A written code review, back within 48 hours.
One of our engineers reads your code against our checklist. Every finding names the file, the risk and the fix.
- ACCESS
- CONTEXT
- TIMING
Six places we look first.
Logic bugs
They pass the demo and fail on real data.
HOW WE CHECK
We trace the paths that carry money or data.
Auth and data access
One missing check exposes every user.
HOW WE CHECK
We trace every route’s auth check and read row-level security policies and storage rules, Supabase included, wherever they live in the repository.
Injection
User input reaching a query, prompt or shell.
HOW WE CHECK
We follow input to where it is used.
Secrets
A committed key outlives the commit.
HOW WE CHECK
We search history as well as the tree.
AI-API spend
An unbounded loop is an unbounded bill.
HOW WE CHECK
We look for missing timeouts, budgets and retry caps.
Tests and structure
Without them, every fix breaks something else.
HOW WE CHECK
We run what exists and map what is missing.
Findings in the order to fix them.
- Findings by severity: critical, warn, ok.
- For each: the file, the risk and the fix.
- What to leave alone.
- What we would fix or build first.
SEVERITY
- critical
- Fix before the next release.
- warn
- Fix soon; it will cost more later.
- ok
- Sound. Leave it alone.
What a cleanup fixes once the report is in.
The scope of a typical cleanup.
| AREA | BEFORE CLEANUP | AFTER CLEANUP |
|---|---|---|
| Secrets | Committed to the repository | In a secrets manager, rotated, never in a prompt |
| Tests | None, or tests that pass whatever the code does | Tests on the paths that make money, run on every pull request |
| Structure | One file does everything; changing one thing breaks another | Modules with one job each; a new engineer can find the thing they need |
| Model calls | No timeout, no cost cap, no fallback | Timeouts, budgets, retries and a fallback that degrades instead of failing |
| Retrieval | Returns something, quietly wrong | Evaluated against real questions, with the misses written down |
| Queries | Built from strings, one database call per row | Parameterised, batched, and indexed where the load needs it |
| Deploys | From someone’s laptop | From the repository, with a rollback that has been tried |
| Docs | The chat history with the AI tool | A README that gets to a running system on one machine, and runbooks for what breaks |
| Ownership | Nobody can say who understands it | Your team, with documentation and our access removed within seven days |
Secrets
- BEFORE CLEANUP
- Committed to the repository
- AFTER CLEANUP
- In a secrets manager, rotated, never in a prompt
Tests
- BEFORE CLEANUP
- None, or tests that pass whatever the code does
- AFTER CLEANUP
- Tests on the paths that make money, run on every pull request
Structure
- BEFORE CLEANUP
- One file does everything; changing one thing breaks another
- AFTER CLEANUP
- Modules with one job each; a new engineer can find the thing they need
Model calls
- BEFORE CLEANUP
- No timeout, no cost cap, no fallback
- AFTER CLEANUP
- Timeouts, budgets, retries and a fallback that degrades instead of failing
Retrieval
- BEFORE CLEANUP
- Returns something, quietly wrong
- AFTER CLEANUP
- Evaluated against real questions, with the misses written down
Queries
- BEFORE CLEANUP
- Built from strings, one database call per row
- AFTER CLEANUP
- Parameterised, batched, and indexed where the load needs it
Deploys
- BEFORE CLEANUP
- From someone’s laptop
- AFTER CLEANUP
- From the repository, with a rollback that has been tried
Docs
- BEFORE CLEANUP
- The chat history with the AI tool
- AFTER CLEANUP
- A README that gets to a running system on one machine, and runbooks for what breaks
Ownership
- BEFORE CLEANUP
- Nobody can say who understands it
- AFTER CLEANUP
- Your team, with documentation and our access removed within seven days
Read-only access, then a written review.
01
Send the form below, or book a call.02
You grant read-only access to one repository.03
The written review arrives within 48 hours of access. Review material is deleted 30 days later unless we go on to work together.
Tell us where the code is and what worries you.
We reply by email with the next step.
Before you share a repository.
Is there any obligation?
No. The review is yours whether or not we work together.
What if you find nothing?
Then the review says so, in writing, and we stop.
Who reads the code?
One of our engineers, with our checklist.
What do you do with the access?
Read. We keep no copy of production data, delete review material 30 days after the review unless we go on to work together, and never use your code to train a model.
What if data is exposed right now?
Say so in the form, or email [email protected] with “urgent” in the subject. A secret we find in your repository is reported the same day, ahead of the written review. Anything outside the repository, such as the running app or your database project settings, we agree on a call.
A call first, if you would rather.
Book a call and tell us what worries you about the code. We will tell you whether a review is the right first step.
- Experience
- Two years serving customers, from startups to enterprise teams.
- Shipped
- 30+ production AI systems.