Find the leaks.
Stick thepatch on.
Rustine dips your app in the water, part by part: your site, your repo, your server. Where it leaks, you see it. Your agent applies the patch, we dip it again to check.
Opening soon. Leave your email and we'll tell you on launch day.
Built for what Claude Code, Cursor, Lovable, Bolt and v0 ship: Supabase, Next.js, Vercel, a VPS set up on a Sunday night.
Project mysaas · 3 parts
52 /100 · D
UNDERWATER nothing yet
What Rustine looks at
The things almost every agent-built app forgets.
Your Supabase database
One table without an RLS policy, and anyone can read your users table without signing in.
Keys in your JavaScript
The service_role key or a live Stripe key shipped to every visitor in the bundle.
Forgotten files
A .env, a .git folder or a backup served online with everything else.
Chatty APIs
An API that returns the exact location of every user, even those who chose to hide it.
Your server
Port 5432 published by Docker, open to the Internet despite your firewall.
EU rules
Cookies set before consent, missing legal notice, processors outside the EU.
Never an intrusive test on someone else's site
Without proof that a site is yours, Rustine only does what a visitor would do. Deeper tests wait until you prove the domain is yours, and we check again before every audit.
Questions
Is it legal to scan my site?
Yes, as long as it is yours. Without proof, Rustine only does what a visitor would do: read headers, the certificate, public files. Deeper tests wait until you prove the domain is yours (a DNS record or a file), and we check again before every audit.
What exactly does Rustine check?
Your site (headers, TLS, exposed files, keys in your JavaScript, Supabase and its RLS policies, cookies and legal notice), your GitHub repo (secrets in history, dependencies with known flaws, published Docker ports) and your server (open ports, SSH, firewall).
And once a problem is found?
Each problem is explained in one plain sentence. To fix it, you copy a prompt ready to paste into Claude Code, Cursor or Lovable, or you let Rustine generate the fix. Then we check again: the problem only turns "fixed" once it is really gone.
How much does it cost?
One project free forever. Paid plans start at €9 a month, and early subscribers keep a launch price for life.
Where does my data go?
Scans are read-only, secrets we find are masked before they are stored, and everything is hosted in Europe, at Hetzner in Germany. Rustine is published by MBEN DEV, in Paris.
When does it open?
As soon as the beta is ready. People on the list hear first, in a single email.