Lovable data leaks happened.

→ Turn on row-level security, scope every table to its owner

~2 hrs
Critical

A secret key is shipped to every visitor

Your Stripe secret is bundled into the front-end JavaScript (…4a2f). Anyone can read it in devtools and charge on your account.

→ Move the call server-side, rotate the key today

~1 hr
High

No backups you could restore from

Point-in-time recovery is off. One bad edit - including one an AI makes - and the data is gone, like the “it deleted my 200 entries” stories.

→ Enable PITR, add a nightly export, test a restore

~30 min
Free · read-only · no card

The checklist

The eleven things that actually burn these apps

Not a 400-line linter dump. Every check exists because it has already cost a builder like you their data, their users, or their weekend - and the report says plainly when one could not run.

  • 01

    Secrets committed to the repo and its history

    The API key you deleted last month is still in the history.

  • 02

    Secrets that ship to the browser

    Keys bundled into front-end JavaScript, readable in devtools.

  • 03

    Database access rules

    Missing or inverted row-level security - the classic data leak.

  • 04

    Whether your backend checks who is calling

    Public write access, open endpoints, auth that trusts the browser.

  • 05

    Injection and unsafe handling of user input

    The string a stranger types becoming a query you never wrote.

  • 06

    Backups and whether you could recover

    Could you actually restore if an AI edit wiped a table?

  • 07

    Known vulnerabilities in your dependencies

    Known CVEs and dangerously outdated packages.

  • 08

    Whether you would know if it went down

    Would you find out from an alert, or from an angry user?

  • 09

    Deploy configuration and what your errors reveal

    Debug mode in production, stack traces shown to strangers.

  • 10

    Your domain, its certificate and how it is served

    Expiring certificates, missing HTTPS, absent security headers.

  • 11

    What a stranger could run up on your bill

    The unmetered endpoint that turns into a $3,000 bill.

Why Hooldur

We operate your app where it lives

You already escaped one walled garden. You should not have to migrate into another one just to sleep at night.

vs. hosting platforms

Not a “migrate to our cloud”

Every rival wants your app on their AWS, their platform, their framework. Hooldur operates it where it already lives, on accounts you own. Fire us any day - nothing moves, nothing breaks.

vs. dashboards

Not another monitoring tab

Software alone can't be accountable. Our agents already do the audit work, and the operated tiers we're building - patching, incident response, backup verification - will ship with a named human behind an escalation guarantee.

vs. agencies

Not a $15K rescue quote

Human rescue agencies start at $15K and a discovery call. Hooldur starts with a free audit - no quotes, no calls - and everything we build after it is priced for builders, not enterprises.

Scoped accountability, stated up front. When Hooldur takes the watch, we are accountable for configuration, security, response, and recovery - not for Vercel's or Supabase's uptime. The promise is simple: you will never face an incident alone, and misconfiguration is on us.

Pricing

The audit is free. What comes next is up to you.

The paid tiers are not live yet - they are the question we ask everyone who runs a free audit: which of these would you pay for? Your answer decides what we build first.

The audit

live now

Free · no card

The whole product, today. Audit your app every day.

  • Eleven read-only checks on your code, database and domain
  • A letter grade, worst thing first
  • Every finding in plain English, with a fix and an effort estimate
  • What we could not check, stated honestly
  • A fresh audit every day to confirm fixes landed
Coming soon

Guardrails

self-serve

We watch, you act.

  • Audits on a schedule, without asking
  • Uptime & error monitoring
  • Plain-English alerts with a proposed fix

Operated

the service

The AI IT department proper.

  • Dependency patching with deploy-and-verify
  • Incident response & backup verification
  • Approval gates on every mutating change
  • Human escalation guarantee

No prices on purpose. The audit ends by asking what you would pay for - that is the research.

Questions

The things people ask first