Malinois
Home / Security guides
Malinois Field Guide

AI app security guides

Use these guides before launch, after a major change, or whenever an app becomes public. Every check is observable from your own deployment and avoids benchmark claims that need a larger verified sample.

AI app security checklist

A launch-to-maintenance workflow covering access, data, dependencies, recovery, and verification.

Read guide →

Security headers checklist

Understand the browser protections each response header adds and verify them without guesswork.

Read guide →

Prevent API key leaks in web apps

Keep provider keys out of public bundles, logs, repositories, and unsafe client-side workflows.

Read guide →

A safe review starts with three rules

Only test what you own

Use your own production or staging URL, and never probe someone else’s app without explicit permission.

Observe before you attack

Start with public responses, browser behavior, and configuration. A passive review can reveal important gaps without exploitation.

Fix, deploy, verify

Treat a finding as open until the corrected deployment is live and a second check confirms the result.

Check the deployed app, not just the checklist

With the owner’s authorization, Malinois reviews public responses for exposed files, secrets, database access signals, and missing security headers.

Run a free passive scan

Passive external review only. No exploitation or penetration testing.