The app changed.
Does the work
still work?
For your side project, your business, or the apps you build for clients. Works with configured journeys on Lovable, Bolt, v0, Replit, Base44, and agent-built apps. Run the journeys the business depends on in a real browser, after each change.

The saved note survives a reload. See this step, its receipt, and the other four journeys. ↗
Three reports worth opening.
One real client-style app and two labelled demo states. Each tells you what ran, what happened, and what remains unknown.
QuickNotes.
Five journeys passed.
Real Lovable app · recorded 8 September 2026. Five configured journeys passed. Dashboard isolation only; live policies were not inspected.
Read the report ↗CONTROLLED DEFECTThe booking leaked.
One journey stopped.
Demo app with a deliberately introduced booking leak. Real browser receipts show the second customer seeing another customer’s booking. Audit findings are fixtures.
Inspect the failure ↗DEMO APP · FIXTURE AUDITFinding. Repair.
A later passing run.
Demo app · fixture audit. SQL was prepared, not applied. The later run disabled the demo defect; it does not prove a database repair.
Follow the repair trail ↗Open the recorded run.
QuickNotes · 8 September 2026, 11:39 UTC. Interactive report from a completed run; not live app status.
The updated run checks a saved note after reload and rejects a fresh sign-in after account deletion. The isolation journey checks user B’s dashboard; it does not directly request user A’s record. Live database policies were not inspected, and rejected sign-in does not by itself verify data erasure.
What runs on your stack.
| Built with | Browser journeys | Access audit & repair |
|---|---|---|
| Lovable / Bolt on your Supabase, v0 + Supabase, agent-built Supabase apps | Supported | Live policies, anonymous probe, exposed keys, migration and PR. |
| Lovable Cloud | Supported | Committed migrations and anonymous probe. No management token; live coverage is limited. |
| Replit, Base44, Firebase, Convex, Prisma on Postgres | Configured sign-in journeys | Not in this version. Reported as not audited, not zero findings. |
The source report names stack detection limits. Repository fingerprints do not establish deployed stack or ownership. Ask for Journeys setup documentation ↗
Measured against known defects.
Detection tests, not customer incidence rates. Each controlled defect stops the journey that depends on it.
| Controlled defect | What goes wrong | Journey that catches it |
|---|---|---|
| cancel-keeps-access | “Plan cancelled” appears; the session stays active. | Cancel and lose dashboard access · step 9. |
| bookings-leak | The dashboard lists every customer’s bookings. | Another customer cannot see the booking · step 6. |
| booking-not-saved | Booking redirects without storing the booking. | Make a booking and find it in the list · step 9. |
| none | The working fixture app. | 5 of 5 passed. |
One person. One idea.
More than welcome.
You don’t need a team or a client list to belong here. Start with the thing you’re building.
Free
A welcoming first step for individual builders. Get to know Antelier before deciding whether you need more.
Signup design preview · hosted accounts are not available yet.
Room to grow.
Optional paid plans will be shaped around useful extras for individuals and teams. Pricing and included usage are still being worked out.
No paid subscription is available today.
Prefer working from your terminal? Use the free CLI →