Ascertify is an independent code audit for SaaS bought on Flippa, Acquire.com or TrustMRR, and apps built with Lovable, Cursor or an agency. It reads the repository without running it and shows what's exposed, what's missing, and what only the seller knows how to run. Every finding is pinned to a file and line, in plain English, before the money moves.
A read-only GitHub invite the seller can revoke, or a zip from the data room. JavaScript and TypeScript apps: Next.js, React, Node, Supabase, Firebase, Prisma.
Your secret database admin key is sitting in code that ships to the browser. It bypasses every access rule you have. Anyone who opens your site can read or change all of your data.
three questions the listing can't answer. the code can.
Whether the code is safe to own, whether what was built is real, and whether anyone but the seller can run it. The demo works and the revenue checks out. The problems live underneath, in files nobody opened before the listing went up, or before the invoice was sent. So we open them, and point at the exact lines.
can anyone reach the customers' data, the keys, the database? Can the seller, after you take over?
Credentials committed to git history, databases open to the internet, admin keys shipped to every visitor's browser.
is it a product, or a template with a Stripe key?
Packages that don't exist in any registry, a database with nothing but default scaffolding, template code passed off as custom.
could a new developer, or you next month, pick this up and keep it running?
No setup instructions, no record of how the database is structured, a schema that exists only in the live system.
our own data, not a vendor study
In September 2026 we scanned 70 public Lovable apps with the same checks a paid report runs. 28 of them, 40%, had a critical or high problem in code their own team wrote, and 19 of the 33 with edge functions had an endpoint anyone could call. The raw numbers are published. Read the Lovable security report →
Point us at a GitHub repo or drop in a zip. Either way, nothing gets installed or run. We only read.
Deterministic checks, no guesswork. Every finding is tied to a real file and line, with the exact snippet shown.
Forward the PDF to the seller as a closing condition, hand it to your developer after transfer, or paste the findings into your AI tool and fix them yourself.
Every scan runs this exact list: deterministic checks, not impressions. Nothing on it requires you to trust our judgment, because every hit comes with the file and line that triggered it.
And every report lists what a static scan can't see: runtime behavior, whether your features actually work, performance under load. A clean result on this list is real, but it's never dressed up as more than it is.
findings that survive a defensive seller
No vague grades, no “your app is risky.” Every finding is pinned to a line of real code: specific enough that “that's not an issue” needs an answer for that line, clear enough that you don't need a CTO to understand it.
No subscription, no upsell loop. You need this at one moment (right before the wire, right before you ship, or right before you pay the final invoice), so it's priced as a single check. Run it again on the next deal or the next milestone, same one-time price.
You're about to wire real money for a codebase you've never opened, or you already paid for one. Knowing what's in it costs $49 while the first 50 last, $99 after.
Free preview
A count of the critical findings in your code. Enough to know whether there's a problem worth raising, before you pay for the detail.
Run free previewEvery finding with file-and-line proof, the exact code, a plain-English explanation, a recommended first step, and a PDF you can forward to your developer.
Get full report ($49)Every claim below is one you can check yourself, which is the only kind of trust worth offering someone who's been burned before.
Connecting a repo installs the Ascertify GitHub App with read-only access to only the repository you pick — never your whole account. You can uninstall it from your GitHub settings the moment the scan is done.
We read files as text: we never run your app, install its dependencies, or execute its tests. Each scan runs in an isolated sandbox and the code is deleted when it completes.
No finding reaches your report without a real file, line, and snippet behind it. Deterministic tools find the risk first. Plain English only explains what's already there.
“Ascertify is the check I'd do by hand after 15+ years building for startups and agencies - automated, with the evidence attached, so you don't have to take anyone's word for it. Including mine.” Valentin Zuld, Founder, Ascertify · 15+ years in software · LinkedIn · Checks last updated: September 2026
The free preview takes a few minutes and tells you whether there's anything in the code worth negotiating over, or fixing before launch. Start there.
Scan the code, free to startNo install, no build, no run. Your code is sandboxed and deleted after the scan.