[MORSALIN]
Service 6.2Updated September 2026

Security Audit & Hardening for Web Apps (Including Apps Built with AI Tools)

A written-scope security review of one web app and its server, including apps built with Lovable, Bolt or Cursor on Supabase. I check access control, auth, secrets, database rules and server setup, then report findings with fixes and effort. From $650 ($500 founding) for the review, about 1–2 weeks. Email your stack to start.

Built with Lovable, Bolt or Cursor? Run the 12-point self-checkSee a sample report, proposal and weekly update
Price
from $650
Founding
from $500
Timeline
~1–2 weeks
Format
Fixed scope, fixed price
Hours
US Eastern Time, async
01Fit

Who this is for.

A good fit if

  • Founders with paying users who have never had a security review
  • Apps built with AI tools on Supabase or Firebase where you’re unsure who can read which rows
  • Laravel, Nuxt, Go or Python apps on a VPS or cloud VM
  • Agencies who want a white-label review before handing over a build

Common triggers

  • News about leaky AI-built apps, such as the 2025 Lovable/Supabase row-level security issue
  • A customer or investor asks “has anyone reviewed your security?”
  • You’re about to store payments, health or personal data

Not a fit if

  • You need a penetration test, a red team, or a report for a SOC 2, ISO or HIPAA auditor
  • You’ve been hacked right now (contain first; ask about cleanup instead)
  • You need a signed statement that the app is secure
02Scope

What I do, and what you get.

What I do

  • Agree a written scope: which app, which server, which roles, what’s out of bounds
  • Review access control: can user A read or change user B’s data (the most common real flaw)
  • For Supabase apps: check that row-level security is on for every exposed table, that policies match who should see what, and that the service key never reaches the browser
  • Review auth: password storage, sessions, password reset, MFA, admin routes
  • Review secrets, dependencies, uploads, rate limits and security headers
  • Review the server: open ports, SSH, firewall, TLS, patching, backups
  • Standard and Plus: apply the agreed hardening to the server and config

What you get

  • A findings report mapped to the OWASP Top 10 (2025), each item rated with evidence and a fix
  • A prioritized fix list with effort estimates and a fixed quote
  • Standard and Plus: hardening applied, with a before/after checklist
  • Supabase apps: a table-by-table RLS summary
  • Handover notes and a short re-check list you can run yourself

Your part

  • A signed written scope before I start
  • Repo read access, a staging copy, and test accounts for each role
  • Server access (for hardening tiers) and a maintenance window if restarts are needed
  • A decision maker who can approve fixes

Included

  • Code, config, database-rule and server review within the written scope
  • Supabase RLS and key-exposure review
  • Server hardening (Standard, Plus)
  • One re-check of hardening items

Not included

  • Penetration testing, exploitation, social engineering
  • Compliance audits or certificates
  • Fixing app code (Remediation Sprint, quoted)
  • Incident response or forensics
03Plans & price

Fixed prices, agreed before work starts.

ReviewEntry offer
$650
Founding price $500
~1–2 weeks

One app + one server, findings report

Standard
$1,170
Founding price $900
~2–3 weeks

Review plus server and config hardening applied

Plus
$1,820
Founding price $1,400
~4–6 weeks, phased

Multi-node, deeper auth and role review, hardening applied; two monthly milestones of $910 ($700 founding): review, then hardening

Build your scope

1 · Plan
2 · After handover (optional)
Your scope
$650
Timeline
~1–2 weeks
Payment
Paid in full before work starts
Earliest start
Oct 5

The fee is credited in full toward a follow-on project of $1,000+ approved within 30 days.

Not a commitment. I confirm the exact price in a written proposal.

Founding price: 3 of 7 spots left, until Mar 31, 2027 — one-off work, in return for a testimonial. How it works

Prices are in USD, paid by bank transfer against an invoice. Work under $1,000 is paid upfront; larger work is 50% to start and 50% before handover, or monthly milestones. The full fee of this service is credited toward a follow-on project of $1,000 or more that you approve within 30 days.How working together works

Variations

Lovable / Bolt / Supabase
Focus on RLS policies, anon vs service keys, storage buckets and edge functions; I fix SQL policies directly, and front-end changes on stacks I don’t support come as written instructions.
Laravel
Policies and gates, mass assignment, APP_KEY, queue and storage exposure.
Go / Python APIs
Authorization middleware, SSRF on outbound calls, body limits and timeouts.
Multi-node (Plus)
Adds the private network between app and database servers and each node’s firewall.
04Process

How it runs.

  1. 01

    Send your stack

    Email your stack and hosting, and I reply within one US business day with scope questions.

  2. 02

    Sign the scope

    We sign a one-page written scope and you pay the prepaid invoice (50/50 for $1,000+).

  3. 03

    Review on staging

    I review on staging and send questions in batches.

  4. 04

    Report and hardening

    You get the report and fix list, and for hardening tiers I apply the changes in an agreed window.

  5. 05

    Optional fixes

    Book a Remediation Sprint for app-code fixes, and the Review fee is credited toward a $1,000+ project approved within 30 days.

05Proof

Where I have done this before.

06FAQ

Questions buyers ask.

Is this a penetration test?

No. It’s a security review of code, config and servers within a written scope. You get findings, not a guarantee.

My app was built with Lovable. Can you still review it?

Yes. I review any stack; I fix database policies and server config directly and give written fixes for front-end code.

Will you touch production?

Only for hardening tiers, only in an agreed window, and only after a backup.

Can you give us a certificate?

No. I can give you the report to share.

How long are findings valid?

They reflect the code on the review date. New code needs a re-check.

07Start

Ask about Security Audit & Hardening.

Tell me what you have and where it hurts. I reply within one US business day with either a fixed quote or the entry step that makes a fixed quote possible.

Helpful to include

  • Stack (and AI tool used, if any)
  • Hosting
  • Number of user roles
  • Kind of data stored
  • Has anyone reviewed it before?
  • Deadline or trigger
Reply within one US business day. No calls needed.

Prefer your own email app? Write to [email protected]. Your details stay with me, never on a list. An AI model drafts a private summary of your message for me.

More in Testing & Security