Auth and data access
Who can read or change records, whether row-level rules match the product, and whether admin paths are actually gated.
What we check
The audit stays on the paths that usually break an AI-built or no-code MVP. It is not a full rewrite.
Who can read or change records, whether row-level rules match the product, and whether admin paths are actually gated.
Checkout, webhooks, retries, and refunds. We look for charges that succeed in the UI and fail in the ledger.
Keys in the repo or the client bundle, environments that drift, and a release path that cannot be repeated.
What you get
You can hand the findings to your own team. If you want us to close them, that is a second fixed price.
Each blocker is named, with where it lives in the repo and why it matters before launch.
What blocks launch, what can wait, and what is noise. You can act on the list without us.
If you want the fixes done, we quote a separate fixed-price sprint for the items you choose. The audit stands on its own.
Who it is for
Homepage and this page name the same people. We do not add a fourth audience here.
The lead offer. You have an AI-built or no-code MVP and need someone to open the repo before users or payments depend on it.
If an AI feature handles patient data, the audit includes access control and a written account of how that data moves. We do not claim a HIPAA certification.
Scheduling and admin automation can be quoted as new work. Mr Sked is scheduling software we have shipped. It is not a clinic deployment.
Questions
Scope, price, and what we will not claim.