Is your AI-built app ready for real users?
It works. People are using it. And nobody has ever checked what happens when it does not — when the database fills up, when the deploy fails at 6pm on a Friday, when someone types an apostrophe into a form. This is that check, written down, for a fixed price.
$450 report in five working days
Who this is for
You built something with an AI tool — or someone did it for you — and it is running. It might be on Vercel, Railway, Render, Fly, Supabase, a server somebody set up once, or something you could not name if asked. It demos perfectly. Real users are on it now.
What you do not have is anyone who has read it end to end and said, in writing, what is wrong and what it costs to fix. That is the whole of this service.
Why AI-built apps break in the same places
The tools that make building fast are optimised for getting something on screen, not for keeping it up. They rarely produce the parts nobody demos: the restart when it crashes, the backup you have actually restored from, the certificate renewal, the way back to the last working version when an update breaks it.
This is measurable, not folklore. A 2026 audit by Escape of 5,600 publicly reachable AI-built applications reported over 2,000 vulnerabilities, more than 400 exposed secrets, and 175 cases of personal data sitting in the open. Not because the people who built them were careless — because nothing in the build asked.
What we actually do
We read the codebase and the environment it runs in. Not a scan — a person reading it, with tools where tools help.
- What is exposed: secrets in the repository or in the client bundle, endpoints with no authorisation, personal data reachable by anyone who guesses a URL.
- What happens when it falls over: whether it restarts, whether anyone finds out, and whether you would know before a customer told you.
- Whether your data survives: what is backed up, how often, and whether a restore has ever been performed — an untested backup is not a backup.
- How a change reaches production, and how it gets undone when it is wrong.
- The things that expire on their own: certificates, tokens, paid plans, free tiers.
- What it costs to run now, and what it costs at ten times the traffic.
What you get
Five to ten pages in plain language, ordered by what would hurt first. Every item says what is wrong, what happens if it stays that way, and what the fix costs as a number.
It is yours whether or not you hire us for any of it. Several people have taken the report to their own developer, which is a fine outcome — the point is that somebody has read it.
Price and scope
$450 for one codebase and one environment. Five working days from the moment we have access. If your setup is larger than that we say so before taking any money, not after.
The $450 comes off anything you book within 90 days, so if the report ends in work, the check was free.
Questions people ask first
Do I have to give you access to my code?
Yes — read access to the repository and to wherever it runs. We cannot tell you what breaks first by looking at the outside of it. Access is read-only unless you ask for something to be fixed, and it is handed back when the report is delivered.
What if the report says everything is fine?
Then it says that, and you have written confirmation from someone with no reason to invent work. It has not happened yet on a first check, but it would be a good outcome.
Is this a security audit?
It covers security, but it is broader and shallower than a formal audit. It answers "what will hurt me first", not "prove this is compliant". If you need a certification for a customer or an insurer, this is not that document.
I did not build it myself. Can you still do it?
That is the more common case. You do not need to understand the code — the report is written to be read by whoever owns the business, not by whoever wrote the software.
Ask about this A written answer within one working day. Sending it commits you to nothing.
The rest of what we do
- Make it production-ready — For something that was built quickly and now has people depending on it. One fixed number, agreed before any w…
- Keep it running — The part nobody wants to own. Your app is live and someone has to notice when it stops, renew the things that …
- Build in stages — From an idea, or from a project that stalled. Priced one stage ahead and paid per stage, and you own everythin…
- The checklist — This is the list we work through on a paid check, published because most of it you can do yourself in an after…
- Our own products — what we build for ourselves, and run.