PlatformSecurity checks

A security check, after every deploy.

Right after a deploy goes live, Antideploy looks at the running app for the mistakes that leak data: a key shipped to the browser, a downloadable .env file, a wide-open CORS policy. It never holds the deploy up, it costs nothing, and your agent is told what it found and how to fix it.

Read the API contract
  • Every deployAn automatic check right after it goes live
  • FreeNo charge for the automatic check or for a full scan
  • SecondsA scan is a handful of requests, not a long job
  • Facts, not guessesDeterministic rules, so a finding is a fact

01How it works

Checked automatically. Fixed with your agent.

The mistakes that break into AI-built apps are specific and common. The checks target those, and each finding says how to fix it.

Automatic, and it never holds you up.

When a deploy goes live, a light check reads what the app already shows the public: its pages, its scripts, well-known file paths and headers. The result is in the deploy status your agent already reads. If it says scanning, your agent asks again a few seconds later. If it found something, each issue comes with a recommendation.

  • It never calls your app's endpoints, so nothing that sends an email or changes data can fire on every deploy
  • Redeploying checks again
  • Findings arrive with a severity, a plain explanation and a fix
See the deploy status
A finding, abridged
"security": {
  "status": "completed",
  "issues": [
    {
      "severity": "high",
      "title": "A Stripe secret key is shipped to the browser",
      "detail": "...",
      "recommendation": "Move it to the server and rotate the key"
    }
  ]
}

A full scan, whenever you ask.

A full scan does everything the automatic check does and also tests your endpoints: data handed out without a login, and SQL injection. Start one from the console's Security page, or have your agent start one and poll until it completes. It runs in seconds and is free.

  • Each finding has a severity, an explanation and how to fix it
  • Fix each at its root, then scan again to confirm it is gone
  • A scan fails loudly if the app cannot be reached, instead of reporting no issues
See the Agent API
Your agent runs
$ API=https://antideploy.com/api/v1

# start a full scan of the live app
$ curl -X POST "$API/security/scans" \
    -H "Authorization: Bearer $TOKEN" \
    -H "Content-Type: application/json" \
    -d '{"applicationId":"'"$APP_ID"'"}'

# poll the watch address until it says completed or failed
$ curl "$API/security/scans/$SCAN_ID" \
    -H "Authorization: Bearer $TOKEN"
POST /api/v1/security/scansGET /api/v1/security/scans/{id}

02What you get

The checks that catch the common leaks.

They target the specific ways AI-built apps get broken into, and every rule is deterministic, so a finding is a fact and not a guess.

  • Keys shipped to the browser. Looks for OpenAI, Anthropic, OpenRouter, Stripe live, AWS, GitHub and Slack keys, and private keys, in the scripts and pages your app serves. Firebase and Maps keys, which are meant to sit in the browser, are recognised and left alone.
  • Files that should never download. A .env, .env.local, .env.production, .git folder or .npmrc that anyone can fetch from your address.
  • Endpoints open without a login. In a full scan, endpoints that hand out data such as a list of users or email addresses to anyone who asks, and a probe for SQL injection with one harmless quote.
  • CORS and headers. A wide-open CORS policy and missing security headers, in both the automatic check and a full scan.
  • Every finding says how to fix it. Each has a severity, a plain-language explanation and a recommendation, so your agent can fix it at the root and scan again.
  • Your agent is told. The result is part of the deploy status, so your agent reports what was found and offers to fix it without you asking.

03Reference

What each check looks for.

The automatic check runs the first three. A full scan runs all five.

CheckWhat it looks for
Keys in the browser codeOpenAI, Anthropic, OpenRouter, Google, AWS, Stripe live, GitHub and Slack keys, and private keys, in the scripts and pages your app serves.
Exposed filesA downloadable .env, .env.local, .env.production, .git folder or .npmrc.
CORS and headersA wide-open CORS policy and missing security headers.
Data open without a loginEndpoints that hand out data, such as users or email addresses, to anyone. Full scan only.
SQL injectionDatabase errors in answer to one harmless quote. Full scan only.

04Before you commit

Here's where it stops.

A platform that only tells you what it is good at is one you find the edges of in production. These are the security checks'.

  1. Not a penetration test

    The checks are deterministic rules over your app's public surface. We deliberately do not attempt deep exploitation, and a clean result is not a guarantee.

  2. The automatic check never calls your endpoints

    So nothing that sends an email or changes data can fire on every deploy. Endpoint tests are in the full scan, which you ask for.

  3. An unreachable app is never reported clean

    If the app cannot be reached when a scan starts, the scan fails and says so, instead of reporting that nothing was found.

  4. It reports, it does not rewrite

    Every finding has a recommendation and your agent can apply it, but Antideploy never edits your project.

05Questions

Security questions, answered.

Anything else? Write to us and a person answers.

support@antideploy.com
Does it cost anything?

No. The automatic check after every deploy and a full scan on demand are free, on every plan.

Does it slow my deploy down?

No. It starts after your app is live and never holds the deploy up. If the result is still scanning when your agent first looks, it asks again a few seconds later.

What does the automatic check look at?

Only what your app already shows the public: its pages, its scripts, well-known file paths and headers. It looks for keys shipped to the browser, files such as .env that anyone can download, and CORS and header problems.

What is the difference between the automatic check and a full scan?

A full scan also tests your endpoints for data handed out without a login, and for SQL injection. The automatic check never calls your endpoints, because an endpoint that does something when loaded would then fire on every deploy.

How do I run a full scan?

From the Security page in the console, or have your agent call POST /api/v1/security/scans with your application's id and poll the result until it is completed.

What happens if it finds something?

The deploy status lists the issues, each with a severity, an explanation and a recommendation. Your agent tells you and offers to fix them, and redeploying checks again.

Does it use AI?

No. The rules are deterministic, so the same app gets the same answer and a finding is a fact.

Is this a replacement for a penetration test?

No. It catches the common, expensive mistakes quickly and for free. It does not try deep exploitation, so it complements a review and does not replace one.

Can a scan break my app?

It is built not to. A scan makes a handful of requests with capped sizes and short timeouts. A full scan adds one harmless quote as its injection probe.

Does Antideploy check for anything else?

Yes. Static sites are checked for phishing pages before they go live, and crypto miners, remote desktops and remote shells are refused when a project is analysed. See hosting.

+The rest of the platform

Everything else your app can use.

Every service is created by your coding agent, wired into your app, and included in the plans. See the whole platform.

Facts on this page were checked against the live platform on 5 October 2026.

Ship it. We will check it.

Paste the sentence into your agent, click Approve once, and every deploy is checked from the first one.

Start from GitHub or a folder
Prompt copied Paste it into Claude Code, Codex or Cursor and press Enter.