Security Audit & Hardening for Web Apps (Including Apps Built with AI Tools)
A written-scope security review of one web app and its server, including apps built with Lovable, Bolt or Cursor on Supabase. I check access control, auth, secrets, database rules and server setup, then report findings with fixes and effort. From $650 ($500 founding) for the review, about 1–2 weeks. Email your stack to start.
Built with Lovable, Bolt or Cursor? Run the 12-point self-checkSee a sample report, proposal and weekly update- Price
- from $650
- Founding
- from $500
- Timeline
- ~1–2 weeks
- Format
- Fixed scope, fixed price
- Hours
- US Eastern Time, async
Who this is for.
A good fit if
- Founders with paying users who have never had a security review
- Apps built with AI tools on Supabase or Firebase where you’re unsure who can read which rows
- Laravel, Nuxt, Go or Python apps on a VPS or cloud VM
- Agencies who want a white-label review before handing over a build
Common triggers
- News about leaky AI-built apps, such as the 2025 Lovable/Supabase row-level security issue
- A customer or investor asks “has anyone reviewed your security?”
- You’re about to store payments, health or personal data
Not a fit if
- You need a penetration test, a red team, or a report for a SOC 2, ISO or HIPAA auditor
- You’ve been hacked right now (contain first; ask about cleanup instead)
- You need a signed statement that the app is secure
What I do, and what you get.
What I do
- Agree a written scope: which app, which server, which roles, what’s out of bounds
- Review access control: can user A read or change user B’s data (the most common real flaw)
- For Supabase apps: check that row-level security is on for every exposed table, that policies match who should see what, and that the service key never reaches the browser
- Review auth: password storage, sessions, password reset, MFA, admin routes
- Review secrets, dependencies, uploads, rate limits and security headers
- Review the server: open ports, SSH, firewall, TLS, patching, backups
- Standard and Plus: apply the agreed hardening to the server and config
What you get
- A findings report mapped to the OWASP Top 10 (2025), each item rated with evidence and a fix
- A prioritized fix list with effort estimates and a fixed quote
- Standard and Plus: hardening applied, with a before/after checklist
- Supabase apps: a table-by-table RLS summary
- Handover notes and a short re-check list you can run yourself
Your part
- A signed written scope before I start
- Repo read access, a staging copy, and test accounts for each role
- Server access (for hardening tiers) and a maintenance window if restarts are needed
- A decision maker who can approve fixes
Included
- Code, config, database-rule and server review within the written scope
- Supabase RLS and key-exposure review
- Server hardening (Standard, Plus)
- One re-check of hardening items
Not included
- Penetration testing, exploitation, social engineering
- Compliance audits or certificates
- Fixing app code (Remediation Sprint, quoted)
- Incident response or forensics
Fixed prices, agreed before work starts.
One app + one server, findings report
Review plus server and config hardening applied
Multi-node, deeper auth and role review, hardening applied; two monthly milestones of $910 ($700 founding): review, then hardening
Build your scope
- Timeline
- ~1–2 weeks
- Payment
- Paid in full before work starts
- Earliest start
- Oct 5
The fee is credited in full toward a follow-on project of $1,000+ approved within 30 days.
Not a commitment. I confirm the exact price in a written proposal.Founding price: 3 of 7 spots left, until Mar 31, 2027 — one-off work, in return for a testimonial. How it works
Prices are in USD, paid by bank transfer against an invoice. Work under $1,000 is paid upfront; larger work is 50% to start and 50% before handover, or monthly milestones. The full fee of this service is credited toward a follow-on project of $1,000 or more that you approve within 30 days.How working together works
Variations
- Lovable / Bolt / Supabase
- Focus on RLS policies, anon vs service keys, storage buckets and edge functions; I fix SQL policies directly, and front-end changes on stacks I don’t support come as written instructions.
- Laravel
- Policies and gates, mass assignment, APP_KEY, queue and storage exposure.
- Go / Python APIs
- Authorization middleware, SSRF on outbound calls, body limits and timeouts.
- Multi-node (Plus)
- Adds the private network between app and database servers and each node’s firewall.
How it runs.
- 01
Send your stack
Email your stack and hosting, and I reply within one US business day with scope questions.
- 02
Sign the scope
We sign a one-page written scope and you pay the prepaid invoice (50/50 for $1,000+).
- 03
Review on staging
I review on staging and send questions in batches.
- 04
Report and hardening
You get the report and fix list, and for hardening tiers I apply the changes in an agreed window.
- 05
Optional fixes
Book a Remediation Sprint for app-code fixes, and the Review fee is credited toward a $1,000+ project approved within 30 days.
Where I have done this before.
Licensing & Entitlement Platform
Security model I designed and coded: per-column encryption with key rotation, RBAC from a route table, SSRF protection, argon2id and TOTP.
Read the case study →Infrastructure · Go · Remote executionCentralized Fleet Control
Zero inbound ports; agents run signed tasks only.
Read the case study →Questions buyers ask.
Is this a penetration test?
No. It’s a security review of code, config and servers within a written scope. You get findings, not a guarantee.
My app was built with Lovable. Can you still review it?
Yes. I review any stack; I fix database policies and server config directly and give written fixes for front-end code.
Will you touch production?
Only for hardening tiers, only in an agreed window, and only after a backup.
Can you give us a certificate?
No. I can give you the report to share.
How long are findings valid?
They reflect the code on the review date. New code needs a re-check.
Ask about Security Audit & Hardening.
Tell me what you have and where it hurts. I reply within one US business day with either a fixed quote or the entry step that makes a fixed quote possible.
Helpful to include
- Stack (and AI tool used, if any)
- Hosting
- Number of user roles
- Kind of data stored
- Has anyone reviewed it before?
- Deadline or trigger
More in Testing & Security
Pre-launch Readiness Check
A fixed-price review of your app and server before real users arrive. I check security basics, backups, deploys, config, error handling and monitoring, then send a written report with a prioritized fix list and effort estimates. From $520 ($400 founding), delivered in about one week. Email me your stack and launch date to start.
Remediation Sprint
A fixed-price sprint that fixes an agreed list of findings from my audit or assessment (or another reviewer’s report, after a quick check). I fix, test and re-check each item and tell you what’s done. From $650 ($500 founding), delivered in 1–3 weeks. Email the report to start.
Critical Flow Tests
I write automated tests for the flows that must never break, such as signup, login, checkout and billing, and run them in your CI on every push. From $780 ($600 founding) for up to 3 flows, in 2–3 weeks. A good first step before an upgrade or refactor. Email your stack and flows to start.
Accessibility Audit & Fix
A new service: a fixed-price accessibility audit of your web app’s key pages and flows against WCAG 2.2 AA, with automated checks, a keyboard and screen-reader pass, and a ranked fix list, followed by fixes quoted from the audit. Audit from $520 ($400 founding), about 1–2 weeks.