Skip to content
NOWL
PlatformPricingBlogCareersAbout UsPublic DB
Sign inStart scanning
NOWL
Security built for AI-generated code.
SYSTEM · OPERATIONAL
PRODUCTPlatformArchitecturePricingAPIPublic findings
COMPANYAbout UsBlogChangelogStatus
LEGALPrivacyTermsCookiesDPARefundsAcceptable Use
CONTACTsupport@nowl.buildlegal@nowl.buildabuse@nowl.build
MANIFESTO · 2026.05

The tools assumed a human wrote the code.
They were wrong.

NOWL emerged as a result of changes in the threat landscape. Individual developers and professionals are rapidly developing SaaS applications, launching them on Friday nights, and then discovering dozens of different vulnerabilities by Sunday.

01 // ORIGIN

Why this exists.

// 2026 // not a venture pitch

The week NOWL started, three things happened in public: Aikido published an audit showing that 10.3% of Lovable's own showcase apps were leaking customer data. Bolt.host users discovered their OpenAI keys were shipped in client bundles. A vibe‑coded social network called Moltbook breached 1.5M API tokens three days after launch.

Anyone who had shipped a vibe‑coded app that month was an audit waiting to happen — the same Supabase rules, the same exposed keys, the same first‑answer code. The breach just hadn't arrived yet.

The existing security tools assumed a different threat model. They scan for the vulnerabilities a tired senior engineer writes at 2am, or the dependencies an enterprise procurement team would have approved. None of them knows what a language model produces when a founder types "build me an auth flow with Supabase" and accepts the first answer.

NOWL knows. The scanner was written from the assumption that an LLM wrote the input. The rules target the patterns Lovable, Bolt, Replit, v0, and Cursor produce in their default templates. The Hallucination Database catches the packages that don't exist on npm but the model insists on installing. The Fix with AI loop is constrained — same model family that broke the code is the one allowed to patch it, under a six-layer guardrail.

And pricing is determined by the value the product holds for those who use it, not by the price set by the sales team. Because we started out as a small team and then grew. We know the ropes.

02 // BUILD

In public.

// shipped weekly // every merge logged
WEEKLY

Friday changelog

Every Friday: what shipped, what broke, what is next. Public failure beats private polish.

View changelog →
MONTHLY

Vibe coding security report

Aggregate stats from anonymized scans. Which platform produced the most Tier 1 findings? Honest data.

View archive →
CONTINUOUS

NOWL-CVE Public DB

Every novel pattern we find is published with NOWL-YYYY-NNNN ID. 90-day responsible disclosure. RSS feed.

security.nowl.build →
// talk

Built for the people shipping AI-generated code.

Questions about NOWL? Write to support@nowl.build — we read every message.

Start scanning →See pricing