BUILT WITH AI · DREADING THE ETERNAL BUG-FIXER ROLE · SHIPPING SOLO

It's never
one fix.

You've built enough to know it — or you're about to find out.

About to find out

You haven't launched yet, and the videos have you terrified: your app could leak one user's data to another, charge someone twice, expose its keys, fall over the second real users arrive.

Already know it

You've shipped plenty, so you've felt the quieter truth they skip: you fix one thing, another surfaces, and the checking never really ends.

But you don't have to ship blind. Even alone.

The first full check doesn't have to be a scramble. Take the modules in sequence, top to bottom, and you've inspected what a whole team would. The 35 sessions you need to get through this launch solo — fewer, if your app's simpler. The exact system I run on my own builds. If you're nice, you'll share it. I'm nice. 😉

What "check the app" actually means
authentication · sessions · recovery · authorization · tenant isolation · privileged access · APIs · malicious inputs · browser security · files · storage · secrets · dependencies · build chain · database constraints · migrations · concurrency · queues · jobs · webhooks · payments · entitlements · privacy · logging · retention · deletion · exports · provider failure · observability · incident detection · backups · restore · disaster recovery · performance · load · capacity · quotas · cost · test evidence · counter-inspection · remediation · release gates · deployment · live checks · AI systems · mobile & offline · real-time collaboration · marketplaces & payouts · sensitive records · media pipelines · multi-region failover · community moderation · enterprise SSO & SCIM · browser extensions
That is why "just ask the AI if it's secure" is not an inspection plan.
25
core sessions
10
specialist packs
35
markdown files you keep
Build your folder

What does your app actually do?

Every answer changes which sessions your folder needs. Tap what's true. The universal sessions are always included; these decide the rest.

Your route: 13 of 35 sessions
universal baseline — tap above to tailor
One-time unlock

Drop your email to unlock.

Your email unlocks the whole library. Enter it once and your folder builds instantly.

That doesn't look like an email.

Your folder is ready.

Don't download 35 files and panic. This folder is the route your app actually needs, with a START-HERE router inside.

  1. Unzip it and drop the files into the AI environment that holds your project (Cursor, Claude, ChatGPT, Lovable, Bolt).
  2. Open START-HERE.md, then begin with Module 00.
  3. Follow each session's next-action instruction, in order.
  4. Never let the AI claim it ran a test it couldn't actually run. Log evidence in FINDINGS-LOG.md.

Every session · tap any file to download it alone

The first check, you can do yourself. The hundredth is the problem.

Running this once is a good weekend. Running it again every time you ship a change — keeping the evidence current, catching what a new feature quietly broke, never letting the checking fall behind the building — that's the part that eats you alive. You already know it never ends. That's the part I build for people. The connected setup where your tools share one source of truth, and the checks that run themselves so a person doesn't have to. I inspected my own builds with these exact modules, then automated the part worth never doing by hand again.

The Inspector is an inspection and evidence framework. It is not a security, engineering, legal, or regulatory certification. Provider-independent. Works in Cursor, Claude, ChatGPT, Lovable, Bolt, and other code-aware AI environments. Markdown files you keep.