+61 448 022 116info@syriant.com
Production Readiness Review · For founders with AI-built apps

Is your Lovable app ready for real users?

Two builders review your code, Supabase set-up and Stripe payments in 48 hours, then give you a fixed price to fix what we find.

US$1,950 fixed · 48 hours · Fee credited against any fix

Sound familiar?

  • Your Supabase tables can be read by anyone with the project URL.
  • A secret key is sitting in the code every visitor downloads.
  • It’s fine in the Lovable preview and broken on your own domain.
  • Stripe takes the payment, but the account never upgrades.
  • You’ve spent more credits fixing the same bug than building the feature.
  • A developer looked at it and said “rebuild it”.

Why this happens

Lovable builds on Supabase, which keeps your data private only when its row-level security rules are switched on and written correctly. In the preview the app runs as you. In production it runs for everyone, and every rule the preview never needed suddenly matters.

None of that is your fault, and none of it is unusual. When security firm Escape scanned more than 5,600 publicly deployed vibe-coded apps, it found more than 2,000 vulnerabilities, over 400 exposed secrets and 175 instances of exposed personal data, including medical records and bank details. Source: Escape, research methodology

What goes wrong in Lovable apps

What it looks like, why, and the fix
→

Tables anyone can read

What it looks like. Customer records, orders or messages can be fetched with nothing more than the project URL and the public key, with no login.

Why it happens. Supabase’s public key is meant to ship to the browser, so privacy rests entirely on row-level security. Generated apps often leave it off, or add a policy that allows everything so the preview works.

The fix. Turn on row-level security for every table, write a policy per table that ties rows to the signed-in user, and test each one as a second user.

→

Secret keys in the browser

What it looks like. A Supabase service-role key, a Stripe secret key or a third-party API key sits in the JavaScript every visitor downloads.

Why it happens. The app was built as a single front end with no server of its own, so anything that needed a secret was called straight from the browser.

The fix. Move those calls into edge functions, keep secrets in the function environment, and rotate every key that was exposed.

→

Works in the preview, broken on your domain

What it looks like. Login links, password resets or Google sign-in loop or fail once the app is on your own domain.

Why it happens. Supabase auth has a site URL and a list of allowed redirect URLs. They were set for the preview domain and never updated.

The fix. Set the production site URL and redirect list, then walk every auth journey on the live domain, not the preview.

→

Stripe takes the money, the account never upgrades

What it looks like. A customer pays, Stripe shows the charge, and the app still treats them as a free user.

Why it happens. Checkout was wired up, but the webhook that tells the database about the payment was never registered, fails signature checks, or writes nothing.

The fix. Register the webhook, verify the Stripe signature, write the entitlement from the server, and test the full flow with Stripe’s test events.

→

Edge functions anyone can call

What it looks like. Functions that send email, charge cards or delete records will run for any caller, signed in or not.

Why it happens. Generated functions often skip the check on the caller’s token, or run with the service-role key, which bypasses every data rule.

The fix. Verify the user’s token at the top of every function and act only on that user’s data.

→

Credits spent fixing the same bug

What it looks like. Each prompt fixes one thing and breaks another. The credit bill grows and the app does not.

Why it happens. There are no tests, so nothing catches a regression, and each fix is a fresh regeneration of code nobody has read.

The fix. The report ranks what to fix and in what order, and we add a handful of tests on the journeys that matter so the next change can be checked.

What is a Production Readiness Review?

A Production Readiness Review is a fixed-price review of an app built with Lovable, carried out by Steve and Oliver Ford at Syriant.

Within 48 hours of read-only access we test your key user journeys and check database access rules, exposed keys, logins, payments and deployment. You get a report ranked by severity, a recorded video walkthrough of your own app, and a fixed price to fix what we find. It costs US$1,950, fixed, and the full fee is credited against fix work of any size.

What you get

→

A report ranked by severity

Every finding in plain English, ranked from “fix today” to “fix eventually”, with the evidence and the fix.

→

A recorded walkthrough of your app

A video of us in your own product, showing each problem as it happens. Watch it when it suits you, and share it with your team.

→

A fixed price to fix it

Not an hourly estimate. A fixed price for the fixes, which you can take to us, your developer, or neither.

→

Fix or rebuild, with the numbers

Most AI-built apps are worth fixing. If yours isn’t, we show you why, with the cost of each path side by side.

→

A one-page summary

For a co-founder, an investor or a buyer who wants the short version.

How it works

  1. 01

    Tell us about your app

    Which tool you built it with, roughly how big it is, and what worries you. We confirm the scope and send an invoice within one business day.

  2. 02

    Share read-only access

    NDA first, then read-only access to the code, database and hosting. No production secrets needed.

  3. 03

    An optional 15-minute call

    If you want one. Otherwise the brief you sent is enough.

  4. 04

    Report and walkthrough in 48 hours

    The clock starts when we have access. We’re in Australia, so your night is our working day.

  5. 05

    You decide

    Fix it with us and the fee is credited, hand the report to your own developer, or do it yourself.

Who does the work

Two people. Both named. Nobody else touches your code.

No account managers and no hand-offs. The two people who review your app are the two who fix it. Steve signs off every report.

Steve Ford

Founder · signs off every report

More than 25 years building and running software. A serial technical co-founder who has built and run his own products, and builds with AI coding tools every day.

LinkedIn →

Oliver Ford

Developer

Builds production apps with AI coding tools every day, specialising in the databases, payments and integrations that turn a working prototype into a product people can rely on.

Who we’ve built for

Clients include
  • Luxury Escapes
  • TRIBE – Travel & Events
  • Daily Blooms
  • Global Reviews
  • Recognix
AI Solution DevelopmentTRIBE – Travel & Events

We came to Syriant with a problem we understood well and no clear idea how to solve it. Verifying event hotel and flight bookings against attendee details was slow and manual, and it needed to be fast and accurate. Steve took that starting point and built CrossChex into an AI-powered platform that solved the problem, and ultimately gave us far more than we originally set out to achieve.

Steve brought much more than technical expertise. He challenged our thinking, identified opportunities we hadn’t considered and continually enhanced the product along the way. He was patient through changes in direction, genuinely collaborative with our team and always focused on getting the best outcome.

Steve became a trusted partner throughout the project and brought expertise we simply didn’t have in-house. I genuinely enjoyed working with him, would absolutely work with him again given the opportunity, and would highly recommend him to anyone looking for both technical expertise and a genuinely collaborative partner.

Kate AshtonGeneral Manager, TRIBE – Travel & Events

Pricing

Fixed price, invoiced in US dollars
Production Readiness Review
US$1,950

One app on one backend. If yours is unusually large, we’ll say so before you pay.

  • Report and recorded walkthrough within 48 hours of read-only access.
  • A fixed price to fix what we find.
  • The full fee is credited against fix work of any size.
Book a review→

One price, whatever we find. Tell us about your app and we’ll confirm the scope before you pay.

Security and access

→

Read-only

We never need write access to review your app.

→

NDA before access

Signed before we see a line of code.

→

No production secrets

We don’t ask for live keys or passwords.

→

Access removed after delivery

You revoke it, and we confirm everything we held is deleted.

What usually goes wrong, by tool

Built with something else?
Lovable
Supabase tables readable by anyone, keys in the browser, Stripe webhooks that never reach the database, edge functions without auth.
Deploys that fail, environment variables missing in production, database changes that never reached the live database, fix loops that burn tokens.
Test and live sharing one database, backups nobody has restored, secrets in code, agent changes nobody reviewed, surprise bills.
Data access rules left open, logic that only runs in the browser, integrations holding live credentials, no way out of the platform.
API routes and server actions without auth checks, secrets exposed to the client, a polished front end with nothing behind it.
Hand-rolled auth, keys in the git history, no tests, three different ways of doing the same thing across the codebase.
Thousands of agent-written lines nobody has read, tests written to pass, keys in commits, auth that was generated rather than designed.
Agent pull requests merged without a real review, tests that miss what matters, dependencies nobody chose, secrets in the repo or logs.

Common questions

What is a Production Readiness Review?

A fixed-price review of an app built with AI coding tools, to find out whether it’s safe and solid enough for real users, real money and real data. We check security, data access, logins, payments and deployment, and give you a fixed price to fix what we find.

Who actually does the work?

Steve and Oliver Ford. Two people, both named on this page, and nobody else touches your code. Steve signs off every report.

What access do you need? Is my code safe?

Read-only access to your code, database and hosting, under an NDA signed before access. We don’t need production secrets, and access is removed when we deliver.

Will you tell me to rebuild?

Only if the numbers say so. We start from fixing what you have, and the report shows the cost of fixing against the cost of rebuilding.

I’m not technical. Will I understand the report?

Yes. The findings are in plain English first, the video shows each problem in your own app, and we’ll take you through it on a call if you want.

Is it really 48 hours?

Yes, from the moment we have read-only access. An unusually large app may take longer, and we’ll tell you before you pay.

Do I have to use you for the fixes?

No. The report works for any developer. If you do use us, the full review fee is credited against the fix work, whatever its size.

What if you don’t find anything serious?

Then you have it in writing from two experienced builders, which is worth having before a launch, a fundraise or a sale.

You’re in Australia. How does that work?

Your night is our working day, billing is in US dollars, and the walkthrough is recorded, so no meeting is needed.

Can I keep building while you review?

Yes. We review a snapshot, and when we fix things we show you how to keep your AI tool from undoing the fixes.

Which tools do you cover?

Lovable, Bolt, Replit, Base44, v0, Cursor, Claude Code and Codex, and apps built with any mix of them. We build with these tools ourselves every day.

Can this help with investor due diligence?

Yes. Investors increasingly ask how an AI-built product was made. For a deeper, investor-led assessment, see our Technical Due Diligence service. Technical Due Diligence →

By Steve and Oliver Ford · Last updated 10 October 2026

Find out what’s really in your app.

Tell us which tool you built it with and what’s worrying you. We’ll confirm the scope and price within one business day.