Security

Security scan

What every deploy is checked for, and what a failed check means.

Every deploy is scanned in two parts. Fixed rules run first and give the same answer every time. Then an AI review looks for problems rules cannot see. The rules are the floor: the AI review can add issues, but never clear one.

1. Fixed rules

Run during the build, in about 2 seconds, before the app goes live.

CheckWhat it findsSeverity
Keys in codeAPI keys, tokens and passwords written into any file.Blocking
Outside domainsEvery website the code calls, compared with your workspace's allowed domains.Blocking for a domain not on the list
Vulnerable packagesPackages in package.json with known security problems, checked against the OSV database.Blocking for high or critical, warning otherwise

2. AI review

A few seconds after the app is live, an AI model reviews the source code (with secret values removed) together with the rule results and your policies. It looks for:

  • data that is not filtered by the signed-in user, so every viewer sees every row
  • customer data sent to third parties, including AI APIs
  • SQL injection, eval and unsafe HTML rendering
  • exports and deletes with no limit or confirmation
  • keys hidden in ways rules miss, such as split strings or base64
  • the app building its own login instead of using getUser()

High-confidence findings are blocking. The rest are warnings, so a wrong guess never blocks a team. A redeploy only reviews files that changed.

What a failed scan means

A failed scan does not stop the deploy. The app goes live for its Owner and the people already added, so you can keep working. Until every blocking issue on the live version is fixed:

Only the live version's latest scan counts. Issues from older versions no longer block anything once a clean version is live.

Warnings never block anything.

Scan statuses

StatusMeaning
passNo issues.
warnOnly warnings.
failAt least one blocking issue.
pending_aiRules are done, the AI review is still running.

If the AI review cannot run, the scan falls back to the rule results and marks the AI review as not run.

Where to see results

  • Your AI tool gets the result straight away from deploy_app, with a fix prompt for each issue.
  • The Security card on the app's page shows the result. Editors, the Owner and admins choose Open review to see each issue with its file, line, evidence (secret values hidden) and the fixes available.
  • Admins see every failing app that is shared in the security queue.

When the scan runs again

Every deploy is scanned. When an admin allows a domain from a request, the scan also re-runs on its own for every app waiting on it, so you do not need to redeploy.