The state of AI-built app security
Live data · updates automatically as we scan · Broid
What this is: every statistic on this page comes from scans Broid has actually run. It is not a survey, not an estimate, and not borrowed from anyone else's report. It updates itself. The methodology and the limitations are set out in full below — including the ways this sample is not representative, because a number you can't interrogate isn't evidence.
Methodology
Stated in full so you can decide how much weight to give it.
- Source. Every site scanned through broid.net, counted once. Re-scans of the same site update its grade but never increment the totals, so "sites scanned" means distinct sites rather than requests.
- What a scan does. An external check of what the live site exposes publicly: security headers, TLS and transport, exposed files and secrets, cookies, CORS, dependency vulnerabilities via the OSV database, DNS and email records — plus a live database-exposure probe using the app's own public key, which counts rows without reading them, and a test of whether AI endpoints answer without authentication.
- What "database exposed" means here. Only a confirmed anonymous read of a real table. Not a guess, not a missing policy inferred from configuration. If we could not confirm it, it is not counted.
- What is stored. Integer counters and nothing else. No hostnames, no URLs, no findings, no report contents. It is not possible to work backwards from this page to any individual site.
Three limitations, stated plainly.
- The sample is self-selected, not random. These are sites whose owners chose to scan them, plus sites scanned out of curiosity by people who don't own them. People worried about their security are more likely to check — which could push the numbers either way. This is not a random sample of the web and must not be reported as one.
- Not every site here was built with AI. We do not ask, and we cannot reliably detect it. The dataset includes large well-known sites people scan to compare.
- It measures the outside only. A scan does not log in, so nothing here says anything about whether one signed-in user can read another's data — which is a serious failure class this dataset is blind to. Absence from these numbers is not evidence of absence in the wild.
Why we publish this at all
There are around twenty security scanners aimed at AI-built apps. Most compete on check counts — 150, 310, 721, 6,000 — numbers that aren't comparable and that no buyer can evaluate. It is a claim you win by inflating.
Measurement is the opposite. A tool that has actually scanned sites can publish what it found, with its method attached, and be checked. A landing page cannot. That is the whole reason this page exists, and it is why the limitations above are on the page rather than in a footnote.
Free to cite. Reference it as "Broid, The State of AI-Built App Security, live dataset, broid.net" with the date you retrieved it, since the numbers move. Machine-readable at /api/stats. If you think our method is wrong, tell us — we'll publish the correction.
Add your app to the dataset. Free A–F grade in seconds, no signup. You see your result; the dataset only ever sees an anonymous counter.
Scan my app free →
What the wider research says
Our dataset is small and self-selected. Two larger studies are worth knowing, with their own caveats:
- 1,072 live AI-built apps scanned — 98% had at least one flaw, 16% had a critical one, and 172 allowed unauthenticated data deletion. Published by Symbiotic Security, a security vendor, and the sample skews toward publicly discoverable Supabase-backed apps.
- Veracode found that across 150+ large language models tracked since 2023, generated code passes security tests about 55% of the time — statistically unchanged in two years, while syntactic correctness exceeds 95%. Waiting for the models to get safer is not a strategy.
See where your app sits
Free A–F grade in seconds, no signup, including the live database-exposure test.
Scan my app free
We publish our own grade too — A+, and it's a live badge on the homepage, not a screenshot.