Code Guard
Most fintech fraud starts with a flaw in the fintech’s own code. Code Guard finds the ones fraudsters use.
What it looks for
- M-Pesa / Daraja, Stripe, Flutterwave or Paystack callbacks that credit balances without verifying the sender: a forged callback is free money.
- Balance updates without a transaction or row lock (double-spend), and payouts without an idempotency key.
- Amounts taken from the client, negative amounts, and money stored as floats.
- Phone, email or payout-account changes without re-authentication or a cooling-off period.
- Payouts without 2FA, OTPs from
Math.random, unthrottled OTP and login endpoints, test backdoors. - Accounts or transactions readable by id without an ownership check, and mass-assignment of balance or role.
- Hard-coded Daraja, Stripe, Flutterwave, Paystack and cloud secrets.
Fixes you paste into your coding agent
Each finding has Copy prompt for your AI agent: a self-contained task with the file and line, why it’s dangerous, the exact change, acceptance criteria and the test to add. It works with Claude Code, Cursor or any agent. Copy all fixes combines them into one prompt, most severe first.
Your code’s privacy
For private repositories use a fine-grained GitHub token with read-only Contents on that repository. It’s used for the scan and never stored. The snapshot is deleted when the scan ends; only findings and short snippets are kept. The page lists exactly which payment-critical files, if any, were sent to the agent.