A report organized by severity
Sorted by what could actually hurt you, not by which file it happens to live in.
A fixed-price review of the app you built with AI tools: security holes, data exposure, and the things that break the first time real users show up. Written in plain English, with a ranked list of what to fix first.
AI tools got you a working app faster than you could have built one yourself. That part is real, and anyone telling you otherwise hasn’t tried it lately.
What they didn’t do is tell you where it leaks. The app runs, the demo works, and the parts that actually matter — who can read your database, what happens when a request fails, whether your API keys shipped to the browser — were never reviewed by anyone. Not by you, and not by the model, which was optimizing for “it works now”.
It’s rarely exotic. It’s an auth check that only runs in the browser. It’s a database rule set to allow-all at 2am because that’s what unblocked you, and nobody went back. It’s an API key in the frontend bundle with no spend cap on it.
You don’t need to become a developer to fix these. You need someone to tell you which ones are real, which ones matter, and in what order.
Sorted by what could actually hurt you, not by which file it happens to live in.
What it is, what could realistically happen because of it, and the exact file and line where it lives.
What to fix before you launch, what can wait until you have real users, and what’s genuinely fine to ignore. The third list is usually longer than people expect.
Each finding comes with a prompt written for Claude Code or Cursor, so you can do the work the same way you built it.
Recorded, so you can send it to whoever helps you.
Once you’ve made the critical fixes, we confirm they’re actually fixed. Included in the price.
A GitHub invite, GitLab, or a zip file — whatever you have. Read-only access is fine. We never need production credentials, and if anyone ever asks you for those, that’s its own finding.
We run analysis agents across every route, every data-access path, and every dependency. This is the part that used to take a week of billable hours.
Agents over-report. We cut the noise, confirm what’s real, and check the things agents are bad at: business logic, and whether your data rules actually do what you think they do.
5 business days from the moment we have access. If we find something urgent on day one, you hear about it on day one.
A repo invite or a zip file. Never production credentials, never a password.
That protects your code, and it also contains anything hostile sitting inside it. A repo can carry prompt injection, planted deliberately or pulled in accidentally through a dependency. An agent with network access reading an untrusted codebase is a bad idea, so ours doesn’t have any.
We use a single provider, on commercial terms that prohibit training on your data and enforce zero retention. We’ll name the provider and send you their data-processing terms on request, before you pay.
We revoke access and destroy local copies within 7 days of that window closing. We hold it that long only because the re-check above is part of what you paid for.
We’ll sign yours or send you ours, whichever is less work for you.
$1,500
Fixed. Delivered in 5 business days. No hourly rate, no scope creep, no second invoice.
One repository, up to roughly 50,000 lines. Bigger than that, or a multi-service system? Tell us in the form and we’ll quote it before you pay anything.
Our agent tooling does the exhaustive pass — every file, every route, every dependency. That part is genuinely faster than a human, and it’s why these are fixed-price instead of hourly.
Then we read every finding before it reaches you. Agents over-report. They flag things that are technically true and practically irrelevant, and they miss things that need knowing what your business actually does. Cutting the noise is the job.
You’re not buying an agent’s output. You’re buying what’s left after someone checked it.
If we get into your codebase and genuinely find nothing that warrants a report, we’ll tell you so and refund you in full.
The audit is diagnosis, not repair. The report is written so that you, or the AI tools you already use, can do the fixes, and most people do exactly that. If you’d rather we did them, we’ll quote that separately once we both know the size of the job.
No. Every finding leads with a plain-English explanation of what’s at stake. The file-and-line detail sits underneath for whoever ends up doing the fixing, which might be you and an AI tool.
That’s one name for it, yes. Whether the app came out of Lovable, Replit, Bolt, v0, Cursor or Claude Code, the questions are the same: who can read your data, what shipped to the browser, and what breaks the first time real traffic arrives. We don’t care which tool wrote it.
No, and we’ll say so plainly. We’re reading your code, not attacking your running system. A pen test tells you what an attacker can do from outside. This tells you where the weaknesses are and why they exist. If a customer or an insurer is demanding a formal pen test, this isn’t a substitute, and we’ll point you to someone who does them.
Everything we look at was written by somebody’s AI in a hurry. We’re not grading you and we’re not going to tell you to rewrite it properly. We’re telling you what to fix.
Yes. We’ll sign your NDA, or send you ours, whichever is less work for you. Your code runs through a sandbox with no outbound network access, it goes to one model provider under no-training and zero-retention terms, and we delete it once the 30-day re-check window closes.
The code, and ideally read-only visibility into your database rules or config — Supabase, Firebase, whatever you’re on. Never production credentials, and never a password.
The common ones: JavaScript and TypeScript, React, Next.js, Node, Python, and the usual hosted backends like Supabase, Firebase, Vercel, and Postgres. If you’re on something unusual, say so in the form and we’ll give you a straight yes or no before you pay.
You get an email the same day we find it. We’re not sitting on a critical issue for 5 days so it can appear in a nicely formatted report.
Once we’ve confirmed the work is a fit, we send an invoice with a payment link. Work starts the day it clears. No deposit, no retainer, no contract minimum.
Looking at the other one? Read about the Workflow Audit, or compare both audits.
Takes about 2 minutes. We reply within one business day, either a yes with a payment link or an honest “this isn’t a fit for you”.