All posts

July 22, 2026 · 4 min read

What Running Our Scanner on a Bunch of Real Live Apps This Week Actually Showed Me

It's been a little over a week since Harbova's free scan went live, and I've been watching the results come in the way you'd expect someone who built the thing to watch them: closely, and a little anxiously, waiting to see whether the pattern I'd found doing this by hand for a year actually held up at scale.

What held up exactly as expected

The same handful of issues kept showing up, over and over, across apps that had nothing else in common: an exposed key here, a database with no real access rule there, a missing security header on an app that otherwise looked carefully built. Nothing about the pattern surprised me. It's exactly what a year of manual audits had already shown me, just confirmed now across a much wider, faster stream of real apps than I could ever have looked at by hand.

What did surprise me

How often a founder's reaction wasn't defensiveness, it was relief. I expected some pushback, "are you sure this is really a problem," that kind of thing. Instead, most people who got a critical finding back seemed genuinely glad to have found out this way rather than some other way. That wasn't something a year of one-off audits, done quietly and privately, ever really let me see, since there was no shared, public moment for people to react out loud.

Why I think the pattern holds regardless of who's scanning

None of this is really about which specific apps happened to get scanned this particular week. It's that the underlying causes, building fast, testing the happy path, shipping the moment a feature visibly works, are the same causes regardless of who's building or what they're building. A scanner just makes that pattern visible faster and to more people than one person looking by hand ever could.

Where this leaves things

A week in, the honest read is that the problem is exactly as widespread as I thought it was before building anything, maybe slightly more so. That's not a fun thing to confirm, and it's also exactly why I built this in the first place. If you haven't run yours yet, I'd genuinely rather you find out from a scan than the other way.

Related reading

See where your own app actually stands. Free, under a minute.

Scan my app free

Harbova is a security service for apps built with AI tools. Start with a free scan, and if it finds something serious, we can fix it and prove it is closed.