PutThrough Product engineering studio
Book a build call

Product engineering studio

Idea to production, in a week.

We design, build and ship web apps, websites, mobile apps, AI agents and internal tools in about seven days. Not a prototype: security, payments, deployment and monitoring are in from day one — so it’s a product you can put real customers through.

See how the week works We take one build at a time, so each week gets full attention.

  • Fixed scope, agreed before day one
  • Fixed price, quoted up front
  • Your code and accounts from the start

Already built something with AI? Start with an audit instead

  • Web
    • TypeScript
    • React
    • Next.js
    • Astro
    • Tailwind CSS
    • Vite
    • JavaScript
    • Remix
    • SvelteKit
    • Vue 3
    • Nuxt
    • shadcn/ui
    • Radix UI
    • TanStack Query
    • TanStack Table
    • React Hook Form
    • Zod
    • Zustand
    • Redux Toolkit
    • Framer Motion
    • MDX
    • Storybook
    • Vitest
    • Playwright
    • Testing Library
    • ESLint
    • Prettier
    • Recharts
    • D3
  • API
    • Node.js
    • Python
    • REST
    • tRPC
    • Hono
    • Fastify
    • Express
    • NestJS
    • FastAPI
    • Django
    • GraphQL
    • OpenAPI
    • WebSockets
    • Server-sent events
    • BullMQ
    • Celery
    • Inngest
    • Trigger.dev
    • Stripe
    • Paddle
    • Razorpay
    • Resend
    • Postmark
    • Twilio
  • Data
    • Postgres
    • Supabase
    • Redis
    • Neon
    • PlanetScale
    • MySQL
    • SQLite
    • Turso
    • Firebase Firestore
    • Upstash
    • Drizzle ORM
    • Prisma
    • Kysely
    • pgvector
    • Meilisearch
    • Typesense
    • Elasticsearch
    • S3
    • Cloudflare R2
  • App
    • React Native
    • Expo
    • EAS Build
    • Swift
    • Kotlin
    • Capacitor
    • Flutter
    • SwiftUI
    • Jetpack Compose
    • Expo Router
    • React Navigation
    • Reanimated
    • MMKV
    • WatermelonDB
    • StoreKit
    • Google Play Billing
    • RevenueCat
    • APNs
    • Firebase Cloud Messaging
    • Expo Notifications
    • Fastlane
    • App Store Connect
    • Google Play Console
    • Detox
    • Maestro
  • Ops
    • Vercel
    • Cloudflare
    • Docker
    • GitHub Actions
    • Sentry
    • AWS
    • Cloudflare Workers
    • Cloudflare D1
    • Fly.io
    • Railway
    • Render
    • Terraform
    • Nginx
    • Caddy
    • GitLab CI
    • Grafana
    • Prometheus
    • Axiom
    • Better Stack
    • Checkly
  • AI
    • Claude
    • OpenAI
    • MCP
    • Gemini
    • OpenRouter
    • LiteLLM
    • Vercel AI SDK
    • Anthropic SDK
    • Qdrant
    • Pinecone
    • Chroma
    • Langfuse
    • LangSmith
    • Braintrust
    • Helicone
    • Ollama
    • vLLM

01The gap

Building got easy. Shipping didn’t.

A few years ago, turning an idea into software meant a months-long agency project or finding a technical cofounder. Today an AI tool can produce a convincing demo in an afternoon. But a demo isn’t a product. The work that decides whether real customers can trust it is still skilled engineering: who can see which data, what happens when a payment fails, how you recover from a bad deploy. And it’s exactly the part AI tools skip.

  1. 01

    The agency route

    Discovery workshops, a proposal, and a launch date months away. Often built well, but priced and paced for companies with time to spare.

  2. 02

    The freelancer route

    Faster and cheaper, until availability changes or the one person who understands your codebase moves on.

  3. 03

    The do-it-yourself route

    An AI tool gets you a working demo. Then come the security, payment and deployment problems it quietly left behind.

PutThrough is the fourth route: senior engineering, a fixed scope, and a product that’s genuinely live in about a week.

02Who we work with

Built for people with more ideas than time.

  • Founders testing an idea

    You need something real in front of customers, not a clickable mockup, before you raise, hire, or quit your job.

  • Small businesses outgrowing spreadsheets

    Bookings, orders, clients or inventory spread across five tools and a spreadsheet. One internal tool, shaped around how you actually work.

  • Teams that want an AI agent

    An assistant that answers from your data and takes actions in your tools, with guardrails, logging and a monthly cost ceiling. Not a demo that makes things up.

  • Founders with an AI-built app

    It demos beautifully, but you’re not sure it’s safe to launch.

    Start with the audit

03What we build

Seven kinds of product. One standard for all of them.

Whatever the shape, it ships with accounts, permissions, payments where you need them, and the operational layer most first versions skip.

In every build, whatever the kind

  • Accounts and roles
  • Payments where you need them
  • An admin view
  • Monitoring and alerts
  • Tested backups
  • Your code, your accounts
  1. 01

    Web apps

    SaaS products, dashboards and customer portals — with accounts, roles and billing.

    For example client portals · SaaS MVPs · booking and scheduling systems · marketplaces · member dashboards

    More on web apps
  2. 02

    Websites

    Fast, accessible marketing and content sites your team can edit without us.

    For example launch sites · product marketing sites · content sites your team edits without us

    More on websites
  3. 03

    Mobile apps

    iOS and Android, built and submitted inside the week, then taken through store review.

    For example companion apps for your web product · ordering and booking apps · field-team tools

    More on mobile apps
  4. 04

    AI agents

    Assistants that answer from your data and act through your tools, with guardrails and a cost ceiling.

    For example customer support agents · lead qualification · document and inbox triage · internal knowledge assistants

    More on AI agents
  5. 05

    CRMs & internal tools

    Pipelines, admin panels and back-office tools shaped around how your team actually works.

    For example sales pipelines · admin panels · inventory and order tracking · approval workflows

    More on CRMs and internal tools
  6. 06

    AI automations

    Repetitive work handed to software: documents read, data moved between your tools and requests routed, with a person in the loop wherever a mistake would matter.

    For example invoice and document processing · CRM and spreadsheet syncing · lead enrichment and routing · scheduled reports · onboarding workflows

    More on AI automations
  7. 07

    Custom software

    For the process nothing off the shelf fits: systems built around how your business actually runs. Bigger ones are planned as a series of one-week milestones, each shipping something usable.

    For example booking and dispatch systems · quoting and estimating tools · partner and supplier portals · integrations and APIs between your tools

Not sure which one yours is? We’ll work it out on the call.

Prefer to write? Send your requirements

04How we think

Six rules we don’t break.

Speed without judgment is how most first versions end up rebuilt. These are the rules that keep a one-week build from turning into a one-month problem.

  1. Scope is a promise.

    We cut the idea down to what genuinely fits in a week, write it down, and hold to it. Scope creep is how one week quietly becomes three.

  2. Production from the first commit.

    Access control, payments, deployment and monitoring are designed in on day one, not bolted on after launch.

  3. Build in the open.

    A written update and a live preview link every evening. You never wait until the end to see what you’re paying for.

  4. You own everything.

    Your repository, your hosting, your accounts, your billing. Nothing of ours that you’d need us to keep running.

  5. Proven technology where it counts.

    Well-supported frameworks and managed services, so the next engineer can pick it up without us.

  6. Honest over agreeable.

    If your idea doesn’t fit in a week, or shouldn’t be built the way you imagined, we’ll tell you on the first call.

05How the week works

Seven days, planned before the first one starts.

The week is fast because the thinking happens first. By the time we write code, the scope is written down, priced, and agreed by both of us.

  1. 0 Day 0

    Scoping call and fixed quote

    We talk through the idea, cut it down to what fits in a week, and write it up. You get a fixed price before you commit to anything.

    You get Written scope and a fixed quote

  2. 1 Day 1

    Spec and design

    Data model, screens and user flows, agreed in writing. This is the last day the scope can change without a new quote.

    You get Signed-off spec and screen designs

  3. 2–5 Days 2–5

    Build, in the open

    We build in your repository. Every evening you get a short written update and a preview link you can click through.

    You get A daily update and a live preview

  4. 6 Day 6

    Harden

    Security, payments and QA: access rules tested, webhooks verified, error states handled, backups restored, monitoring switched on.

    You get The production checklist, passed

  5. 7 Day 7

    Launch and handover Live

    Production deploy on your domain, then a written handover covering how it works, how to change it, and what to watch.

    You get A live product and a handover document

What fits in a week

  • One core workflow, done properly
  • Accounts, roles and billing
  • An admin view for your team
  • Two or three integrations you already use
  • A landing page alongside the product

What doesn’t

  • Several separate products at once
  • Heavy offline, hardware or real-time work
  • Formal compliance programs such as HIPAA or SOC 2
  • Large migrations out of a legacy system

If it doesn’t fit, we say so on the call and quote it as two weeks or more — never as one week that quietly becomes three. Mobile apps are built and submitted within the week; review then takes as long as Apple and Google take.

Your part of the week

A one-week build needs a decision-maker, not a committee. Here’s what we’ll ask of you.

  • 20 minutes a day to review the preview and answer questions
  • Access to the accounts the product needs: domain, hosting, Stripe, and app store developer accounts for mobile
  • Your logo, brand colors and any content, by Day 1
  • Feedback within one business day, so the week doesn’t stall

06Day 7

What you walk away with.

Launch day isn’t just a URL. It’s everything you need to run, change and grow the product, with or without us.

handover/ Day 7 · Live
  • The live product On your own domain, in production.

  • Full source code In your repository, with the complete commit history.

  • A written handover How it’s built, how to change common things, and where the risks are.

  • A recorded walkthrough Of the codebase and the admin tools.

  • Every account and credential In your name.

  • The production checklist Completed and signed off.

  • An optional care plan For what comes next.

07Production-ready, not a prototype

We build against the checklist we audit other people’s apps with.

Apps built with AI coding tools tend to fail in the same well-documented ways. Every build is checked against that list before launch — not after your first incident.

See the standard in a sample audit report
production-checklist All checks passing
  • Access control

    Every table and endpoint checks who is asking, on the server. Tested, not assumed.

  • Payments

    Webhooks verified and idempotent. Refunds, failures and cancellations handled.

  • Deploys

    Separate staging and production, and a rollback we have actually run.

  • Monitoring

    Errors and uptime alert you from launch day, not from your first complaint.

  • Backups

    Automated, and restored once before handover to prove they work.

  • Store compliance

    Current iOS and Android SDK floors, privacy manifests and data-safety forms.

08How we compare

Choosing how to build it.

Every route has its place. Here’s an honest comparison.

Four ways to build a first version, compared
Typical agency Freelancer DIY with AI tools PutThrough
Time to launch Months Weeks to months Days, as a demo About a week
Price Large, often changes Usually hourly Tool subscriptions Fixed, agreed up front
Production-ready Usually Varies Rarely Checked against a written list
Code ownership Usually yours Varies Yours Yours from the first commit
Communication Account manager Varies Not applicable Daily written updates
After launch Retainer Depends on availability On you Warranty, then optional care

09Pricing

Ways to work together.

  • One-week build

    One core workflow, done properly and launched. For MVPs, internal tools, agents and websites.

    Book a build call
  • Extended build 2–4 weeks

    Quoted per milestone

    Bigger products, planned as a sequence of one-week milestones. Each one ships something usable, and you can stop after any of them.

    Talk it through
  • Care plan

    from $499 /mo

    Monitoring, updates, store deadlines and a few hours of changes every month.

    See what’s covered
  • Audit & fix

    Audit $349 web + mobile $499

    For apps you already built with AI tools.

    Start with the audit

Full pricing

10After launch

Launch is day one, not the finish line.

Real users find things demos never do.

Over time, most products need three things:

  • Small improvements as feedback arrives
  • Dependency and security updates
  • For mobile, keeping up with Apple’s and Google’s yearly requirements

The care plan covers all three for a fixed monthly fee. Or take the handover document and run it yourself. It’s written so you can.

See the care plan
  1. Launch Day 7
  2. Care plan or run it yourself Your choice

Audit & fix For apps already built with AI tools

Already built something with AI?

If you have a Lovable, Bolt, Cursor or Replit app that demos well but you’re not sure it’s safe to launch, start here. Read-only access, a written report ranked by severity, and a fixed price.

$349

web + mobile $499 Delivered in two business days

Apps we work on

  • Lovable
  • Bolt
  • Replit
  • Cursor
  • v0
  • Base44
  • Next.js
  • React
  • Astro
  • Supabase
  • Firebase
  • Neon
  • Postgres
  • Node
  • Python
  • Expo
  • React Native
  • Capacitor
  • Flutter
  • Swift / SwiftUI
  • Kotlin / Jetpack Compose
  • App Store Connect
  • Google Play Console
  • TypeScript
  • Vercel
  • Cloudflare
  • Claude
  • OpenAI
  • MCP
  • Postgres / pgvector
  • Evals and tracing

AI-built app audit report

yourapp.com · web

Sample
Findings 4 Critical 3 High 3 Medium 2 Low
  1. PT-001 Critical Row-level security disabled on all public tables
  2. PT-002 Critical Service role key present in the client bundle
  3. PT-003 Critical Stripe webhook endpoint does not verify signatures
  4. PT-004 Critical Webhook handler is not idempotent
  5. PT-005 High Administrative actions are gated in the interface only

The app demos beautifully and cannot go live.

AI coding tools are very good at producing something that works on the happy path, in one browser, with one user, on a laptop. Production is the rest of it. These are the twenty failure modes the audit checks for. The four mobile items are covered by the web + mobile audit.

Open any one to see what is actually wrong underneath it.

Security Your database is publicly readable

Row-level security was never switched on, so the browser key that ships in your JavaScript bundle can read every row in every table — including other customers’ records. From the outside the app looks completely normal.

What we do Access policies written and tested per table, with a test asserting a user of one tenant cannot reach another’s rows, run in CI so a future migration cannot silently remove isolation.

Security A secret key is sitting in your JavaScript bundle

An admin-level key was used in client code to work around access rules that were never configured. It bypasses every policy you add later, so fixing the policies alone changes nothing.

What we do Rotate the key, move every privileged call behind server-side endpoints, and add a build-time scan of the client bundle that fails the build if a key pattern reappears.

Security Admin buttons are hidden, not blocked

The role check lives in the React component. The endpoints behind it have none, so anyone who calls them directly can perform administrative actions — including changing their own role.

What we do The role check moves to the server on every privileged endpoint. The interface still hides what you cannot do, but hiding is no longer what stops you.

Security One customer can read another customer’s data

The tenant identifier used to filter queries is read from a value the client sends. Change it in the request and another organization’s records come back, because the server never checks it against the session.

What we do Tenant identity resolved server-side from the authenticated session only, and the client-supplied parameter rejected outright rather than ignored.

Security Uploaded files are public to anyone with the URL

The storage bucket was left open and filenames are predictable. Invoices, identity documents and private images are readable without logging in, and enumerable by anyone who guesses the pattern.

What we do Per-object access rules, signed URLs with an expiry, and non-guessable keys — plus a sweep of what is already exposed.

Payments Payments charge but nothing happens

The card is charged, the customer sees a success screen, and the account is never upgraded. Almost always the webhook is unverified, unhandled, or never arrives at a handler that does anything.

What we do Signature verification on every event, the payment provider treated as the source of truth for subscription state, and a reconciliation pass over what is already wrong.

Payments One customer, three subscriptions

Payment providers retry webhooks by design and occasionally deliver duplicates in normal operation. The handler inserts a row each time, so your database quietly disagrees with the provider about what was bought.

What we do Event IDs stored with a unique constraint, and subscription writes made upserts keyed on the provider’s own identifier rather than blind inserts.

Payments Cancellations and refunds never reach your database

One event is handled — the successful checkout — and nothing else. Canceled customers keep their access, refunded customers still count as revenue, and failed renewals are invisible.

What we do The full lifecycle implemented and tested: renewal, failure, refund, dispute, cancellation, and the grace periods between them.

Payments The price is set by the browser

The amount to charge is sent from the client to the checkout session. Anyone can change it in the request before it is sent, and pay whatever they like.

What we do Price resolved server-side from your own catalog. The client sends an identifier for what it wants to buy, never a number.

Reliability Works locally, fails in production

Different environment variables, a missing build step, a server-only library imported into client code, a database connection that works from your laptop and not from the host. The error is a 500 with nothing behind it.

What we do Environment parity, configuration validated at boot so a missing value fails loudly at deploy rather than silently at runtime, and real errors surfaced instead of swallowed.

Reliability You find out it is down from a customer

No error tracking, no uptime check, no alerting. A broken payment path or a failing migration is reported by whoever happens to hit it, and there is no trace left to diagnose from afterwards.

What we do Error tracking with releases and source maps, uptime checks on the paths that matter, and alerts routed somewhere a human actually reads.

Reliability It got slow and nobody knows why

Missing indexes, queries issued inside a loop, whole tables fetched and then filtered in memory. All of it is fine with fifty rows and none of it is fine with fifty thousand.

What we do The slow queries identified from real timings, indexes added where they are needed, repeated queries collapsed, and a performance check that fails the build on a regression.

Reliability There is no way back from a bad deploy

Deploys go out from a laptop, there is no record of what shipped, and the only way to undo a release is to write the old behavior again by hand under pressure.

What we do Deploys from CI on merge, immutable builds you can identify, and a rollback that has been executed at least once so you know it works.

Data No backups, or none anyone has restored

Running on defaults with no export schedule, or with backups nobody has ever restored from. A backup that has not been restored is an assumption, not a recovery plan.

What we do Scheduled backups with a retention policy, a documented restore, and that restore actually performed into a scratch environment to prove it works.

Data Staging writes to the live database

One connection string across every environment. Preview deployments mutate real customer data, and a migration tested on a branch runs against production. There is also nowhere safe to rehearse a restore.

What we do Separate projects per environment with distinct credentials, and a seeded non-production dataset containing no real customer records.

Data Schema changes are made by hand

Columns added in a dashboard, no migration files, no history. Environments drift apart and nobody can recreate the database from scratch — including whoever has to recover it.

What we do Migrations committed to the repository and applied in CI, so the schema is reproducible from zero and every change is reviewable.

Mobile Rejected by the App Store for minimum functionality

A web view with nothing a browser could not do. Resubmitting the same build with a better description does not change the outcome, and each attempt costs a review cycle.

What we do Genuine native capability — push, biometric unlock, offline behavior, native share — implemented against the real platform APIs, which is what the guideline actually asks for.

Mobile Refused at upload for an old target SDK

Google raises the target API floor every year and refuses new builds below it before review even begins. The upgrade then surfaces layout and orientation changes the app never handled.

What we do Target level raised and the consequences fixed: edge-to-edge layout with correct insets, and large-screen orientation behavior that no longer assumes portrait.

Mobile Your privacy answers do not match what the app sends

The data safety form declares no collection while the app ships analytics and account data. That mismatch is itself a policy violation, independent of the collection it fails to declare.

What we do Declarations rewritten from an audit of the network calls the build actually makes, plus privacy manifests and required-reason declarations for every bundled dependency.

Mobile Push and deep links work in the simulator only

Certificates, entitlements and associated domains were never configured for a release build, so notifications silently fail and links open the browser instead of the app.

What we do Configured and verified on physical devices against a release build, on both platforms, with the release process written down so you can repeat it.

Not an exhaustive list

…and the ones specific to your app

Twenty is what every audit checks for, because they are the failures that recur across almost every AI-built codebase. Yours will also have its own — the ones that come from your particular combination of platform, stack and history, which nobody could put on a list in advance. Those are what the audit is actually for.

If none of these is your problem, say so on the call and we will tell you whether we are the right people.

How it works

Three steps, and you can stop after any of them. The report is yours whether or not we fix anything.

  1. Audit

    We review security, auth, payments, deploys and store readiness, and rank every finding with evidence and a fix estimate.

    $349 web + mobile $499

    Two business days

  2. Fix sprint

    We fix what the report found, on a scope agreed from it. The audit fee comes off the price.

    from $1,800

    One to two weeks

  3. Care

    Optional. Monitoring, dependency updates and a few hours of fixes every month.

    from $499 /mo

    Monthly

Mobile app headed for the stores? The Store-ready mobile sprint is from $2,500. What it covers

The audit fee is credited in full against a fix sprint — or a one-week build — booked from it.

11Questions

Before you book.

Something we haven’t covered?

Ask on a call
01 What actually fits in a week?

One product with one core workflow, done properly: accounts, roles, payments, an admin view and a couple of integrations. Most first versions fit once they’re scoped honestly. We decide it together on the scoping call, before you pay anything.

02 What if my idea is bigger than a week?

We’ll tell you on the call. Usually we split it: a first week that ships something real, then further weeks quoted separately. Each one has its own fixed scope and price, so you can stop after any of them.

03 Who owns the code?

You do, from the first commit. We build in your repository, on hosting and accounts in your name, and nothing of ours is left behind that you need us to maintain.

04 What happens after launch?

You get a written handover, and you can run the product yourself or hire anyone to extend it. If you’d rather we stay on, the Care plan covers monitoring, updates and a few hours of fixes every month.

05 How does payment work?

Half to book the week, half on launch day, invoiced in US dollars. The audit is paid up front. The price is fixed when you book; only a change of scope changes it, and that is always a new quote you agree to first.

06 You’re in India — how do time zones work?

We work async with teams in the US and Europe, with a daily overlap window for calls. In practice you review the day’s preview in your morning and your feedback is in the build by the next one.

07 What don’t you do?

Brand identity, content writing, marketing and paid growth. We don’t run penetration tests or issue compliance certificates. And we don’t take on a week we don’t believe fits in a week.

08 What if the audit finds nothing serious?

Then it’s free. If the report contains no material finding — nothing that would expose data, lose money, break a deploy or block a store submission — we don’t invoice it, and you keep the report.

09 What access do you need to run an audit?

Read-only to start: your repository, and viewer access to your hosting and database dashboards. We don’t need write access, production credentials or customer data to produce the report. Write access is only requested at the start of a fix sprint, and it can be revoked the day it ends.

10 Can you work on an app built with a platform I’m locked into?

Usually, yes. We work on Lovable, Bolt, Replit, Cursor, v0 and Base44 output, and on the Supabase, Firebase, Neon and Postgres backends behind them. Where a platform makes part of the stack unreachable, the audit says which findings can’t be fixed without moving off it, and what moving would involve.

11 Can you guarantee the App Store will approve my app?

No, and nobody can. Approval is Apple’s and Google’s decision. We cover everything on our side of that line: packaging, SDK requirements, privacy details and data-safety answers, store metadata, and responding to review feedback until the app is through.

12 Do you use AI to build?

Yes. AI tools speed up the typing, and a senior engineer designs, reviews and tests every line that ships. That combination is why a week is enough.

13 What tech stack do you use? Can I choose?

Our defaults are proven and widely supported: TypeScript, React and Next.js, Postgres and Supabase, React Native and Expo. If you have a strong reason for something else, tell us on the call.

14 Can you work from my Figma or existing designs?

Yes. It usually makes the week faster. If you have no designs, Day 1 includes simple, clean screens we agree on together.

15 Can you take over a codebase someone else started?

Usually. Start with the audit, so we both know what we’re inheriting before we quote.

16 What do you need from me during the week?

About 20 minutes a day, account access, and feedback within one business day. The full list is in “Your part of the week.”

17 What if I want to change something mid-week?

Small adjustments inside the agreed scope are part of the process. Anything new goes on a list for week two, quoted separately, so the launch date holds.

18 Do you sign NDAs?

Yes, before we see anything confidential.

19 Can you build for healthcare or finance?

We build with strong security practices, but we don’t run formal compliance programs such as HIPAA or SOC 2. If you need those, we’ll say so up front.

12Field notes

Field notes.

What we’ve learned about shipping fast without shipping fragile.

All field notes

Have an idea?

Let’s scope your week.

A free 30-minute call. We’ll tell you honestly what fits in a week, and send a fixed quote afterward.

Book a build call

Prefer to write? Send your requirements

Already built it?

Find out what’s wrong with it.

Read-only access, a ranked written report, and a fixed price. Free if it finds nothing material.

Get the audit
What do you need?

What it should do, who will use it, the must-haves, and any links. A few sentences is plenty.

Budget, if you have one in mind
When would you like to start?