Production-readiness audit for fast-built and AI-built apps
Your app was built fast — with Lovable, Bolt, Cursor, an agency or a weekend of heroics — and now real users are finding its limits. A fixed-fee audit tells you what will break first and what to fix, in order.
Who this is for
You have a product that works in a demo and has real users now: paying customers, a pilot with a client, or a launch date. It was built quickly, maybe mostly by an AI coding tool, and nobody has looked at it with production in mind. Things like:
- Users sometimes see data that isn't theirs, or you're not sure they can't.
- Payments work, except when they don't, and nobody can say why an order is stuck.
- Deploys are a person running commands, and rolling back means hoping.
- There are no backups you've actually restored, and no alerts before customers complain.
What I check
- Access and data isolation. Authentication, authorization on every route and query, tenant isolation, secrets in the repo or the frontend bundle.
- Money paths. Checkout, webhooks, idempotency, what happens when a provider times out or calls you twice, and whether every payment is recorded before anything else changes.
- Data safety. Migrations, backups and whether a restore has ever been tested, and anything that deletes or overwrites data without a trail.
- Operations. How code gets to production, how it gets rolled back, logging, error tracking, and what tells you it's down.
- The code agents wrote. Duplicated logic, dead paths, tests that assert nothing, and dependencies nobody chose on purpose.
What you get
- A written report: each issue, why it matters in plain language, how to reproduce or verify it, and the fix.
- A priority order: what to fix this week, this month, and what can wait.
- A call to walk through it.
Why me
Since 2023 I've run software that handles real money: the backend of Odigix (30,000+ registered users, SlickPay and OneClick payments, idempotent delivery from rate-limited third-party suppliers) and Rooqn's wholesale ledger. I use coding agents every day, so I know both what they're good at and where they quietly cut corners.
Questions clients ask
- What does the audit cost?
- It's a fixed fee agreed before any work starts, based on the size of the codebase and how many systems it touches. After a short call I send you the price and the scope in writing. No hourly meter.
- Which stacks do you audit?
- Laravel, Vue/Inertia, React/Next.js and Node/TypeScript backends on PostgreSQL or MySQL — the stacks I build and run in production. If your app is on something else, I'll say so on the first call rather than learn on your budget.
- Do you fix the problems too?
- If you want. The report is yours either way and written so any competent developer can act on it. Most clients ask me to fix the top items, then decide on the rest.
- Do I need to give you production access?
- No. Read access to the repository and a copy of the environment variable names (not the values) is enough to start. For database or infrastructure checks, a read-only account or a sanitized copy works.
Building something similar?
Tell me where you are and what's blocking you. I'll give you an honest read on how I'd approach it.