A plain-language security check for vibe-coded apps before real users and real logins arrive. Walks a founder through the handful of things that actually get small apps compromised (exposed secrets, weak or fake auth, unprotected data, missing input checks) and gives a prioritized fix list. Use before a launch, before taking real users, before handling payments or personal data, or any time someone jokes that they "vibe-coded the 2FA." Finds the real risks, in order, without fear-mongering.