EngineeringCodeCross Team
Harden a Windsurf MVP before paid traffic (2026)
A 2026 wrap-in-place playbook for founders still shipping from Windsurf Cascade: rank the blast (chat and rules secrets, preview vs .windsurf.build, auth/RLS gaps, unreviewed agent diffs, no CI, no host rollback), prove the doors before ads, then decide stay-harden vs leave.
Engineering
14 min
- Secrets
- Host vault
- Origin
- Claimed host
- Ads
- After
Not chat or git
Not .windsurf.build
Proof first
Citation-ready definition: Windsurf is an AI IDE. Cascade plans, edits many files, and runs terminal steps on a local folder. A Preview is a local lab. App Deploys can print a public `*.windsurf.build` URL. That URL is a preview, not the ad target. Secrets in chat, rules, memories, MCP config, or a committed `.env` are live keys. Named Cascade checkpoints undo local edits. They are not a host rollback. Ads wait until org Git, host-injected secrets, and a stranger test hold.
This note is from CodeCross (Austin registration, Pakistan engineering on a US Central overlap). Cousin tools sit on vibe coding. Buying help is the Austin app development company page. If nobody can name a host rollback tonight, use book a conversation.
Money leaves when the campaign still lists a `*.windsurf.build` preview, a laptop Preview tab, or a key that lived in Cascade chat. A stranger can find a row because the generated backend has no row rules. Turbo accepted a `git push` to an unprotected main. The only undo is “open Windsurf and revert the prompt.” A green Cascade terminal is not a stranger test on the name you would put on a billboard.
This essay is the pre-ads wrap while the app still depends on Windsurf-assisted generation. It expands Harden a Windsurf Cascade MVP before campaigns. It is not the first useful ship on Windsurf to production, not the runtime exit on get off Windsurf, not the extract on migrate from Windsurf, not the overlap week on transition from Windsurf. Cousin wraps: Bubble, Framer, Softgen, Lovable, Replit, v0, Bolt. Those pages are not this Cascade week. The question here is narrower: can you buy a click while Windsurf still owns preview and the agent still writes the tree? Soft CTA: when chat secrets, the public origin, or the host off switch is still red, book.
The punchy lists live on the landers. Windsurf MVP hardening is the clipboard for this week. Windsurf to production is preview-is-not-a-ship-path. Get off Windsurf is the runtime exit. Migrate from Windsurf is extract. Transition from Windsurf is the overlap week. The vibe coding hub maps cousins. This essay is the pre-ads proof on a Cascade-built repo.
Stay in Windsurf. Close the doors first.
Windsurf is paid to make Cascade finish tonight. Paid traffic is paid to send strangers at a public URL. Those jobs collide. A green Preview tab can still leave a key in chat, a `.windsurf.build` host as the public origin, or an agent push to an open main branch.
Windsurf’s own docs draw the line. Cascade is an agent in the editor. Code mode writes the tree. Chat mode answers. It can search, call MCP tools, and run the terminal. You accept the steps. That is a workshop, not a host. It stays a lab until ads, mail, and Auth print the name you mean to keep.
Windsurf Previews open a local app in the IDE or a browser. You send elements and errors back to Cascade. The preview lives on your machine. App Deploys is the other door. Cascade uploads the project and prints a public `<SUBDOMAIN>.windsurf.build` URL. The vendor says those deploys are mainly for preview. For apps with sensitive data, claim the site. You do not need a new editor this week. You do need to name who can push, who holds secrets, and which URL ads will hit.
Rank the blast. Ads make a small leak big.
Start with the blast, not a prettier Cascade restyle. A stranger who dumps a table, burns a paid API from a public route, or clones a key from git will cost more than a new landing block. Rank those doors. Close the worst one tonight.
Blast rank — close the Windsurf top layer first
Off switch and restore
A prior host deploy you can republish — not a named Cascade checkpoint on one laptop.
CI absent
Install and start only work inside an open Windsurf window. No clean-checkout check.
Unreviewed Cascade diffs
Turbo accepted git push. No pull request. Force-push still allowed. Agent overwrote main.
Auth and row rules on the generated backend
Demo login. Open tables. RLS off. Anon grants left wide. Admin hidden only in the UI.
Preview vs .windsurf.build vs claimed host
Ads, mail, sitemap, and Auth redirects that still print localhost, a laptop Preview, or *.windsurf.build.
Secrets in chat, rules, MCP, and git
Keys in Cascade transcripts, memories, .windsurf/rules, AGENTS.md, mcp_config.json, or a committed .env.
Put six names on paper: who owns secrets, who proves login on the advertised host, who can push to main, who watches spend and errors, who owns the public origin, and who can restore a prior host deploy tonight. Two red names plus a campaign date means spend stays off. Soft CTA: if you cannot name a human for each layer, book.
Secrets: if Cascade saw it, treat it as leaked
Keys are the first thing ads will leak. Cascade reads what you paste. Memories and rules split the store. Auto memories live on the machine in `~/.codeium/windsurf/memories/`. They are not in git. Workspace rules live in `.devin/rules/` or the older `.windsurf/rules/`. Those files go with the repo. Root `AGENTS.md` is always on. Do not put a live token in a rule. A teammate clone then holds the same secret.
MCP config is the second drawer. The docs show a GitHub personal access token in `mcp_config.json` `env`. They also support `${env:VAR_NAME}` and `${file:/path}` so you do not hardcode the value. Use that. A PAT in a JSON file is still a PAT. Rotate anything that sat in plain text.
Ignore files is the vendor example to keep. Their sample `.devinignore` lists `*.pem` and `.env.local` under “Secrets and local config.” Paths in `.gitignore` are also blocked from agent edits. That is the floor, not a vault. A `.env` Cascade wrote and you committed is now in git history. Secret scanning will scan that history for known key shapes. Rotate first. History cleanup is extra work after the issuer is dead.
Using secrets in GitHub Actions is the host drawer you want. Repository, environment, or org secrets inject at run time. They do not live in the tree Cascade just edited. If App Deploys already pointed at Netlify, Netlify environment variables say the same: set values in the UI, CLI, or API — not the repo. Production and Deploy Previews can hold different values. Soft CTA: if the only place the key still lives is a Cascade thread you are afraid to open, book.
Preview and .windsurf.build leak into public links
Windsurf gives you several addresses that look live. They are not the same job.
Three live URLs — only one is the ad target
01 · Preview
Lab
Local process. IDE or browser tab. Dies when the laptop sleeps.
02 · *.windsurf.build
Preview host
Public App Deploy under Windsurf’s Netlify umbrella. Claim it or lose it.
03 · Claimed custom domain
Ads
The name you mean to keep. This is the only public origin.
Windsurf Previews is the lab: a local server, proxied into the editor. Listeners send selected elements back to Cascade. That is workshop evidence. It is not a campaign URL.
App Deploys prints `<SUBDOMAIN>.windsurf.build`. Cascade uploads your files to vendor servers, then deploys on Netlify under their account. You get a public URL and a claim link. Unclaimed deploys may be deleted. You cannot rename a `.windsurf.build` subdomain after the first deploy — you delete `windsurf_deployment.yaml` and ship a new site. The same page is blunt: only deploy code you are comfortable sharing in public. Stay-harden is fine if ads, mail, sitemap, and Auth print the claimed name. It is not fine if the campaign still lists `.windsurf.build` or a laptop Preview.
Search the tree for `windsurf.build`, `localhost`, and leftover Preview hosts. Check signup redirects and “view app” links in mail. Getting started still installs the same editor (docs now also say Devin Desktop). The installer does not make Preview a company.
Auth and row rules: a hidden admin page is not a gate
Rows are the next thing ads will leak. Cascade is good at wiring a sign-in screen. It is weaker at naming who may read a row after that screen. If the agent stood up a hosted Postgres — often Supabase — row level security is the server gate. A table in an exposed schema without RLS is open to any role with a grant. Adding a policy does not revoke default `anon` and `authenticated` grants. Prove both.
A demo login that only works inside Preview is a costume. The advertised host must sign a stranger in. Logout and expiry must work after a hard refresh. Admin must be a server check, not a role Cascade mixed into a client file. OAuth, magic links, and reset mail must land on the claimed host — not `localhost` and not `.windsurf.build`.
Run these four checks on the advertised host. A Preview pass with your editor session does not count:
- Every table that holds personal data or money has RLS on, and `anon` grants are named. A hidden admin route is not that proof.
- A stranger account cannot read another user’s row by changing an id in the URL or the API.
- Sign-up and sign-in work on the claimed host. Preview success is not that proof.
- Service-role or admin keys never shipped to the browser. Those keys skip row rules.
Unreviewed Cascade diffs are a write API on your repo
Cascade can change many files in one plan. Cascade keeps a todo list and calls tools until the limit. Two Cascades on the same file can race. Reverts undo local edits back to a step. The docs say those reverts are currently irreversible. That is a laptop undo. It is not branch protection.
Terminal auto-execution has four levels: Disabled, Allowlist Only, Auto, and Turbo. Turbo runs every command except the deny list. An allow entry of `git *` auto-runs `git add -A`. The dedicated agent terminal also loads your shell config, so env from `.zshrc` or `.bashrc` is in reach. Turbo plus a live key in the shell is how a “small fix” ships a secret and a force-push in one breath.
About protected branches is the remote lock. Require reviews. Require status checks. Keep force-push off. Restrict who can push to `main`. A Cascade commit from one laptop is not that lock. If the org remote still allows a direct push of whatever the agent wrote, ads wait.
Cascade Hooks can block a file read or a command before it runs. A pre-hook that exits `2` stops the action. Workspace hooks live in `.devin/hooks.json` (or older `.windsurf/hooks.json`) and can ride with the repo. Use them if you stay in Windsurf. They do not replace a required review on GitHub.
Off switch: a named checkpoint is not a host rollback
A bad release needs an off switch you can name tonight. Cascade lets you revert to a prompt or a named checkpoint. That restores the local tree. It does not take a public `.windsurf.build` or claimed Netlify site back.
App Deploys tells you to claim the project for logs, domain, and provider control. After you claim, rollback is a prior Netlify deploy — or a prior GitHub Actions deploy if CI already ships from the org remote. “We will open Windsurf and undo Cascade” waits on one laptop and one agent. It is repair. It is not an off switch.
Name the deploy owner. Prove you can restore a prior host version. A feature flag is extra. It does not replace a version you can republish in minutes.
Watching: errors, spend, and a silent Preview
Watching without an off switch is half a lock. Before ads, name three signals: auth failures on the advertised host, 5xx after a Cascade ship, and paid-API or host spend. App Deploys apply rate limits by plan. That is vendor abuse control, not your product meter. If nobody owns the first 24 hours of spend, the campaign stays off.
A clean checkout is the other watch. Clone the org remote on a machine without Windsurf. Install. Build. Start with host-injected secrets. If that path fails, Cascade is still the runtime. CI/CD after an AI builder is the later essay. This page only asks: does a second machine boot without an open Cascade window?
Wrap score — mark costume vs proof
Secrets
Costume
Key in chat
Wrap
Moved to host env
Proof
Rotated + not in git
Public name
Costume
Ads list .windsurf.build
Wrap
Claimed, old links live
Proof
Sitemap + Auth match
Auth / rows
Costume
Hidden admin page
Wrap
RLS listed
Proof
Stranger cannot find rows
Review
Costume
Turbo push to main
Wrap
PR opened once
Proof
Protected main + review
CI
Costume
Only Windsurf starts it
Wrap
Script in repo
Proof
Clean checkout boots
Off / watch
Costume
“Revert Cascade”
Wrap
Prior deploy known
Proof
Host rollback hit once
Score each row against the advertised host, not Preview. One red cell — a key in chat, a `.windsurf.build` in ads, an open table, an unprotected main, a start path that needs Windsurf, or a rollback you have never hit — is enough to hold the spend. Move that cell. Do not greenwash the matrix.
The pre-ads week
Treat the next seven days as operator time on the Cascade repo, not a slogan. Inventory who can push, who holds secrets, and which URL ads will hit. Then seal. Then prove. Leave the editor-exit pages closed until that list is honest.
Harden on Windsurf — seven operator steps
01 →
Inventory the public path
Who can push. Who is admin. Which URL ads will hit. Where Cascade secrets still live.
02 →
Seal secrets
Drain chat, rules, memories, MCP JSON, and committed env. Rotate. Host-inject the new values.
03 →
Lock auth and rows
Stranger cannot find another user’s row. Login works on the claimed host.
04 →
Protect main
Required review. Status checks. No force-push of whatever Cascade produced.
05 →
Fix the URL map
Redirects, Auth callbacks, sitemap origin. No Preview or .windsurf.build in ads.
06 →
Name CI and watch
Clean checkout builds. Who sees 5xx, auth fails, and paid-API spend.
07
Rollback + watch, then buy
Prior host deploy restored once. Then spend.
Day 0 is inventory. Write five facts. The public URL. The person who can push to main. Whether a live key still sits in Cascade chat, a rule file, or git. Whether a stranger can read another user’s row. Whether a prior host deploy can come back tonight. If the public origin is already taking leads and you cannot name those five, stop. You do not need a new page. You need this list.
Seal secrets first. Then rows. Then review. Bots do not wait for DNS. If a public API exists, prove it fails closed without a session. Then strip `.windsurf.build` hosts. Then restore a prior host deploy once so you know the off switch works. Then spend. The Windsurf MVP hardening clipboard is the short list. This page is the week you run it.
Illustrative operator days before a Windsurf ad buy
daysUnpriced Ads on a red list
3–5 wks
Campaign live. Doors still open. Cleanup later.
Illustrative operator days — not measured traffic, not a Source: Admin analytics series. Unpriced feature sprints on a public Cascade app often cost more than the wrap when the first leak hits.
Treat those bars as calendar you reserve, not a vendor promise. If you cannot name the advertised host, who can push, and who can restore a prior deploy, the later days will thrash. The long bar is the expensive miss: a “small” test while `.windsurf.build` or an open table is still the company.
Stay-harden vs leave. Do not mix the seats.
Pick one seat for this week. Stay-harden keeps Windsurf as the studio, with secrets out of chat, a claimed host as the origin, protected main, and a host rollback already proved. Leave opens get-off Windsurf and stops buying clicks that need that editor window. Running both seats at once is how teams rebuild pages they already had.
Stay-harden vs exit — pick one seat
Stay-harden (this page)
Studio still in Windsurf
Cascade still plans. You accept the agent and the bill.
Doors closed on that path
Secrets, origin, auth, review, CI, rollback.
Ads wait for green
A red layer pauses spend, not the product.
If the public origin must leave Windsurf preview and App Deploys, stop this wrap and open the exit. If ads are close and the origin can stay on a claimed host, finish the wrap first. ↓If the public origin must leave Windsurf preview and App Deploys, stop this wrap and open the exit. If ads are close and the origin can stay on a claimed host, finish the wrap first.
Leave (other pages)
Process leaves Windsurf preview
Org Git plus a host you run. See get-off and migrate.
A claimed domain is not the exit
DNS on a claimed Netlify site is still that vendor path until CI owns ship.
Kill the Windsurf-only ship
App still answers when the editor is closed.
If you only need a leave date, use when to leave an AI builder. A door that will not close belongs on rewrite vs harden. A personal Git remote belongs on GitHub handoff. A laptop-only ship path belongs on CI/CD after an AI builder. Cousin wraps: Bubble, Framer, Softgen, Lovable, Replit, v0, and Bolt. Those pages are not this Cascade week.
Wrap loop — prove, then decide
01
Prove the door
One layer. One test on the advertised host.
02
Close it
Rotate, redirect, add RLS, protect main, or restore a prior deploy.
03
Re-check ads list
If a layer is still red, spend stays off.
04 · loops
Stay or leave
Green wrap can stay. Red host row opens the exit.
When the list turns red
Leave the product up. Kill the campaign if any of these are still true:
- A live key still exists only in Cascade chat, a memory, a rule file, MCP JSON, or a committed env file.
- A table that holds personal data or money is still readable without a named row rule.
- Ads, mail, or the sitemap still list a Preview host, `localhost`, or `*.windsurf.build`.
- Main still accepts a direct Cascade push, or Turbo can `git push` without a review.
- The app will not boot from a clean checkout with host-injected secrets.
- The off switch is “we will revert Cascade,” or you have never restored a prior host deploy.
- Two people disagree about who can push or who holds admin.
A single red door is a miss, even if Preview is green. Stop adding pages until secrets, row rules, protected main, and the host rollback are honest. Finish that wrap. Then spend — or open get-off Windsurf if the editor is still the company.
Bring a second pair of hands when the founder cannot rotate a key without pasting it back into Cascade, when a stranger can still find another user’s row, or when nobody has restored a prior host deploy before the date. Hire for secrets, row rules, Git seats, and the URL map — not a prettier Cascade screen. Austin app development company is the studio brief. Austin mobile app development if the next door is a store binary that still points at this Windsurf URL.
Next steps
Walk the gates in order. Inventory the public URL, the person who can push, and who holds admin. Drain Cascade chat, rules, memories, and MCP secrets into host env. Rotate anything that appeared there. Fail-close row rules on every table that holds personal data. Require review on main. Strip Preview hosts and leftover `.windsurf.build` names from ads, mail, sitemap, and Auth. Prove a clean checkout. Restore a prior host deploy once. Then buy the click — or open the exit if the process itself must leave Windsurf.
CodeCross LLC is an Austin-registered product studio (1606 Headway Cir STE 9212, Austin, TX). The Windsurf week we run is chat-and-git secrets, claimed-host origin, auth and row locks, protected main, then a host rollback. The Austin app development company page is the studio brief. Austin mobile app development is the store-binary door if a signed build still points at this Windsurf URL. Company-level evidence lives on proof. When the off switch, secret drawers, or the advertised host is still red, book a conversation.
Windsurf is allowed to stay the studio. Ads are not allowed to treat a Preview pass, a `.windsurf.build` URL, or a Turbo push as that proof. Show a prior host deploy you can restore, row rules that fail closed for strangers, and keys that never lived in Cascade chat. Most teams never need a second codebase once those three exist.
FAQ
When Preview looks good, did production receive the same data?
No. Windsurf Previews open a local process. App Deploys upload a copy to vendor servers and print a preview URL. Local rows, laptop env, and a warm Cascade session do not move with that click. Prove the money path on the advertised host with stranger-like accounts.
Does claiming a .windsurf.build site finish the wrap?
No. App Deploys say claiming gives you provider control, logs, and a chance to change the Netlify name. The vendor still calls the feature preview-first. Unclaimed sites may vanish. Stay-harden is fine if ads, mail, sitemap, and Auth redirects print the name you mean to keep. It is not fine if the campaign still lists the lab host. Leaving Windsurf as the ship path is the get-off job, not this page.
If Preview can find a row, does that search exist on the advertised host for a stranger?
Not as proof. Your editor session is not a stranger. Row level security applies in the database, not in a hidden page. A Preview pass can look closed while `anon` still holds a grant. Prove a private-window account on the advertised host cannot find another user’s row.
Can I paste keys into Cascade rules and buy ads?
No. Memories and rules put workspace rules in the repo. MCP config should interpolate `${env:…}` or `${file:…}` instead of a raw token. Ignore files exist so `.env.local` never sits in the agent’s reach. Rotate anything that appeared in chat, rules, or git. Do not buy ads on a red drawer.
Can strangers write rows if I hid the admin page?
Hiding a link is not a lock. Row rules and grants govern read and write. A public API Cascade wired with no session check is a write API. A service-role key in the browser skips those rules. Row level security is the seat list. A shared admin login is a miss.
Is “we will revert Cascade” an off switch?
No. Cascade reverts local edits to a prompt or a named checkpoint. Those reverts are currently irreversible on the laptop, and they do not republish a host. App Deploys want a claimed provider account for real logs and rollback. Name the deploy owner. Hit a prior host version once before ads.
Does Turbo mode plus a green terminal mean ads are safe?
No. Terminal Turbo auto-runs every command except the deny list. An allow of `git *` includes `git add -A`. Protected branches are what stop that push from becoming production. A green terminal on one machine is a lab. Protect main. Require a review. Then talk about spend.
Thirty minutes with a senior teammate — honest next steps.
Ready to price an Austin build?
Bring the problem, the users, and a budget ceiling. We’ll tell you whether an app is the right next spend — and what the first year actually costs.
Prefer writing? Send project details on the contact page.