Remediation Sprint: Fix the Issues From Your Audit
A fixed-price sprint that fixes an agreed list of findings from my audit or assessment (or another reviewer’s report, after a quick check). I fix, test and re-check each item and tell you what’s done. From $650 ($500 founding), delivered in 1–3 weeks. Email the report to start.
See a sample report, proposal and weekly update- Price
- from $650
- Founding
- from $500
- Timeline
- 1–2 weeks
- Format
- Fixed scope, fixed price
- Hours
- US Eastern Time, async
Who this is for.
A good fit if
- Clients who finished a Security Audit, Pre-launch Check or Codebase Assessment
- Teams holding someone else’s audit report with nobody free to fix it
- Founders of AI-built apps on Supabase with broken row-level security
Common triggers
- An audit report with red items and a launch date
- A customer asks for proof the issues are fixed
- A dependency alert you can’t upgrade past alone
Not a fit if
- There’s no written list of issues yet (start with a Pre-launch Check, Security Audit or Codebase Assessment)
- The stack isn’t one I support for fixes (Laravel, Vue/Nuxt, Go, Python, Postgres/Supabase SQL)
- You want new features in the same sprint
What I do, and what you get.
What I do
- Confirm the fix list and the order with you before starting
- Fix each item in a separate branch or pull request
- Add a test where one makes sense so the issue can’t quietly come back
- Re-check each item and mark it fixed, partly fixed or deferred
- Tell you early if an item is bigger than estimated, with options
What you get
- Pull requests with fixes, each linked to a finding
- An updated findings list with status and evidence
- Tests added for fixed access-control and auth issues
- A list of anything deferred, with estimates
- Handover notes
Your part
- The report and repo write access (via pull requests)
- A staging environment and someone to review and merge
- Deploying to production, or a window where I do it with you
Included
- Fixes for the agreed findings in the sprint
- Tests for fixed items where practical
- Re-check of each fixed item
- Status report
Not included
- New features or redesigns
- Items not on the list (added by change order)
- Full re-audit (quoted)
- Unsupported stacks
Fixed prices, agreed before work starts.
The top items from the report, agreed in writing before the start
A longer agreed list; may run across two months. Bigger lists: book a second sprint the next month
Build your scope
- Timeline
- 1–2 weeks
- Payment
- Paid in full before work starts
- Earliest start
- Oct 5
Founding price: 3 of 7 spots left, until Mar 31, 2027 — one-off work, in return for a testimonial. How it works
Prices are in USD, paid by bank transfer against an invoice. Work under $1,000 is paid upfront; larger work is 50% to start and 50% before handover, or monthly milestones. How working together works
Variations
- After my audit
- Starts straight away because the list is already estimated.
- After someone else’s report
- I first check and estimate their list before we agree the sprint.
- Supabase RLS
- Policy changes as migrations, tested with the anon key for each role.
How it runs.
- 01
Send the report
Send the report, and I reply within one US business day.
- 02
Agree the list
We agree which items fit the sprint and you pay the prepaid invoice.
- 03
Fix in priority order
I fix items in priority order with pull requests and short updates twice a week.
- 04
Re-check and report
I re-check every fixed item and send a status report.
- 05
Optional Care Plan
A Care Plan keeps your dependencies patched afterward.
Where I have done this before.
Questions buyers ask.
What if an item takes longer than estimated?
I tell you first and we choose: defer it, swap it for a smaller item, or add a change order.
What if the sprint finishes with room to spare?
I only invoice the sprint once the list is agreed, so it’s sized to fit the items; unused capacity doesn’t carry over.
Can you fix a Lovable front end?
I fix database policies and server config. Front-end changes on unsupported stacks come as instructions, or we discuss a move to a supported stack.
Will you re-audit afterward?
Each fixed item is re-checked. A full re-audit is separate.
Ask about Remediation Sprint.
Tell me what you have and where it hurts. I reply within one US business day with either a fixed quote or the entry step that makes a fixed quote possible.
Helpful to include
- The report (or its findings list)
- Who wrote it
- Stack and versions
- Staging available?
- Deadline
More in Testing & Security
Pre-launch Readiness Check
A fixed-price review of your app and server before real users arrive. I check security basics, backups, deploys, config, error handling and monitoring, then send a written report with a prioritized fix list and effort estimates. From $520 ($400 founding), delivered in about one week. Email me your stack and launch date to start.
Security Audit & Hardening
A written-scope security review of one web app and its server, including apps built with Lovable, Bolt or Cursor on Supabase. I check access control, auth, secrets, database rules and server setup, then report findings with fixes and effort. From $650 ($500 founding) for the review, about 1–2 weeks. Email your stack to start.
Critical Flow Tests
I write automated tests for the flows that must never break, such as signup, login, checkout and billing, and run them in your CI on every push. From $780 ($600 founding) for up to 3 flows, in 2–3 weeks. A good first step before an upgrade or refactor. Email your stack and flows to start.
Accessibility Audit & Fix
A new service: a fixed-price accessibility audit of your web app’s key pages and flows against WCAG 2.2 AA, with automated checks, a keyboard and screen-reader pass, and a ranked fix list, followed by fixes quoted from the audit. Audit from $520 ($400 founding), about 1–2 weeks.