The demo works. Production is a different sport.

AI tools are genuinely good at getting an app to the point where it demos well. They're much less reliable at the parts nobody sees in a demo: who can read whose data, what happens when a payment webhook fires twice, where the API keys ended up, and whether the database survives its first ten thousand rows.

I use the same AI tools every day, so I know exactly where they cut corners. A rescue starts with an audit that tells you, in plain language, what's safe, what's risky, and what it costs to fix. Then I fix the critical issues myself, or with your team, and stay on as the senior reviewer if you want someone accountable for what ships next.

What the audit covers

Security & access

Authentication, authorization, row-level security, secrets in client bundles, input validation, injection, and webhook verification.

Data & payments

Schema design, migrations, backups, idempotent payment and webhook handling, and what happens to data when something fails halfway.

Reliability

Error handling, retries, rate limits, logging, and monitoring, so you find out about problems before your customers do.

Speed & cost

Core Web Vitals, slow queries, caching, bundle size, and AI token spend that quietly grows with every new user.

Code health

Types, duplication, dead code, dependency risk, and whether the next engineer (or the next AI session) can change it safely.

Shipping

Environments, CI, preview deploys, tests on the flows that make money, and a rollback plan for when a release goes wrong.

How a rescue works

  • Audit. Fixed scope, fixed fee. You get a written report with every finding ranked by severity, with effort estimates in plain language.
  • Harden. I fix the critical and high-risk issues first: the ones that could leak data, lose money, or take the app down.
  • Own. Optional: I stay on as the senior engineer who reviews every change, so your team (and your AI tools) can keep shipping fast without reopening the holes.

Stacks I work in

Next.js · React
Nuxt · Vue
TypeScript
Node.js
Supabase
PostgreSQL · Neon
Drizzle ORM
Stripe
Vercel · Cloudflare
Claude · Gemini APIs
Playwright

Frequently asked

Do I have to rewrite it?

Rarely. Most of an AI-built codebase is usually fine. The risk tends to concentrate in a few places: auth, data access, payments, and anything that touches secrets. The audit tells you exactly where, so you fix what matters instead of starting over.

My app was built with Lovable, Bolt, v0, or Replit. Can you work with that?

Yes. If it's a React, Next.js, Vue, or Nuxt app with a Node or Supabase backend, I can work with it directly. If a tool locks the code in, part of the audit is getting it into a repository you actually own.

How long does an audit take, and what does it cost?

It depends on the size of the codebase, so I scope it on a free 30-minute call and quote a fixed fee before any work starts. No hourly surprises.

Will you tell me if it isn't worth saving?

Yes. If rebuilding is cheaper than fixing, you'll hear that plainly, with the reasons. You'll get a straight answer either way.

Can you work alongside my team?

Yes, and that's often the best setup. Your team keeps shipping; I review, fix the hard parts, and leave behind the tests and guardrails that keep the app healthy.