Production-Readiness Audits for AI-Built Apps

Your AI-built app passes the demo. I find what breaks in production.

A senior engineer's review of the security, reliability, and scale problems that get founders breached, sued, or quietly losing money, delivered as a plain-English fix list you can act on the same day.

20 years building production systems in regulated, compliance-heavy environments. Reviewed by one senior engineer, start to finish.

AI ships features fast. It skips the boring stuff that keeps you safe.

AI coding tools are great at making something that works in a demo. They are bad at the unglamorous production layer: tenant isolation, secret handling, idempotent payments, deploy safety. That is exactly where the company-ending problems live, and they stay invisible until a real customer, or a real attacker, hits them.

  • An unauthenticated request that could read and charge any customer's saved card.
  • A payment-gateway master key shipped to every visitor's browser.
  • A checkout that double-charges on a normal retry.
  • Test code that deploys straight onto the live production system.

These are not hypotheticals. They are the kinds of issues these tools ship every day.

A report you can hand to any developer and fix from.

  • A systematic review of your app's code and deployment across security hygiene, reliability, and scale-readiness.
  • Every finding ranked by business consequence, in plain language, with where it lives in the code and how to fix it.
  • Every finding I report, validated, so you know what is real versus theoretical.

What a real audit turns up.

Here's a sample report from a real audit, so you can see exactly what you'd get. It reviews an AI-built, payment-taking app, the kind I audit, and every finding in it is real. This one turned up an unauthenticated request that could read and charge any customer's saved card, the payment provider's secret key exposed to the browser, and a checkout that double-charges on a retry, each reproduced and ranked with a plain-English fix.

Your report looks exactly like this. Your findings stay between us, always.

Read the full sample report (PDF)

From the sample report

7
Critical issues found
31
Findings, all validated
5
Reproduced live

This is for you if...

  • You shipped an app built largely with AI tools (Cursor, Claude Code, v0, Lovable, and the like).
  • It takes payments or holds customer data.
  • You want to know you are not one bug away from a breach before you add more customers.
Not for: teams wanting a formal penetration test or a compliance certification. That is a different, heavier engagement.

One fixed price, sized to your app.

From $1,500 single-app audit

You tell me about your app and I send back one fixed price for the whole audit: no hourly billing, no meter running. A single app starts at $1,500; larger or multi-product scopes are priced the same way. That number is a quote based on what you describe, not a locked price the moment you hit send. Once I have read-only access, if the codebase is materially larger or more tangled than the form let on, I'll send you a revised quote to approve before any work begins, so you always sign off on the number up front and the bill is never a surprise. Optional: I will fix the critical items for you afterward, fixed scope and fixed price, if you would rather not manage it.

If I don't find real, reproduced problems in your code, the audit is free.

This is a reliability and security-hygiene review, not a penetration test or a compliance certification.

Who's doing the audit.

I'm Jeff Hanes. Twenty years building and running production software, including years in regulated, compliance-heavy environments where getting it wrong has real consequences. I do these audits myself: one experienced set of eyes, not a junior running a scanner, and never a subcontractor.

Questions.

How long does it take?

Typically 3 to 5 business days. You get the report and, if you want it, a short walkthrough.

What do you need from me?

Read access to the code and answers to a few questions about your setup.

Is my code safe with you?

Yes. Access is read-only and time-boxed, I never ask for production secrets or customer data, and everything is deleted after the engagement. An NDA is available and I am happy to sign yours. Your code is handled confidentially, per engagement, and is never shared or used to train anything. It is why the sample above is a demonstration app I built, not a client's report.

Is this a penetration test?

No. It is a production-readiness review: security hygiene, reliability, and scale-readiness. Same boundary, stated up front.

Will you find every issue?

No, and be wary of anyone who says they will. No review, human or automated, can guarantee it finds every problem in a codebase. What I do is find the highest-consequence security and reliability issues, validate every one I report, and rank them so you fix what matters first. It meaningfully reduces your risk. It is not a guarantee that your software is secure or bug-free, and the full terms are in the engagement agreement.

What if you don't find anything serious?

You get a clean bill of health and the steps to verify it yourself. And the guarantee is real: if nothing lands at medium severity or higher on the scale you see up front, the audit is free. What counts is set by that scale, not by my opinion after the fact.

Can you fix the issues too?

Yes, optional. A fixed-scope, fixed-price fix engagement after the audit.

Find out what's hiding in production.

Tell me about your app and I'll get back to you with a fixed quote within one business day.

Trouble sending? Email me directly at jeff.h@forgebuilt.io. Read-only code access comes later, only once we've agreed scope.

Get a fixed quote