Skip to content
Production Review Services Checklist img-forge Plans Company Docs Blog

Fixed scope · human reviewed · three business days

Find the production risks
before your users do.

Shipping an app built with Lovable, Bolt, v0, Cursor, Claude Code, or another AI coding tool? We review the code paths that turn working demos into expensive incidents: authentication, customer isolation, billing, secrets, validation, logging, tests, and rollback.

See a sample report Ask a question first →
One repository Prioritized findings 30-minute findings call $495 remediation credit

What gets reviewed

The failure paths that carry real business cost.

This is a focused review of production controls, not a generic code-quality score.

01

Auth + sessions

Login, session lifecycle, authorization boundaries, logout, password reset, and privileged routes.

02

Tenant isolation

Every customer-scoped read and write checked for cross-tenant access paths.

03

Billing + webhooks

Stripe signatures, replay protection, entitlement changes, tier gates, and failure recovery.

04

Secrets + validation

Environment separation, exposed credentials, request validation, unsafe redirects, and API abuse controls.

05

Logging + errors

Useful production signals without leaking tokens, personal data, internals, or security-sensitive context.

06

Tests + rollback

Coverage of the highest-cost failure paths and a deployment rollback process that can actually be executed.

What you receive

A decision document, not a scanner dump.

Every finding explains the evidence, the practical failure mode, the recommended fix, and where it belongs in the launch sequence.

Open the sample report →
production-risk-review.pdfhuman reviewed
executive_summaryLaunch posture, critical blockers, and the shortest safe path forward
prioritized_findingsSeverity, evidence, exploit/failure scenario, and recommended remediation
control_coverageWhat was reviewed, what passed, and what could not be verified
remediation_planFix order, effort range, dependencies, and suggested verification tests
findings_call30 minutes with Kurt to challenge findings and decide next steps

How it works

Three days from access to prioritized answers.

  1. 01

    Purchase + intake

    Tell us what is launching, the stack, and the failure you are most worried about.

  2. 02

    Bounded access

    Grant time-bounded read-only repository access. You can revoke it at any time.

  3. 03

    Review + report

    Kurt validates findings, ranks them by business risk, and delivers the report within three business days.

  4. 04

    Decide

    Review the findings together. Fix them yourself or apply the $495 credit to a Hardening Sprint.

Engagement security

Your code stays yours. Every action stays accountable.

  • Human accountability. Kurt is accountable for the review and validates every finding before delivery.
  • No autonomous production changes. AI systems cannot deploy into client production, and no client change ships without human approval.
  • Bounded access. Access is time-bounded, least-privilege, and revocable. We do not ask for customer data when code and configuration evidence will do.
  • Client ownership. You retain ownership of source code, accounts, infrastructure, and every deliverable.

Common questions

What do you need access to?

Read-only repository access is usually enough for the review. If deployment configuration lives outside the repository, we may ask for exported settings or a screen share. We do not need production database contents, customer records, or permanent credentials.

Do you change the application during the review?

No. The review is read-only. No code, infrastructure, billing setting, or production environment changes without a separate written scope and your explicit approval.

Is this a penetration test or certification?

No. It is a focused application production-risk review, not a penetration test, SOC 2 audit, compliance certification, or independent assurance engagement. Findings are based on the repository and context provided during the review window.

What happens if you find something critical?

We notify you as soon as the finding is validated instead of waiting for the final report. The report then documents the evidence, likely impact, and recommended remediation order.

Can you fix the findings?

Yes. A Hardening Sprint is scoped from the findings. The full $495 review fee is credited toward a sprint started within 30 days of delivery.

What kinds of apps are a fit?

AI-built or AI-assisted web applications approaching launch, accepting payments, onboarding customers, or entering procurement. Lovable, Bolt, v0, Cursor, Claude Code, Replit, and conventional repositories are all welcome.

Not ready to purchase?

Reserve a review or ask about fit.

Share the basics. We reply within one business day and will tell you plainly if the fixed-scope review is not the right starting point.

Book 30 minutes with Kurt →
No credentials in this form