Six places we look first.

01

Logic bugs

They pass the demo and fail on real data.

HOW WE CHECK

We trace the paths that carry money or data.

02

Auth and data access

One missing check exposes every user.

HOW WE CHECK

We trace every route’s auth check and read row-level security policies and storage rules, Supabase included, wherever they live in the repository.

03

Injection

User input reaching a query, prompt or shell.

HOW WE CHECK

We follow input to where it is used.

04

Secrets

A committed key outlives the commit.

HOW WE CHECK

We search history as well as the tree.

05

AI-API spend

An unbounded loop is an unbounded bill.

HOW WE CHECK

We look for missing timeouts, budgets and retry caps.

06

Tests and structure

Without them, every fix breaks something else.

HOW WE CHECK

We run what exists and map what is missing.

Findings in the order to fix them.

  1. Findings by severity: critical, warn, ok.
  2. For each: the file, the risk and the fix.
  3. What to leave alone.
  4. What we would fix or build first.

SEVERITY

critical
Fix before the next release.
warn
Fix soon; it will cost more later.
ok
Sound. Leave it alone.

What a cleanup fixes once the report is in.

The scope of a typical cleanup.

What a cleanup changes, area by area.
AREABEFORE CLEANUPAFTER CLEANUP
SecretsCommitted to the repositoryIn a secrets manager, rotated, never in a prompt
TestsNone, or tests that pass whatever the code doesTests on the paths that make money, run on every pull request
StructureOne file does everything; changing one thing breaks anotherModules with one job each; a new engineer can find the thing they need
Model callsNo timeout, no cost cap, no fallbackTimeouts, budgets, retries and a fallback that degrades instead of failing
RetrievalReturns something, quietly wrongEvaluated against real questions, with the misses written down
QueriesBuilt from strings, one database call per rowParameterised, batched, and indexed where the load needs it
DeploysFrom someone’s laptopFrom the repository, with a rollback that has been tried
DocsThe chat history with the AI toolA README that gets to a running system on one machine, and runbooks for what breaks
OwnershipNobody can say who understands itYour team, with documentation and our access removed within seven days
  1. Secrets

    BEFORE CLEANUP
    Committed to the repository
    AFTER CLEANUP
    In a secrets manager, rotated, never in a prompt
  2. Tests

    BEFORE CLEANUP
    None, or tests that pass whatever the code does
    AFTER CLEANUP
    Tests on the paths that make money, run on every pull request
  3. Structure

    BEFORE CLEANUP
    One file does everything; changing one thing breaks another
    AFTER CLEANUP
    Modules with one job each; a new engineer can find the thing they need
  4. Model calls

    BEFORE CLEANUP
    No timeout, no cost cap, no fallback
    AFTER CLEANUP
    Timeouts, budgets, retries and a fallback that degrades instead of failing
  5. Retrieval

    BEFORE CLEANUP
    Returns something, quietly wrong
    AFTER CLEANUP
    Evaluated against real questions, with the misses written down
  6. Queries

    BEFORE CLEANUP
    Built from strings, one database call per row
    AFTER CLEANUP
    Parameterised, batched, and indexed where the load needs it
  7. Deploys

    BEFORE CLEANUP
    From someone’s laptop
    AFTER CLEANUP
    From the repository, with a rollback that has been tried
  8. Docs

    BEFORE CLEANUP
    The chat history with the AI tool
    AFTER CLEANUP
    A README that gets to a running system on one machine, and runbooks for what breaks
  9. Ownership

    BEFORE CLEANUP
    Nobody can say who understands it
    AFTER CLEANUP
    Your team, with documentation and our access removed within seven days

Read-only access, then a written review.

  1. 01

    Send the form below, or book a call.
  2. 02

    You grant read-only access to one repository.
  3. 03

    The written review arrives within 48 hours of access. Review material is deleted 30 days later unless we go on to work together.

Tell us where the code is and what worries you.

We reply by email with the next step.

Private is fine: we ask for read-only access.

Read by an engineer, kept for 24 months, never sold. Details in our privacy notice.

Before you share a repository.

Is there any obligation?

No. The review is yours whether or not we work together.

What if you find nothing?

Then the review says so, in writing, and we stop.

Who reads the code?

One of our engineers, with our checklist.

What do you do with the access?

Read. We keep no copy of production data, delete review material 30 days after the review unless we go on to work together, and never use your code to train a model.

What if data is exposed right now?

Say so in the form, or email [email protected] with “urgent” in the subject. A secret we find in your repository is reported the same day, ahead of the written review. Anything outside the repository, such as the running app or your database project settings, we agree on a call.

A call first, if you would rather.

Book a call and tell us what worries you about the code. We will tell you whether a review is the right first step.

Experience
Two years serving customers, from startups to enterprise teams.
Shipped
30+ production AI systems.