# A security check, after every deploy.

URL: https://antideploy.com/platform/security-checks

Right after a deploy goes live, Antideploy looks at the running app for the mistakes that leak data: a key shipped to the browser, a downloadable .env file, a wide-open CORS policy. It never holds the deploy up, it costs nothing, and your agent is told what it found and how to fix it.

## At a glance

- **Every deploy**: An automatic check right after it goes live
- **Free**: No charge for the automatic check or for a full scan
- **Seconds**: A scan is a handful of requests, not a long job
- **Facts, not guesses**: Deterministic rules, so a finding is a fact

## Checked automatically. Fixed with your agent.

The mistakes that break into AI-built apps are specific and common. The checks target those, and each finding says how to fix it.

### Automatic, and it never holds you up.

When a deploy goes live, a light check reads what the app already shows the public: its pages, its scripts, well-known file paths and headers. The result is in the deploy status your agent already reads. If it says scanning, your agent asks again a few seconds later. If it found something, each issue comes with a recommendation.

- It never calls your app's endpoints, so nothing that sends an email or changes data can fire on every deploy
- Redeploying checks again
- Findings arrive with a severity, a plain explanation and a fix

[See the deploy status](https://antideploy.com/platform/deployments)

**A finding, abridged**

```
"security": {
  "status": "completed",
  "issues": [
    {
      "severity": "high",
      "title": "A Stripe secret key is shipped to the browser",
      "detail": "...",
      "recommendation": "Move it to the server and rotate the key"
    }
  ]
}
```

### A full scan, whenever you ask.

A full scan does everything the automatic check does and also tests your endpoints: data handed out without a login, and SQL injection. Start one from the console's Security page, or have your agent start one and poll until it completes. It runs in seconds and is free.

- Each finding has a severity, an explanation and how to fix it
- Fix each at its root, then scan again to confirm it is gone
- A scan fails loudly if the app cannot be reached, instead of reporting no issues

[See the Agent API](https://antideploy.com/platform/agent-api)

**Your agent runs**

```bash
API=https://antideploy.com/api/v1

# start a full scan of the live app
curl -X POST "$API/security/scans" \
    -H "Authorization: Bearer $TOKEN" \
    -H "Content-Type: application/json" \
    -d '{"applicationId":"'"$APP_ID"'"}'

# poll the watch address until it says completed or failed
curl "$API/security/scans/$SCAN_ID" \
    -H "Authorization: Bearer $TOKEN"
```

Related: `POST /api/v1/security/scans`, `GET /api/v1/security/scans/{id}`

## The checks that catch the common leaks.

They target the specific ways AI-built apps get broken into, and every rule is deterministic, so a finding is a fact and not a guess.

- **Keys shipped to the browser.** Looks for OpenAI, Anthropic, OpenRouter, Stripe live, AWS, GitHub and Slack keys, and private keys, in the scripts and pages your app serves. Firebase and Maps keys, which are meant to sit in the browser, are recognised and left alone.
- **Files that should never download.** A `.env`, `.env.local`, `.env.production`, `.git` folder or `.npmrc` that anyone can fetch from your address.
- **Endpoints open without a login.** In a full scan, endpoints that hand out data such as a list of users or email addresses to anyone who asks, and a probe for SQL injection with one harmless quote.
- **CORS and headers.** A wide-open CORS policy and missing security headers, in both the automatic check and a full scan.
- **Every finding says how to fix it.** Each has a severity, a plain-language explanation and a recommendation, so your agent can fix it at the root and scan again.
- **Your agent is told.** The result is part of the deploy status, so your agent reports what was found and offers to fix it without you asking.

## What each check looks for.

The automatic check runs the first three. A full scan runs all five.

| Check | What it looks for |
| --- | --- |
| Keys in the browser code | OpenAI, Anthropic, OpenRouter, Google, AWS, Stripe live, GitHub and Slack keys, and private keys, in the scripts and pages your app serves. |
| Exposed files | A downloadable `.env`, `.env.local`, `.env.production`, `.git` folder or `.npmrc`. |
| CORS and headers | A wide-open CORS policy and missing security headers. |
| Data open without a login | Endpoints that hand out data, such as users or email addresses, to anyone. Full scan only. |
| SQL injection | Database errors in answer to one harmless quote. Full scan only. |

## Here's where it stops.

A platform that only tells you what it is good at is one you find the edges of in production. These are the security checks'.

### Not a penetration test

The checks are deterministic rules over your app's public surface. We deliberately do not attempt deep exploitation, and a clean result is not a guarantee.

### The automatic check never calls your endpoints

So nothing that sends an email or changes data can fire on every deploy. Endpoint tests are in the full scan, which you ask for.

### An unreachable app is never reported clean

If the app cannot be reached when a scan starts, the scan fails and says so, instead of reporting that nothing was found.

### It reports, it does not rewrite

Every finding has a recommendation and your agent can apply it, but Antideploy never edits your project.

## Security questions, answered.

Anything else? Write to us and a person answers.

[support@antideploy.com](mailto:support@antideploy.com)

### Does it cost anything?

No. The automatic check after every deploy and a full scan on demand are free, on every plan.

### Does it slow my deploy down?

No. It starts after your app is live and never holds the deploy up. If the result is still scanning when your agent first looks, it asks again a few seconds later.

### What does the automatic check look at?

Only what your app already shows the public: its pages, its scripts, well-known file paths and headers. It looks for keys shipped to the browser, files such as `.env` that anyone can download, and CORS and header problems.

### What is the difference between the automatic check and a full scan?

A full scan also tests your endpoints for data handed out without a login, and for SQL injection. The automatic check never calls your endpoints, because an endpoint that does something when loaded would then fire on every deploy.

### How do I run a full scan?

From the Security page in the console, or have your agent call `POST /api/v1/security/scans` with your application's id and poll the result until it is completed.

### What happens if it finds something?

The deploy status lists the issues, each with a severity, an explanation and a recommendation. Your agent tells you and offers to fix them, and redeploying checks again.

### Does it use AI?

No. The rules are deterministic, so the same app gets the same answer and a finding is a fact.

### Is this a replacement for a penetration test?

No. It catches the common, expensive mistakes quickly and for free. It does not try deep exploitation, so it complements a review and does not replace one.

### Can a scan break my app?

It is built not to. A scan makes a handful of requests with capped sizes and short timeouts. A full scan adds one harmless quote as its injection probe.

### Does Antideploy check for anything else?

Yes. Static sites are checked for phishing pages before they go live, and crypto miners, remote desktops and remote shells are refused when a project is analysed. See [hosting](https://antideploy.com/platform/hosting).

## Everything else your app can use.

Every service is created by your coding agent, wired into your app, and included in the plans. [See the whole platform](https://antideploy.com/platform).

- [Hosting](https://antideploy.com/platform/hosting)
- [Static sites](https://antideploy.com/platform/static-sites)
- [Deployments](https://antideploy.com/platform/deployments)
- [Database](https://antideploy.com/platform/database)
- [Authentication](https://antideploy.com/platform/authentication)
- [File storage](https://antideploy.com/platform/file-storage)
- [Email](https://antideploy.com/platform/email)
- [AI models](https://antideploy.com/platform/ai-models)
- [Cron jobs](https://antideploy.com/platform/cron-jobs)
- [Custom domains](https://antideploy.com/platform/custom-domains)
- [Environment variables](https://antideploy.com/platform/environment-variables)
- [Logs and monitoring](https://antideploy.com/platform/logs-and-monitoring)
- [Console](https://antideploy.com/platform/console)
- [Agent API](https://antideploy.com/platform/agent-api)

Facts on this page were checked against the live platform on 5 October 2026.

## Ship it. We will check it.

Paste the sentence into your agent, click Approve once, and every deploy is checked from the first one.

To set this up, give your coding agent this sentence:

```text
Set this project up to deploy on Antideploy. Fetch https://antideploy.com/agent.md and follow it.
```
