byte.status = ON_SHIFT

Don't let your AI app bankrupt you

A funny security survival game for vibe coders who ship fast and would prefer not to ship their database too.

already sharp? try the expert sus-or-ship arcade →
Fix RLS, auth, and SQL mistakes
Stop leaked keys before bots do
Learn GDPR without the paperwork
Case file — live demo
Case KL-01Leaked secretbeginnerBlast radius £23k
Incoming disaster. Stay calm.
1/1 · Key lockerbeginner

The 2 AM push

You push your project to a public GitHub repo at 2 AM and go to bed proud. At 2:07 AM you bolt upright: the .env file went with it. Stripe secret key. Database password. Everything.

$ git log --oneline
a3f9c21 added env stuff (oops)
9b1d044 initial commit

Heart pounding. First move?

tap to answer

// how it works

// what's inside

£4.1M of disasters — all survivable

Every scenario is a real mistake AI-assisted coders ship, priced at what it costs in production. Answer wrong here, where it's free.

10
rooms
29
doors
100
disasters
£4.1M
damage to dodge

+ a new Incident Room drop every month, from fresh real-world disasters

// not just a quiz

A pre-launch checklist for your own app

35 concrete checks to run before you ship — RLS, secrets, CORS, billing caps, GDPR — each linked to the lesson behind it. Tick them off, track your readiness, keep it for the next project. The part you actually keep using.

Open the checklist
  • RLS on every table, service key server-side
  • Secrets out of the client and git history
  • Billing caps before you share the link
  • A real deletion path for GDPR

// pricing

Cheaper than one leaked key