Also promised, in theory: The keys aren’t in the bundle. The model only does its job. The rules got tightened after the demo. The defaults are safe.
The promises came with the build. Maybe the app is live, maybe the pilot stalled, maybe a vendor built it and handed you the keys. Either way you’ve had the thought: what else can this thing do, for someone who isn’t me? Good question. It deserves an answer before somebody else asks it.
Let’s talkYou’ve read the stories. The Tea app took off, and within days tens of thousands of user selfies and government IDs were spilling out of a storage bucket nobody had locked. CVE-2025-48757 documented the same gap as a genre: vibe-coded apps shipping with their databases readable by anyone who thought to ask. The pattern is public record and it keeps repeating, because the same tools keep building the same gaps.
These weren’t careless people, they were fast, and fast is a real advantage. But the tools that wrote the code care about one thing: does it work. Safe never came up.
The gap between working and safe is where the breach lives.
API keys pasted where the code needed them: the client bundle, the repo, a config file the whole internet can fetch.
The demo needed permissive rules to work, and the rules never got tightened. Any signed-in user, sometimes any visitor at all, can read rows that were never theirs.
If your product talks to a model, the model is an entrance. Prompt injection is a stranger talking your own AI into using its tools and its data on their behalf.
AI picked the packages, the versions, and the defaults, and no human reviewed the choice. Whatever is wrong with them is now wrong with your product.
None of this means you built wrong. You built fast, and nobody has looked yet.
AI is confident whether it’s right or wrong. The review exists to know the difference before someone hostile finds it for you.
For a decade at ShapeShift, this shop never touched customer key custody. That work was available and we did not take it: hold the keys and one mistake ends somebody else’s money with our name on it. The judgment was made against our own commercial interest, which is the only kind worth citing. The engagement is on the record, refusal included.
Behind that, the record it came from. We have shipped where being wrong costs money rather than embarrassment: an exchange from 2013, a lending platform holding collateral with Phil as fractional CTO through its launch, and fund rails moving real money for WallStreetBets. None of those were allowed to work only on the demo.
And we build with AI every day. That counts for more here than a certificate would: the tools that wrote your code are the tools that write ours, and we know where they cut corners because we watch them do it.
The scope stands whether we do the fixes or not. Take the ranked findings to your own engineers or to another firm; the document is built to survive that trip. If you want the people who found the gaps to close them, hardening and watch are priced on the same page, and you decide with the list in hand.
Nothing you send is used to train any model. The scope runs under NDA, signed before any code moves. When the work is done, your artifacts are deleted on request.
Innovation Theory has been at this since 2011, through several waves of new tech. We were shipping production systems before AI wrote a line of code.
25 years in the craft · 140+ engagements · in business since 2011
Ten minutes with Phil about what you have. A straight answer in two days, from the person whose name goes on the scope. Free. Send context, not code, and never credentials.
Think it’s already open? Don’t wait two days. First, revoke any key you believe is exposed; that costs nothing and closes the fastest door. Then email phil@innovationtheory.com with URGENT in the subject. That word puts it ahead of everything else on the desk.