01 What actually fits in a week?
One product with one core workflow, done properly: accounts, roles, payments, an admin view and a couple of integrations. Most first versions fit once they’re scoped honestly. We decide it together on the scoping call, before you pay anything.
02 What if my idea is bigger than a week?
We’ll tell you on the call. Usually we split it: a first week that ships something real, then further weeks quoted separately. Each one has its own fixed scope and price, so you can stop after any of them.
03 Who owns the code?
You do, from the first commit. We build in your repository, on hosting and accounts in your name, and nothing of ours is left behind that you need us to maintain.
04 What happens after launch?
You get a written handover, and you can run the product yourself or hire anyone to extend it. If you’d rather we stay on, the Care plan covers monitoring, updates and a few hours of fixes every month.
05 How does payment work?
Half to book the week, half on launch day, invoiced in US dollars. The audit is paid up front. The price is fixed when you book; only a change of scope changes it, and that is always a new quote you agree to first.
06 You’re in India — how do time zones work?
We work async with teams in the US and Europe, with a daily overlap window for calls. In practice you review the day’s preview in your morning and your feedback is in the build by the next one.
07 What don’t you do?
Brand identity, content writing, marketing and paid growth. We don’t run penetration tests or issue compliance certificates. And we don’t take on a week we don’t believe fits in a week.
08 What if the audit finds nothing serious?
Then it’s free. If the report contains no material finding — nothing that would expose data, lose money, break a deploy or block a store submission — we don’t invoice it, and you keep the report.
09 What access do you need to run an audit?
Read-only to start: your repository, and viewer access to your hosting and database dashboards. We don’t need write access, production credentials or customer data to produce the report. Write access is only requested at the start of a fix sprint, and it can be revoked the day it ends.
10 Can you work on an app built with a platform I’m locked into?
Usually, yes. We work on Lovable, Bolt, Replit, Cursor, v0 and Base44 output, and on the Supabase, Firebase, Neon and Postgres backends behind them. Where a platform makes part of the stack unreachable, the audit says which findings can’t be fixed without moving off it, and what moving would involve.
11 Can you guarantee the App Store will approve my app?
No, and nobody can. Approval is Apple’s and Google’s decision. We cover everything on our side of that line: packaging, SDK requirements, privacy details and data-safety answers, store metadata, and responding to review feedback until the app is through.
12 Do you use AI to build?
Yes. AI tools speed up the typing, and a senior engineer designs, reviews and tests every line that ships. That combination is why a week is enough.
13 What tech stack do you use? Can I choose?
Our defaults are proven and widely supported: TypeScript, React and Next.js, Postgres and Supabase, React Native and Expo. If you have a strong reason for something else, tell us on the call.
14 Can you work from my Figma or existing designs?
Yes. It usually makes the week faster. If you have no designs, Day 1 includes simple, clean screens we agree on together.
15 Can you take over a codebase someone else started?
Usually. Start with the audit, so we both know what we’re inheriting before we quote.
16 What do you need from me during the week?
About 20 minutes a day, account access, and feedback within one business day. The full list is in “Your part of the week.”
17 What if I want to change something mid-week?
Small adjustments inside the agreed scope are part of the process. Anything new goes on a list for week two, quoted separately, so the launch date holds.
18 Do you sign NDAs?
Yes, before we see anything confidential.
19 Can you build for healthcare or finance?
We build with strong security practices, but we don’t run formal compliance programs such as HIPAA or SOC 2. If you need those, we’ll say so up front.