All work

02 · SaaS product · 2026

LeftUnlocked

Left Unlocked scans apps built with AI tools like Lovable, Bolt and v0, and explains in plain language what was left open and how to close it. No sign-up, no jargon, read-only. I planned, designed, wrote and built the whole product, from the first page to payments.

Client
My own product
Field
App security
Year
2026
Role
Product, design, development and copy
Stack
Server-rendered HTML, framework-free JavaScript, Railway, Cloudflare
Live site
leftunlocked.com
leftunlocked.com

16

read-only checks in every scan

301

scans in the last 30 days

5

guides, one per tool

100

in all four Lighthouse categories on desktop

01The challenge

AI tools like Lovable and Bolt let anyone put an app online in an afternoon. Security doesn’t come with them: tables open to the whole world, paid API keys sitting in the browser, and sites without basic security headers.

Existing tools talk to security people: long reports, jargon and severity scores. Whoever built the app needs to know at a glance whether something is open, and exactly what to paste to close it.

02The approach

  1. 01

    The scan is on the homepage

    One field and one button, above the fold. No feature tour and no sign-up before the first scan. You can get a result without going through any other screen first.

    What I didn’t doA classic landing page: hero, features, pricing, and only then sign-up.

  2. 02

    What the scanner does, right by the button

    Next to the button it says plainly: read-only, nothing is written, no user data is read. A separate page explains what the bot does, its limits and how to block it.

    What I didn’t doA legal checkbox nobody reads.

  3. 03

    Plain explanations and ready-made fixes

    Every finding follows the same order: the evidence, why it matters, how to fix it, and a paste-ready fix for the tool the app was built with: a prompt for Lovable, SQL for Supabase, config for Vercel, Netlify and Nginx.

    What I didn’t doA list of findings with CVE codes and links to docs.

  4. 04

    No framework

    No framework: HTML built on the server, a few small hand-written JavaScript modules, and fonts with tuned fallbacks so the page doesn’t jump when they load.

    What I didn’t doA full React app for one field and a button.

03The solution

leftunlocked.com
Left Unlocked homepage
Homepage: one field, one button, and a one-line promise.
Homepage on mobile
On mobile the scan stays the first thing on screen.
leftunlocked.com
Sample scan report
Sample report: a grade, a summary by severity, and for each finding an explanation and a paste-ready fix.
Scan report on mobile
The report on mobile.
leftunlocked.com
Pricing page
Pricing: free to check, a few dollars a month to keep it checked.
leftunlocked.com
Lovable security guide
A guide for each tool: the five things that go wrong, and how to fix them.

04Behind the design

Paper#F7F8F6
Ink#12181C
Slate#5A6B72
"Alive" green#0B775E
Soft green#E3F3ED
Critical#C6362F

Instrument Sans 700 · Headings and buttons

Your app is live.

Inter 400 · Body text

Ten seconds, read-only, plain English.

JetBrains Mono 400 · URLs, code and evidence

https:// my-store.lovable.app

05The result

The product is live and used by real people: 301 scans in the last 30 days, with payments, GitHub sign-in and automatic pull requests with the fixes.

The site’s own security headers meet the same standard it checks other sites against.

Lighthouse · measured 2 Oct 2026

MetricMobileDesktop
Performance95100
Accessibility100100
Best practices100100
SEO100100
LCP2.5s0.5s

Security headers · 2 Oct 2026

ALeft Unlocked scan100/100Report

  • Present:Content-Security-Policyno unsafe-inline
  • Present:Strict-Transport-Security
  • Present:X-Frame-OptionsDENY
  • Present:X-Content-Type-Options
  • Present:Referrer-Policy
  • Present:Permissions-Policy

Scan grades, last 30 days

  • A76
  • B131
  • C68
  • D17
  • F9

From the site’s public stats, as of 2 Oct 2026

Want a site like this for your business?