App check

Find out what will break before your users do

You built it with AI, or someone did, and it’s live or about to be

Here’s what will breakApp check report · Bookings app
Ranked
  1. Anyone can read every customer’s emailFixpolicy: owner only
    Fix first
  2. Your payment key is in the page sourceFixSTRIPE_KEY on the server, rotated
    Fix first
  3. Bots can hammer search all nightFixsearch: 30 a minute per user
    This week
Signed offBy the engineer who checked it
What you get

What will break, how to fix it, and a signature

You keep the report, whether or not we do the fixes

policy: noneAnyone can read every customer’s emailFix first

A ranked list of what will break

Worst first, written in plain English

Bots can hammer search all night- search: no limit+ search: 30 a minute per user

The fix for each problem

Written so any developer can act on it

App check reportSigned off

A signed report you can share

With your team, or with your investors

How it runs

From access to a signed report in five business days

You share the code and the live app once, and we take it from there

Five business days
  1. Access

    You share the code and the live app with us

  2. Read

    We read every line the AI wrote

  3. Rank

    We rank what will break, worst first

  4. Fix

    We write the fix for each problem

  5. Sign

    An engineer signs the report and hands it over

What we check

The line items every app check covers

We check each one in your code and on your live app

  • Rate limitsOne bot shouldn’t be able to hammer your app and run up the billFree fix
  • Who can read whatSigned-in users should only ever see their own dataFree fix
  • DuplicatesA double tap should never charge or book anyone twiceFree fix
  • Secrets and keysPayment and API keys stay on the server, never in the page
  • Sign-inSign-in, password resets and sessions work the way they should
  • BackupsIf data gets lost, you can actually get it back
  • LoggingWhen something breaks, there’s a record of what happened
Free fixes

Want to check it yourself first?

Every Free fixes episode is one line item of this check, with the fix

  • Your rate limit is probably not limiting anything
  • Row level security switched on is not row level security working
  • A dedupe key carries the intent, not just the identity
Get the free fixes
Who it’s for

For founders with something real on the line

It’s for you if
  • Your app is live, or about to be
  • Users, revenue, investors or a launch date depend on it
  • You built it with AI, no-code or a cheap freelancer
  • Nobody technical answers for it today
It’s not for
  • Hobby projects, which the free fixes are for
  • Anyone shopping for the cheapest quote
Questions

What founders ask before an app check

Can you check something I built with AI?

Yes, and most app checks start there. We read what the AI wrote, tell you what’s risky, and either fix it or hand you the list

Do I have to hire you for the fixes?

No. You keep the report whether or not we do the fixes, and the fix for each problem is written so any developer can act on it

Will my app be hack proof afterwards?

No one can honestly certify an app as hack proof, and we’d be careful of anyone who offers to. You’ll know exactly what we checked, what we found and how to fix it

Do I need to know anything technical?

No. We explain everything in plain English, and you’ll always know what we’re working on and why

App checkFixed price, from $1,500 · Five business days

Book the free call

Bring what you have. We’ll tell you where it stands

You’ll leave the call knowing what’s risky and what to do next

  • 30 minutes
  • Free
  • No slides, no sales team