AI app production review + hardening
Shipping an AI-built app?
Find the risks before launch.
We find and fix the production risks in apps built with Lovable, Bolt, v0, Cursor, Claude Code, and other AI tools—before customers, attackers, or procurement teams find them.
Auth
Sessions, roles, protected routes
Isolation
Cross-tenant reads and writes
Billing
Webhooks, tiers, entitlements
Launch
Logs, tests, deploys, rollback
Fixed-scope first step
One application. Human-reviewed findings. Three-business-day turnaround. The entire $495 fee is credited toward a Hardening Sprint.
Build + Govern
Start with the structure AI needs to stay useful.
The scaffold preview is the control layer in miniature: describe the system, then get architecture, threat analysis, decisions, tests, and deployable files before an agent starts improvising in production.
Production hardening for AI-generated software
Turn AI-generated apps into
production-ready software.
Vibe coding gets you a demo. Stackbilder generates governed scaffolds, threat models, ADRs, and test plans — before your prototype becomes production debt.
Verify before code lands
Every scaffold includes governance output.
T-001: Spoofing — JWT validation bypass via alg:none
T-002: Tampering — D1 SQL injection in query builder
Severity: HIGH | Mitigation: parameterized queries...
Use cookie-based sessions over stateless JWTs.
Context: Edge runtime + D1 session store available...
test_auth_flow: login → session → protected route
test_billing: checkout → webhook → tier upgrade
Coverage target: 85% | Framework: vitest...
Build on explicit architecture
Requirements, components, data boundaries, and deployment shape are recorded before implementation so generated code has a frame to obey.
Govern decisions and risk
STRIDE threats, ADRs, and constraints give agents permission rails. The output says what is allowed, what is risky, and what has to be tested.
Execute with bounded tools
Durable jobs, tier gates, quotas, and MCP tools keep autonomous actions observable and interruptible instead of turning them into opaque API calls.
Verify with evidence
Receipts, test plans, and trust surfaces make the work reviewable after the model call. Read the field guide →
Execute proof workload
img-forge is the live workload, not the whole company story.
The Tarot Detective is a live detective game whose entire art pipeline runs through the governed img-forge surface — 16 portraits, 23 locations, 28 props. Every character keeps the same face across every scene: once a look is approved, every subsequent call reuses the same seed, so asset 43 still matches asset 2.
Execute with agents
One governed agent flow. One URL back.
Connect MCP, discover allowed tools, call generate_image, receive a job_id and asset_url, and keep billing inside explicit credit controls. REST is there when raw HTTP fits better.
# Codex
[mcp_servers.img-forge]
url = "https://imgforge-mcp.stackbilder.com"
auth = "oauth"
oauth_resource = "https://imgforge-mcp.stackbilder.com"
codex mcp login img-forge
# First successful flow
list_models
generate_image(prompt: "a red fox in a snowy forest")
check_job(job_id: "60b3ba6a-...") 11 models, one auth
SDXL, FLUX, Leonardo, and Gemini behind one token and one billing surface. Switch tiers per request — no per-provider accounts, no integration rewrite.
Generate, edit, correct
img2img restyling and mask-based inpainting through the same endpoint. Asset 43 of 67 has a bad hand? Fix the region, keep everything else — no re-roll, no drift from the approved look.
Your agent can respect its budget
billing_status and billing_purchase_credits are MCP tools — an agent checks its balance mid-run, tops up, and keeps generating. Replicate, fal.ai, and Leonardo expose nothing like this to agents.
Agent trust markers
OAuth 2.1 / PKCE, MCP 2026-07-28 compatibility, legacy 2025-11-25 compatibility, read-only discovery through list_models, credit controls, and no surprise overages.
Buyer paths
Self-serve the workload, or bring the control layer to yours.
Start with the platform, use img-forge today, or bring Stackbilt in for a governed customer workflow. No competing primary CTA, just the right next step.
Free
Get started, no strings
- ✓5 free image generations / month
- ✓Draft and standard tiers
- ✓3 governed scaffolds / month
- ✓REST API + MCP access
Pro
The whole platform, one price
- ✓1,000 img-forge credits / month
- ✓All tiers, Ultra and Ultra+ included
- ✓Unlimited scaffolds + LLM polish
- ✓Credit packs stack on top
- ✓Priority support
Agency
For production pipelines at volume
- ✓4,000 credits / month
- ✓Credits roll over while active
- ✓~8 full production runs / month
- ✓Priority queue + dedicated support
Need one-time volume? Builder and Studio credit packs never expire · full plan comparison
Higher-touch path
Need the control layer around your own workflow?
Services cover audits, Cloudflare-native buildouts, governed agent workflows, and trust bundles without forcing the self-serve img-forge buyer path.
Start with the control layer.
Free tier includes 3 governed scaffolds and 5 image generations. No credit card. No tokens to buy.
Or get launch updates — no spam, just milestones.