01
You choose the source
Upload a ZIP or import a selected repository through the read-only GitHub review flow.
Trust and privacy
Before Users runs a bounded static review of your ZIP or read-only GitHub repository to identify launch risks before real users touch the product.
Scan boundaries
01
Upload a ZIP or import a selected repository through the read-only GitHub review flow.
02
The review reads file paths, bounded text files, package manifests, lockfiles, and configuration signals.
03
Uploaded or imported code is not executed, imported, installed, or used to run package-manager commands.
04
Findings are organized into a temporary report with masked evidence, launch blockers, warnings, and hardening suggestions.
Storage model
The service stores only the limited scan details needed for account ownership, usage limits, and operational review. Long-term raw project contents are not required to generate the current report.
Data boundaries
The review model is designed around temporary processing, masked evidence, and sanitized report data.
GitHub permissions
GitHub import lets you review a selected repository without granting permission to change code during the import flow.
Review coverage
The review focuses on launch-blocking and launch-adjacent risks that commonly appear in AI-built SaaS projects.
Looks for committed env files, private keys, service-role keys, database URLs, and provider tokens with masked evidence.
Flags routes where IDs, destructive methods, admin areas, or ownership checks may need server-side verification.
Reviews service-role exposure, RLS signals, broad grants, permissive policies, and storage hints.
Checks secret-key exposure, webhook verification patterns, client-trusted payment inputs, and subscription update signals.
Looks for wildcard CORS, debug flags, source-map exposure, and missing security-header posture.
Reviews lockfiles, broad versions, install scripts, package risk signals, and deterministic advisory matches.
Uses static rules for patterns like dynamic code execution, unsafe redirects, client-side role checks, and permissive APIs.
Limitations
A static pre-launch review can reduce obvious launch risk, but it cannot prove complete security or replace deeper review for sensitive systems.
Report safety
Reports are designed to be useful for teammates without turning findings into a new disclosure risk.
Responsible use
The product is built for founders, builders, and teams reviewing their own pre-launch applications. Do not upload third-party code or private repositories unless you have explicit permission to review them.
Ready when you are
You stay in control: review the findings, read the evidence, and decide what to fix before launch.