ShoredBook the £550 day

For founders who built with Lovable, Bolt, Replit or v0

Founder-built. Production-ready. Shored up, not rebuilt.

I take founder-built apps from open tables and leaked secrets to tested, migration-gated production, without slowing the founder down.

Who this is for

You built your app with Lovable, Bolt, Replit or v0. It works, it has users, and something has made you nervous: a security warning, a migration that will not apply, a bug that keeps coming back, or an investor asking how solid it is.

Building with Cursor or Claude Code and shipping every day? The retainer is for you: it installs the conventions and gates so the next prompt cannot reopen a hole.

See the retainer

The £550 day

One day. One report. Then a fixed price to fix it.

For £550 ($750) I spend one day inside your repo and your Supabase project, read-only, and hand you a report that says exactly what is load-bearing and how well each piece is protected:

  • Every table: is row-level security on, and do the policy bodies actually restrict anything, or do they say “allow all” to make an error go away?
  • Anonymous and authenticated grants, exposed RPC functions, and any service-role key sitting in the browser bundle.
  • Secrets in the repo and in its history, not just the current commit.
  • Migrations: does the schema exist as code, or is production the only copy?
  • Tests and CI: what would actually turn red if someone broke the important thing.
  • Each risk graded by what it costs you if it goes wrong, with the cheapest adequate fix.

The report ends with a fixed total for the fixing work. Your £550 comes off that total if you go ahead. If you do not, you still have the report and a roadmap you can hand to anyone.

Report within two working days of access. Read-only.

Prices

The day

£550 / $750

One read-only day inside your repo and your Supabase project. Report within two working days of access.

  • Full enforcement-tier report
  • RLS and secrets findings
  • Migrations state
  • Prioritised roadmap
  • Fixed quote for the fixing work

Hardening sprint

£4,500 / $6,000

Up to ten days on the set that matters, shipped as reviewed pull requests while you keep building. The £550 is credited.

  • RLS policies that restrict something
  • Secrets out of the repo and its history
  • Migrations baseline and CI apply
  • Rebuild-from-empty gate
  • Tests and observability

Priced by what it closes, not by the day. If it takes fewer than ten days, the time left goes on the next items from your report. If the day shows the app needs more than ten days, you get a separate fixed quote before anything starts.

Keep-building-safely retainer

£3,000 / $4,000

per month

For founders building with Cursor, Claude Code or a no-code builder who want the guard-rails to stay up. It installs:

  • Conventions file for your AI tooling
  • Agent-ready issue format
  • CI gates
  • Review loop
  • Monthly enforcement sweep

Larger apps quoted up to £4,000.

Prices in GBP and USD. EUR on request.

How it works

  1. 1

    Access

    Read-only GitHub access (or a zip), read-only Supabase project access or a schema dump, and a 20-minute call.

  2. 2

    The day

    One day inside the repo and the database. If I find a live exposure I tell you immediately, before the report, at no extra charge.

  3. 3

    Report and fixed quote

    Within two working days of access you get the report and a fixed total for the fixing work, with the £550 credited if you go ahead.

  4. 4

    Sprint, you keep building

    Fixes go in as reviewed pull requests while you keep using your builder. The sprint leaves you the guard-rails so the next prompt cannot reopen the hole.

Evidence

Two founder-built apps taken from open tables and leaked secrets to tested, migration-gated production, without stopping the founder building:

2

founder-built apps rescued in 2026

1,565

commits across the two rescues

226

pull requests merged in six weeks on one of them

A screenplay-analysis SaaS (React, Supabase, Deno edge functions, LLM pipeline)

Day one: enabled RLS, revoked anonymous grants, purged a committed env file and rotated its keys, baselined the production schema into migrations, moved the model calls server-side. Then a row-level-security test suite, mutation testing on the tests themselves, and a per-call quota chokepoint.

481 commits, 226 pull requests merged, six weeks.

A funded AI media platform (Next.js, Supabase, Vercel, Inngest, image generation)

Stopped password-reset links and database rows being written to logs, turned an accumulated schema into versioned migrations applied by CI on every merge, pinned workflows by SHA, put authentication on portal routes that had none and rate limits on the auth routes, and enabled RLS on the audit tables with a lint guard.

1,084 commits over nine weeks.

My own systems, so you can see how I build:

  • A production scheduler where Postgres row-level security is forced on every table and the app runs as a restricted role, so isolation holds even if the code is wrong.
  • A self-hosted security-testing agent runtime in C# with a policy engine the model cannot bypass, which is the engine behind the audit day.
  • A 2,080-commit product on Azure with LLM evals in CI, built with the autonomous issue loop I install for clients.

Questions

Will you break anything?

The audit is read-only. Fixes only happen after you accept a written quote.

Do I have to stop building?

No. You keep using your builder. The fixes go in as reviewed pull requests, and the sprint leaves you with the guard-rails so the next prompt cannot reopen the hole.

What if the report says it is fine?

Then you have a report that says so, with the evidence, which is what an investor or acquirer will ask for.

Can you fix it today if it is bad?

If the day finds a live exposure, I tell you immediately with the exact policy or key rotation, before the report, at no extra charge. Closing it is a ten-minute job you can do yourself, or I can do it for a fixed quote.

Book the £550 day

One read-only day inside your repo and your Supabase project. Report within two working days of access, then a fixed price to fix what matters, with the day credited.

Calls in UK and European hours, and in US hours from East Coast mornings to Pacific evenings.