Product
Scanner Reports AI Integration
Resources
Guides Research Security checklist Docs Status
Account
Sign in Scan your app free
Home/About
About

A free security scanner for apps built with AI.

Epherem reads your app’s code and shows you the security mistakes AI coding tools tend to leave behind. It’s free, and it tells you plainly what it couldn’t check.

Why it exists

Tools like Lovable, Bolt, Cursor and Replit let people ship real apps without a background in security. Researchers who have studied apps built this way keep finding the same few mistakes: one user able to see or change another user’s data, secret keys reachable from the browser, databases left open, and user input trusted when it shouldn’t be. These are ordinary web-security mistakes, not exotic AI ones. Read the review of the studies.

Most security tools assume a security engineer will read the results. Epherem is written for the person who built the app, in plain words.

What it does

You upload a ZIP of your project, or connect GitHub and pick a repository. Epherem runs 55 checks written for the mistakes AI-built apps tend to make (who can see and change data, keys and secrets, input handling, configuration) and looks up packages with exact versions (from a lockfile) in the public OSV advisory database. A scan takes from a few seconds to a few minutes, and stops at 5 minutes.

Your report shows everything those checks find: the file and line, a short excerpt of the code, what someone could do, a suggested fix, and a prompt for your AI tool. Only published advisories for the package versions you use are shown as known issues. Code findings come in two groups: likely issues, where the scanner saw the risky code itself, and findings that need checking, where it looked for a protection and didn’t see it, or the match depends on context it can’t see. Start with the likely issues.

Epherem is free during early access. You can run up to 5 scans a day.

Who runs it

Epherem is built and run by Kirtik, one person in Singapore. It isn’t a company. If something in a report looks wrong, email support@epherem.com and I’ll read it.

What it promises, and what it doesn’t

Honesty about limits

No scanner can show that an app is secure, and Epherem never says a scan is complete. It reads your code. It doesn’t test your live site or see settings in dashboards such as Supabase’s. Every report names what the scan couldn’t check, and anything it didn’t analyse is never reported as clean.

What happens to your code

Your uploaded code is used only to run the scan and is deleted afterwards. Your report stays in your account until you delete it. Your code is not sent to any AI provider; only package names and versions go to OSV.dev to look up advisories.

Contact

Questions, feedback or a problem with a report: support@epherem.com.

See it on your own app

Upload a ZIP or connect GitHub. It’s free. A scan takes from a few seconds to a few minutes, and stops at 5 minutes.

Scan your app free