Skip to content
Veristria
See the evidence

Ecosystem

Three surfaces where fast shipping goes quiet

Three independent security products for AI-assisted teams: exposed API keys in client-side JavaScript bundles, Supabase row-level security that has drifted from the schema, and Stripe Connect fee leaks. Each has its own domain, pricing and roadmap. What they share is a refusal to report anything they cannot prove.

Secret exposure

KeyDrift

Free scan, no account. Monitoring from $29/month.

Finds the API keys and secrets that AI coding tools leave behind in client-side JavaScript bundles.

Backend posture

RowShield

Free URL check. One connected project, scanned daily, is free. Faster monitoring from $29/month.

Checks what your Supabase anon key can read from a deployed URL — free, read-only, under ten seconds. Connecting one project is free and runs the nine-rule audit daily; paid plans add projects, faster scans, and more alert channels.

Revenue integrity

FeeGuard

Detection is free. Monitoring from $49/month.

Finds the Stripe Connect transfers and fees a refund leaves behind, from an export you paste — read-only, no credentials. 90-day lookback. Detection stays free.


Secret exposure

KeyDrift

Finds the API keys and secrets that AI coding tools leave behind in client-side JavaScript bundles.

The problem
Build-time environment variables inline their values into the JavaScript bundle. An .env file that is correctly git-ignored still ships its contents to every visitor, and no repository scanner will ever see it.
What it does
KeyDrift reads the JavaScript your site actually serves, not your source tree, and identifies Supabase, Stripe, OpenAI and AWS credentials in it — while recognising the publishable keys that belong there and are not leaks.
Who it is for
Solo founders and small product teams shipping AI-assisted frontends on Vercel, Netlify and similar.
How you can check it
Findings carry a masked prefix and the exact chunk they came from, so you can rotate immediately. Live secrets are never stored, and the first scan needs no account.

What it catches

  • NEXT_PUBLIC_ or VITE_ inlining a secret into the bundle at build time
  • A Supabase service_role key shipped to every visitor
  • Stripe sk_live_ or OpenAI sk-proj- keys readable in DevTools
  • Secrets left behind by Lovable, Bolt, Cursor, Claude Code or Replit
  • A clean repository scan while the deployed bundle leaks
Backend posture

RowShield

Checks what your Supabase anon key can read from a deployed URL — free, read-only, under ten seconds. Connecting one project is free and runs the nine-rule audit daily; paid plans add projects, faster scans, and more alert channels.

The problem
Supabase makes the database directly reachable from the browser, and row-level security is the only thing standing between a public anon key and every row in the table. Policies drift as the schema does.
What it does
RowShield tests the policies continuously against the live project, detects schema drift as tables and columns change, and reports the specific query that returns a row it should not.
Who it is for
Teams building on Supabase, especially those whose schema is moving faster than their security review.
How you can check it
Every finding is a reproducible query, with remediation SQL generated from your actual columns. The free audit is read-only and runs before any credential is connected.

What it catches

  • Row-level security disabled on a public table
  • RLS enabled but with a policy that is always true — USING (true)
  • A new table shipped without any policy at all
  • Schema drift leaving an old policy covering less than it did
  • A Security Advisor warning that returns after every deploy
Revenue integrity

FeeGuard

Finds the Stripe Connect application fees a refund leaves behind, from an export you paste — read-only, no credentials. 90-day lookback. Detection stays free.

The problem
On a Stripe Connect platform, a refund, dispute or FX movement can leave the connected account paid while the platform absorbs the loss. Nothing errors; the money is simply gone.
What it does
FeeGuard reconciles charges, transfers, application fees and disputes in real time, flags the discrepancies, and can reverse the ones that qualify automatically.
Who it is for
Marketplace and SaaS platforms running Stripe Connect at enough volume that manual reconciliation has stopped being viable.
How you can check it
Each discrepancy links to the underlying Stripe objects, so you can check the arithmetic yourself. The connection uses a restricted key scoped to the reads it needs, and recovery is reviewed before it runs.

What it catches

  • A refund issued without reverse_transfer — the platform pays, the seller keeps it
  • An application fee still attached to revenue that no longer exists
  • A dispute lost after the payout had already cleared
  • FX slippage between charge and payout eroding margin invisibly
  • A leak discovered at month-end close, after it stopped being recoverable

Coverage

Why three products rather than one platform

The three surfaces are genuinely different problems with different buyers, different credentials and different failure modes. Bundling them would mean asking a Supabase team to pay for Stripe reconciliation they will never use, and it would mean one product’s outage taking the other two down. They stay separate.

What they share is the parent: the same company desks, one standard for what counts as a finding, and one set of writing. Questions about any of them reach us at support@teamveristria.com, and the FAQ answers which product fits which problem.

Get product updates

Enter your email for product updates across KeyDrift, RowShield and FeeGuard.

Founding customers (first 100) lock in 25% off annual forever.