Apps built with Lovable, Bolt, Cursor or v0 usually work — and routinely ship with exposed keys, missing row-level security and no rate limiting. For $750 diagnostic, credited in full I read the codebase and hand you a findings register; the fee is credited in full against a fixed-price remediation, so the diagnosis is never the product.
$750 diagnostic, credited in full· diagnostic 1 week · remediation 2–4 weeks
Half on start, half on delivery of the evidence pack. Milestone billing above $8,000. Evidence pack or no fee: every engagement ends with a dated evidence pack. If I don’t deliver it, you don’t pay the closing half.
What is this for, exactly?
Founders and agencies whose AI-built application (Lovable, Bolt, Cursor, v0) works — and is about to carry real customers.
What do you get?
- Findings register: every defect with severity, exploitability and reproduction
- The remediation itself — fixes applied in your codebase, with the diff
- A verification pass re-testing every finding after the fix
- A written assurance note: what was fixed, what residual risk was accepted, what was out of scope
Why does this problem exist at all?
Because generation quality and security quality are different things, and only one of them is visible in a demo.
AI-generated code, measured
- 56%Share of AI-generated code that passes security checks — stalled across four annual snapshots and more than 100 models, with no security-specific prompting.Veracode, 2026 GenAI Code Security Report (opens in a new tab) · retrieved
- 15%Pass rate of AI-generated code on cross-site-scripting (XSS) tasks in the same report — the weakest category measured.Veracode, 2026 GenAI Code Security Report (opens in a new tab) · retrieved
The tools are excellent at making software exist. Making it safe is still a person’s job.
That pass rate has stalled across four annual snapshots and more than 100 models — it is not a gap that the next model release closes.
When is the right moment for this?
Three triggers, in practice: you are about to put real customers on the app; a paying customer or investor just asked a security question you could not answer in writing; or something already went wrong and you got away with it. The wrong moment is after the incident that you don't get away with — at that point you need an incident desk, not a diagnostic.
What does “verified” mean here?
Every finding in the register is re-tested after its fix, and the verification pass is part of the deliverable — not a promise that nothing can ever go wrong, but proof that the specific doors I found are closed. The assurance note then states plainly what was fixed, what residual risk you accepted, and what was out of scope. That document is written to be shown to the customer or investor who asked.