01 How do I know whether my app needs this?
If it was built largely by an AI coding tool and it has not been reviewed by an engineer since, it almost certainly has at least one of the four critical findings in our sample report — open database policies, a key in the client bundle, an unverified payment webhook, or authorization enforced only in the interface. The $349 audit exists to answer exactly this question, and if it finds nothing material you get the fee back.
02 Can you work on an app built with Lovable, Bolt, Replit or Cursor?
Yes. Those four plus v0 and Base44 are most of what we see, and the backends behind them are usually Supabase, Firebase, Neon or plain Postgres. Some platforms make parts of the stack unreachable — typically the server layer — and where that is the case the audit says which findings cannot be fixed without moving off, and what moving would involve.
03 Will you break my app while fixing it?
Everything lands as a branch and a pull request you review before it merges, so there is no point at which you first see a change that is already live. Access-control changes ship with tests that assert the intended behaviour, and anything touching payments is reconciled against the provider rather than assumed. Where a fix has to run against live data, it goes out as a staged change with a backfill rather than a single migration.
04 Do I need the audit, or can you just start fixing?
The audit is required, because it is the only way either of us knows what the work is. Quoting a fixed price for an unknown codebase means padding the number to cover the worst case, which is worse for you. The fee is credited in full against the sprint, so it costs nothing extra if you go ahead.
05 What access do you need, and when?
Read-only for the audit — your repository plus viewer access to hosting and the database. No production credentials and no customer data. Write access is requested only when a sprint starts and is revoked the day it ends. If a finding needs confirming with a live request, we ask for written permission first and anything that writes data is reproduced on a local or staging copy.
06 How long does it take?
The audit is two business days from the moment access works. A sprint is one to two weeks depending on what the audit found. The largest single factor is whether tenant isolation has to be retrofitted, because that touches every query rather than a handful of files.
07 What happens to the findings you do not fix?
They stay in the report with their severity and estimate, so you can schedule them, hand them to another engineer, or leave them knowingly. Nothing is quietly dropped because it was out of scope.
08 Do you offer ongoing support afterwards?
Optionally. A care retainer covers monitoring, dependency and security updates, and the store deadline work that comes round every year. Plenty of apps will not need one, and we would rather say so than sell it.
09 Who owns the code?
You do, throughout. It lives in your repository on your accounts under your billing from the first commit, so there is nothing to transfer at the end and no layer of ours left behind that you would need us to maintain.