+61 448 022 116info@syriant.com
Production Readiness Review · For founders with AI-built apps

Is your Codex app ready for real users?

Two builders review the pull requests your agent merged, your tests, dependencies and secrets in 48 hours, then give you a fixed price to fix what we find.

US$1,950 fixed · 48 hours · Fee credited against any fix

Sound familiar?

  • Pull requests from the agent were merged without a real review.
  • The tests pass, but they don’t test what matters.
  • Dependencies were added that nobody chose.
  • Secrets ended up in the repo or the logs.
  • Auth and permissions were generated, not designed.
  • You can’t tell which parts are safe to change.

Why this happens

Codex works in a cloud sandbox and hands you a pull request. When the checks are green it is tempting to merge, and over time the repo fills with changes that passed their own tests and were never really read. The sandbox also cannot reach your real services, so what the tests prove and what production does can drift apart.

None of that is your fault, and none of it is unusual. When security firm Escape scanned more than 5,600 publicly deployed vibe-coded apps, it found more than 2,000 vulnerabilities, over 400 exposed secrets and 175 instances of exposed personal data, including medical records and bank details. Source: Escape, research methodology

What goes wrong in Codex apps

What it looks like, why, and the fix
→

Pull requests merged on green

What it looks like. The repo history is a run of agent pull requests, each merged minutes after it opened.

Why it happens. The checks passed, the description read well, and reading the diff takes longer than merging it.

The fix. We read the merged changes that touch auth, data and payments. Then branch protection and a real review on anything that touches those again.

→

Tests that miss what matters

What it looks like. The suite is green and the integration with your database, payments or email is where the bugs are.

Why it happens. The sandbox cannot reach real services, so the agent mocked them, and the tests prove the mocks work.

The fix. Add integration tests on the key flows that run against real test accounts, and keep the mocks for everything else.

→

Dependencies nobody chose

What it looks like. The lockfile has grown with packages nobody can explain.

Why it happens. The agent adds whatever package solves the task, without checking whether it is maintained, licensed suitably or already covered by something in the project.

The fix. Audit the dependency list, remove what is unused, and update or replace what is vulnerable.

→

Secrets in the repo or the logs

What it looks like. A key is in a committed file, a pull request description or a task log.

Why it happens. The agent reads environment values to do its work, and they can end up in its output.

The fix. Rotate the key, scrub it from history and logs, and give the agent only the values it needs.

→

Auth that was generated, not designed

What it looks like. Permission checks differ from endpoint to endpoint, with gaps between them.

Why it happens. Each task added its own check with no single model of who can do what.

The fix. Write down the roles, put the check in one place, and test the app as each role.

→

Nobody knows what is safe to change

What it looks like. Small changes have wide effects, so nobody wants to touch anything.

Why it happens. The codebase grew one pull request at a time, faster than anyone’s understanding of it.

The fix. The report includes a plain-English map of the codebase and what depends on what.

What is a Production Readiness Review?

A Production Readiness Review is a fixed-price review of an app built with Codex, carried out by Steve and Oliver Ford at Syriant.

Within 48 hours of read-only access we test your key user journeys and check database access rules, exposed keys, logins, payments and deployment. You get a report ranked by severity, a recorded video walkthrough of your own app, and a fixed price to fix what we find. It costs US$1,950, fixed, and the full fee is credited against fix work of any size.

What you get

→

A report ranked by severity

Every finding in plain English, ranked from “fix today” to “fix eventually”, with the evidence and the fix.

→

A recorded walkthrough of your app

A video of us in your own product, showing each problem as it happens. Watch it when it suits you, and share it with your team.

→

A fixed price to fix it

Not an hourly estimate. A fixed price for the fixes, which you can take to us, your developer, or neither.

→

Fix or rebuild, with the numbers

Most AI-built apps are worth fixing. If yours isn’t, we show you why, with the cost of each path side by side.

→

A one-page summary

For a co-founder, an investor or a buyer who wants the short version.

How it works

  1. 01

    Tell us about your app

    Which tool you built it with, roughly how big it is, and what worries you. We confirm the scope and send an invoice within one business day.

  2. 02

    Share read-only access

    NDA first, then read-only access to the code, database and hosting. No production secrets needed.

  3. 03

    An optional 15-minute call

    If you want one. Otherwise the brief you sent is enough.

  4. 04

    Report and walkthrough in 48 hours

    The clock starts when we have access. We’re in Australia, so your night is our working day.

  5. 05

    You decide

    Fix it with us and the fee is credited, hand the report to your own developer, or do it yourself.

Who does the work

Two people. Both named. Nobody else touches your code.

No account managers and no hand-offs. The two people who review your app are the two who fix it. Steve signs off every report.

Steve Ford

Founder · signs off every report

More than 25 years building and running software. A serial technical co-founder who has built and run his own products, and builds with AI coding tools every day.

LinkedIn →

Oliver Ford

Developer

Builds production apps with AI coding tools every day, specialising in the databases, payments and integrations that turn a working prototype into a product people can rely on.

Who we’ve built for

Clients include
  • Luxury Escapes
  • TRIBE – Travel & Events
  • Daily Blooms
  • Global Reviews
  • Recognix
AI Solution DevelopmentTRIBE – Travel & Events

We came to Syriant with a problem we understood well and no clear idea how to solve it. Verifying event hotel and flight bookings against attendee details was slow and manual, and it needed to be fast and accurate. Steve took that starting point and built CrossChex into an AI-powered platform that solved the problem, and ultimately gave us far more than we originally set out to achieve.

Steve brought much more than technical expertise. He challenged our thinking, identified opportunities we hadn’t considered and continually enhanced the product along the way. He was patient through changes in direction, genuinely collaborative with our team and always focused on getting the best outcome.

Steve became a trusted partner throughout the project and brought expertise we simply didn’t have in-house. I genuinely enjoyed working with him, would absolutely work with him again given the opportunity, and would highly recommend him to anyone looking for both technical expertise and a genuinely collaborative partner.

Kate AshtonGeneral Manager, TRIBE – Travel & Events

Pricing

Fixed price, invoiced in US dollars
Production Readiness Review
US$1,950

One app on one backend. If yours is unusually large, we’ll say so before you pay.

  • Report and recorded walkthrough within 48 hours of read-only access.
  • A fixed price to fix what we find.
  • The full fee is credited against fix work of any size.
Book a review→

One price, whatever we find. Tell us about your app and we’ll confirm the scope before you pay.

Security and access

→

Read-only

We never need write access to review your app.

→

NDA before access

Signed before we see a line of code.

→

No production secrets

We don’t ask for live keys or passwords.

→

Access removed after delivery

You revoke it, and we confirm everything we held is deleted.

What usually goes wrong, by tool

Built with something else?
Supabase tables readable by anyone, keys in the browser, Stripe webhooks that never reach the database, edge functions without auth.
Deploys that fail, environment variables missing in production, database changes that never reached the live database, fix loops that burn tokens.
Test and live sharing one database, backups nobody has restored, secrets in code, agent changes nobody reviewed, surprise bills.
Data access rules left open, logic that only runs in the browser, integrations holding live credentials, no way out of the platform.
API routes and server actions without auth checks, secrets exposed to the client, a polished front end with nothing behind it.
Hand-rolled auth, keys in the git history, no tests, three different ways of doing the same thing across the codebase.
Thousands of agent-written lines nobody has read, tests written to pass, keys in commits, auth that was generated rather than designed.
Codex
Agent pull requests merged without a real review, tests that miss what matters, dependencies nobody chose, secrets in the repo or logs.

Common questions

What is a Production Readiness Review?

A fixed-price review of an app built with AI coding tools, to find out whether it’s safe and solid enough for real users, real money and real data. We check security, data access, logins, payments and deployment, and give you a fixed price to fix what we find.

Who actually does the work?

Steve and Oliver Ford. Two people, both named on this page, and nobody else touches your code. Steve signs off every report.

What access do you need? Is my code safe?

Read-only access to your code, database and hosting, under an NDA signed before access. We don’t need production secrets, and access is removed when we deliver.

Will you tell me to rebuild?

Only if the numbers say so. We start from fixing what you have, and the report shows the cost of fixing against the cost of rebuilding.

I’m not technical. Will I understand the report?

Yes. The findings are in plain English first, the video shows each problem in your own app, and we’ll take you through it on a call if you want.

Is it really 48 hours?

Yes, from the moment we have read-only access. An unusually large app may take longer, and we’ll tell you before you pay.

Do I have to use you for the fixes?

No. The report works for any developer. If you do use us, the full review fee is credited against the fix work, whatever its size.

What if you don’t find anything serious?

Then you have it in writing from two experienced builders, which is worth having before a launch, a fundraise or a sale.

You’re in Australia. How does that work?

Your night is our working day, billing is in US dollars, and the walkthrough is recorded, so no meeting is needed.

Can I keep building while you review?

Yes. We review a snapshot, and when we fix things we show you how to keep your AI tool from undoing the fixes.

Which tools do you cover?

Lovable, Bolt, Replit, Base44, v0, Cursor, Claude Code and Codex, and apps built with any mix of them. We build with these tools ourselves every day.

Can this help with investor due diligence?

Yes. Investors increasingly ask how an AI-built product was made. For a deeper, investor-led assessment, see our Technical Due Diligence service. Technical Due Diligence →

By Steve and Oliver Ford · Last updated 10 October 2026

Find out what’s really in your app.

Tell us which tool you built it with and what’s worrying you. We’ll confirm the scope and price within one business day.