Claim verification
Does the product actually do what the landing page, docs, pricing, and UI tell users?
Product truth audits for AI-coded apps
RealityDiff compares your landing-page promises, specs, code, data flows, and live product. You get evidence-backed gaps, not a generic AI code review.
Run by Ethan Cho. No credentials or write access are requested in the application form.
Landing pages, docs, UI copy, pricing, policies.
Routes, flows, error paths, deployment state.
State transitions, credits, limits, webhooks.
Reproduction, impact, source lines, smallest fix.
Not another code scanner
Security scanners find familiar vulnerable patterns. Browser tests check flows you already knew to specify. RealityDiff looks for contradictions across the whole product, especially after rapid AI-assisted pivots.
Does the product actually do what the landing page, docs, pricing, and UI tell users?
Old products, routes, jobs, tables, and CTAs that stayed live after strategy moved on.
Event names, enums, filters, and state machines whose readers silently disagree with writers.
Payments, credits, points, and rewards that can duplicate under retries or concurrent requests.
Wrong production branches, missing secrets, sandbox payments, stale environments, and ephemeral data.
Auth, mobile, empty states, failures, limits, and actions that only break in the running product.
Internal pilot
We ran the first pilot on an app we built and operate. Identifying details remain withheld while the issues are remediated. These are sanitized findings, not hypotheticals.
Live product + repository + deployment configuration
The product’s core trust claim said holdout tests were hidden from participants. The exact holdout files and expected answers were shipped in the public repository, allowing prompts to overfit the supposedly secret cases.
A valid payment webhook directly incremented a user balance, but no provider event ID was recorded. A normal webhook retry could credit the same purchase twice.
Two concurrent requests could both see zero attempts, both run the expensive model, both write a result, and both grant the success reward. The UI promise was stronger than the database guarantee.
More than 1,000 lines from an earlier product pivot remained reachable at a polished public route, with its own database tables and submission workflow, despite disappearing from navigation and strategy.
The newest, prominently promoted feature was linked in navigation but omitted from the dynamically generated sitemap, while lower-priority legacy pages were included.
The root document used lang="en" while primary pages and controls were Korean. Screen readers, translation tools, and search engines received the wrong language signal.
Security note: identifying details and exploit-ready code are withheld from the public sample. Full clients receive exact source locations and reproduction steps privately.
The workflow
No giant dashboard, no scanner noise. Every finding must connect a real promise to inspected evidence and a realistic user or business impact.
I inventory public copy, documentation, important flows, routes, jobs, data contracts, and deployment assumptions.
I inspect the live app and repository, trace cross-layer behavior, and reject findings that cannot be evidenced.
You receive severity, reproduction, source locations, impact, and the smallest practical fix in priority order.
First five products
For live web apps built quickly with Claude Code, Cursor, Replit, Lovable, Bolt, Base44, v0, or a similarly fast stack.
Accountable by name
RealityDiff is operated directly by Ethan Cho, a product builder and investor based in Seoul. There is no anonymous reviewer pool and no source-code training pipeline.
Ex-Google and Qualcomm, currently building and reviewing AI-assisted products. Every audit is performed personally, and every reported gap must connect a product promise to inspected evidence.
Read-only access, non-destructive testing, and no credentials in the intake form. Temporary source checkouts are deleted within 14 days after the report walkthrough unless a different period is agreed. An NDA is available before access.
Straight answers
The audit is designed to minimize access and avoid production risk.
No. RealityDiff is a product-behavior and business-logic audit. It may identify security-relevant gaps, but it does not replace a formal pentest, SOC 2 review, HIPAA assessment, or legal advice.
No. Read-only repository access is the default. Live testing is non-destructive. I will not create users, purchases, load, or persistent data without explicit permission.
It is used only to deliver the audit. No source code is published, used for training, or included in public samples. Public case studies require separate approval and are sanitized.
You should use it. The missing layer is independence: the same assumptions often shape the product, the tests, and the AI review. RealityDiff starts from the product promise and checks multiple layers against live reality.
After scope and access are confirmed, before the audit starts. If the final report contains fewer than five actionable, evidence-backed gaps, the fee is refunded in full.
Yes, as a separately scoped behavioral review. The five-gap guarantee applies only when public or read-only repository access is available, because cross-layer evidence is the core of the full audit.
Within 72 hours after scope, payment, and access are confirmed. If that timing cannot be met, I will tell you before payment.