Skip to content
The AI security agent you talk to

Ship it. Then just say “check it.”

Opviva is a security agent you talk to. Tell it what you shipped — it scans your live app and code, proves each exploit is real, and opens the fix as a pull request you approve in one click. Then it keeps watching. No live site yet? Connect your repo and it grades your code — no domain needed.

No signup for a shallow scan · we never store your source code

Free · no signup for the URL scan · 1 free code scan every day · we never store your source code

#1 Project of the Day on Smol Hunt

You shipped your app in a weekend.

myapp.lovable.app
live
3 critical issues · exposed Supabase key, public .env
Scanning myapp.lovable.app…
  • Security headersExposed
  • Exposed Supabase keyExposed
  • Public .env fileExposed
Opviva is fixing it…
  • Detected
  • Analyzing
  • Writing the patch
  • Pull request opened
Pull request merged · monitored 24/7
5,600
vibe-coded apps scanned in one 2026 study
2,000+
critical vulnerabilities found in them
91.5%
of AI-generated apps had a vulnerability
48 days
a major vibe-platform breach stayed open

Sources: Escape.tech mass scan & vibe-coding security studies, 2026.

How Opviva works

Four steps, one agent. You stay in control — it does the security work end to end.

  1. 1

    You tell it what you shipped

    In plain language, or just paste your app's URL. No scanners to configure, no dashboards to learn.

  2. 2

    It proves the exploit

    Opviva scans your live app and code, then reproduces each real vulnerability — so you see the impact, not a maybe.

  3. 3

    It opens the fix

    The agent writes the fix and opens a pull request. Small ones auto-merge; risky ones wait for your one-click approval.

  4. 4

    It keeps watching

    After launch it monitors your app and attack surface, and comes back the moment something new shows up.

A scanner hands you a list. Opviva does the work.

Most tools stop at “here are some maybe-issues.” Opviva proves each one, ships the fix, and keeps watching.

Typical security scanner

  • Hands you a list of maybe-issues
  • You triage and verify every finding
  • You write and ship every fix yourself
  • Drowns you in false positives
  • One-time scan, then you're on your own
  • Configure the tool, read the docs

Opviva

  • Proves each exploit is real — reproduced, not guessed
  • It does the triage — you see only confirmed issues
  • Writes the fix and opens a pull request you approve in one click
  • No noise — only real, reproduced findings
  • Keeps watching your app and attack surface 24/7
  • Just talk to it in plain language

What the free scan checks

A URL-only shallow scan — no code access — surfaces the exact issues AI builders ship. No live URL? Connect a repo instead: the agent scans your code, dependencies, and secrets with no domain needed — 1 code scan free every day.

Security headers

Missing CSP, HSTS, clickjacking and MIME-sniff protection.

Exposed secrets

API keys and an exposed Supabase service_role key in your bundle.

Sensitive files

Publicly downloadable .env and .git directories.

HTTPS & cookies

Insecure cookies, weak transport, and stack disclosure.

Your app probably has one of these right now. Find out free — no signup.

Not another dashboard. An agent that does the work.

Security tools hand you findings and leave the hard part — proving they're real and fixing them — to you. Opviva is the opposite: you talk to one agent, it proves each exploit, ships the fix as a pull request you approve, and keeps watching. You stay in control; it does the work.

Your code stays yours

We never store your source. Scans run, then drop it.

Read-only by default

Least-privilege GitHub access. You approve risky fixes.

Every fix is reviewable

Changes ship as pull requests you can read before merging.

Tamper-evident · hash-chained

Watch it prove the exploit

The agent doesn't just flag an issue — it reproduces it on a live Evidence Canvas. An AI agent logs in as itself, with valid credentials, so a bad decision hides inside a chain of tool calls. Opviva records every step, append-only and sealed, so you can prove exactly what happened and that the record was never touched.

Session reconstructedcheckout-agent
Hash-chain verified

One agent's session, replayed newest first. It handled a refund normally — then quietly overstepped. Opviva caught it and sealed an unforgeable record.

  • Opviva flagged the action and sealed the sessionCaught & sealed

    2026-06-20T14:02:56Z

  • checkout-agent ran DELETE FROM users — outside its allowed scopeThe violation

    2026-06-20T14:02:55Z

  • checkout-agent issued a ₹4,200 refund to the original method

    2026-06-20T14:02:44Z

  • checkout-agent queried the orders table for order #80421

    2026-06-20T14:02:43Z

  • checkout-agent received a refund request from a customer

    2026-06-20T14:02:41Z

Session
sess_8f21a9c4
9f2a1c4e0a8f
Sealed
2026-06-20 14:02:56 UTC
Chain head
block #1,284
a17be93cd80b
1,284
sessions recorded · chain intact

Every step is sealed and linked to the one before it — edit or delete any of them and the record visibly breaks, so it can't be forged. Illustrative reconstruction.

See how the Evidence Canvas works →

No surprises. You stay in control.

Our promise: nothing merges without your one-click approval, we never store your source, and you can cancel anytime.

Will it break my app?

No. Every fix ships as a pull request you review and approve — nothing merges without your one-click OK. Read-only by default.

Do you keep my source code?

Never. Scans run and the code is dropped — we never store it. GitHub access is least-privilege and you stay in control.

Is the scan really free?

Yes — the scan and letter grade are free forever, no card. You only pay if you want the agent fixing and watching for you.

What if I'm not technical?

You don't need to be. Paste a URL or talk to the agent in plain language — it does the security work and explains every finding.

Ready? Grade your app's security in seconds — free, no signup.

Simple, honest pricing

Start free — 1 code scan every day, no card. Plans are credit bundles, not feature locks — and 24/7 monitoring is a per-app add-on funded by credits. Cancel anytime.

Free

See where you stand — free.

$0forever
1free code scan / day
  • 1 free code scan every day
  • Credits power everything else — top up anytime
  • Plain-English proof of what it finds
  • Security score (0–100)

Starter

The agent watches your app.

$19per month

No GST · billed in USD

2,000credits / mo

24/7 monitoring

Weekly · 200 cr/app

Daily · 1,300 cr/app

  • ≈ 40 code scans or 8 fix PRs / mo
  • Alerts the moment something regresses
  • Proof on every finding, on the Evidence Canvas
  • Credits roll over one month
Most popular

Growth

It watches — and opens the fixes.

$49per month

No GST · billed in USD

5,000credits / mo

4,500 + 500 bonus

24/7 monitoring

Weekly · 200 cr/app

Daily · 400 cr/app · up to 3 apps

  • ≈ 100 code scans or 20 fix PRs / mo
  • Agent-opened fix PRs, ready to review
  • One-click approval; small fixes auto-merge
  • Credits roll over one month

Scale

Hands-off. The agent runs security.

$99per month

No GST · billed in USD

10,900credits / mo

9,900 + 1,000 bonus

24/7 monitoring

Weekly · 200 cr/app

Daily · 200 cr/app · up to 10 apps

  • ≈ 218 code scans or 43 fix PRs / mo
  • Everything in Growth, priority queue
  • Dependency upgrades handled for you
  • Priority incident response

See full plan details →

Frequently asked questions

What is Opviva?

Opviva is an AI security agent for AI-built apps that you talk to. You describe what you shipped in plain language; it scans your live app and code, proves each vulnerability is real by reproducing the exploit, opens the fix as a pull request you approve in one click, and keeps watching after launch — all on a live Evidence Canvas.

Is Opviva the same as Opvia?

No — they're unrelated. Opviva (opviva.com) is an AI application-security agent for apps built with Lovable, Bolt, Cursor, and v0. It is not affiliated with Opvia, the offshore-talent and business-consulting firm, or any other similarly named company. If you searched for 'opviva' and were shown 'opvia', you're in the right place now.

How is Opviva different from a normal security scanner?

A scanner hands you a list of maybe-issues and leaves the work to you. Opviva is an agent: it proves each finding is real by reproducing it, then writes the fix and opens it as a reviewable pull request that merges on your one-click approval — and it keeps monitoring after launch. You talk to it in plain language instead of configuring tools.

Is my AI-built app secure?

Often not by default. In a 2026 mass scan, 91.5% of AI-generated apps had a vulnerability — commonly exposed API or Supabase keys, missing access control, a public .env, or no security headers. Opviva's free scan grades your live app in seconds so you know.

How does the free security scan work?

Paste your app's URL, or just tell the agent to check your app. Opviva inspects the live response headers and front-end bundle for exposed secrets, sensitive files, and missing protections, then gives a 0–100 score and a letter grade with a plain-English report. No signup, no source-code access. Every account also gets 1 free code scan a day — connect your repo and the agent scans your code, dependencies, and secrets, no domain needed.

What does it mean that Opviva 'proves the exploit'?

Instead of a theoretical warning, Opviva reproduces the vulnerability — for example reading another user's data through a missing Row-Level Security policy, or pulling an exposed service_role key from your bundle — and records every step on a tamper-evident Evidence Canvas. You see the real impact, not a maybe.

Can Opviva fix the issues automatically?

Yes. The agent writes the fix and opens it as a pull request. Small, safe fixes can auto-merge; higher-risk changes wait for your one-click approval so you always stay in control. It keeps monitoring after the fix ships.

Which platforms does Opviva support?

Any live web app, including those built with Lovable, Bolt, v0, Replit, Cursor, Claude Code, and Emergent. Non-developers just talk to the agent or paste a URL; developers can use the API, CLI, and CI.

Do I need a live domain to use Opviva?

No — connect your GitHub repo and the agent scans your code, dependencies, and secrets, then grades you with no domain at all. Perfect for half-finished apps, side projects, and student work. A verified domain unlocks the live side: 24/7 monitoring and attack-surface testing against your running app.

Do you store my source code?

No. Scans run and the code is dropped — we never store your source. GitHub access is least-privilege and you approve risky fixes before they merge.

How much does Opviva cost?

Everything runs on one credit balance — a code scan is 50 credits, a fix PR is 250, and 24/7 monitoring is a per-app, opt-in add-on funded by credits. You get 1 free code scan every day — see where you stand, free, no card. Plans (Starter, Growth, Scale) are credit bundles with bonus credits and a cheaper monitoring rate, not feature locks; any credits — plan, top-up, bonus, or referral — spend the same. See the pricing page for current rates in your currency.

How do I add Row Level Security to my Supabase app?

Enable RLS on every table in the Supabase dashboard and write per-user policies, then make sure the service_role key is only used server-side. Or just ask Opviva — the agent proves the gap, then opens a reviewed pull request that adds RLS and moves the key off the client for you.

Tell the agent to check your app — free

One scan. Plain-English report. No signup for the shallow check.