+61 448 022 116info@syriant.com
Production Readiness Review · For founders with AI-built apps

Is your Replit app ready for real users?

Two builders review your code, database set-up, secrets and deployment in 48 hours, then give you a fixed price to fix what we find.

US$1,950 fixed · 48 hours · Fee credited against any fix

Sound familiar?

  • You’re not sure your test and live data are really separate.
  • There are backups, but nobody has tried restoring one.
  • Secrets are sitting in the code, not in the secrets store.
  • The agent changed things you didn’t ask it to.
  • The hosting bill keeps climbing and you don’t know why.
  • A developer looked at it and said “start again”.

Why this happens

Replit gives you the editor, the database, the secrets store and the hosting in one place, and the Agent can change all of them. That makes it quick to ship and easy to end up with one database for everything, keys in code and a deployment nobody has looked at since it went live.

None of that is your fault, and none of it is unusual. When security firm Escape scanned more than 5,600 publicly deployed vibe-coded apps, it found more than 2,000 vulnerabilities, over 400 exposed secrets and 175 instances of exposed personal data, including medical records and bank details. Source: Escape, research methodology

What goes wrong in Replit apps

What it looks like, why, and the fix
→

Test and live data in one database

What it looks like. A change you try in the workspace shows up for customers, or test records appear in the live app.

Why it happens. Apps often start with a single database used by both the workspace and the deployment. Separating them is a step that has to be done on purpose.

The fix. Set up a separate production database, migrate the live data into it, and confirm the deployment points at the right one.

→

Backups nobody has restored

What it looks like. There are checkpoints and backups, and nobody knows whether they would bring the live data back.

Why it happens. A checkpoint restores your workspace. That is not the same as restoring the production database after bad data or a bad deploy.

The fix. Take a backup of the production database, restore it somewhere safe, and write down the steps. Then schedule it.

→

Secrets in the code

What it looks like. API keys and database URLs are written into source files instead of the secrets store.

Why it happens. The Agent or a quick fix pasted the value where it was needed. If the Repl is public or shared, so is the key.

The fix. Move every secret into the secrets store, rotate the ones that were in code, and check the project’s visibility.

→

Changes nobody asked for

What it looks like. The Agent rewrote files, dropped a feature or changed behaviour that had nothing to do with the request.

Why it happens. The Agent edits broadly to make a task work, and without a review step those changes ship with the ones you wanted.

The fix. The report lists what changed and what it affected. We add tests on the key journeys so unrelated changes get caught.

→

Routes anyone can call

What it looks like. Server routes that read or change data respond to any caller, signed in or not.

Why it happens. Generated server code often checks the login on the page and not on the route behind it.

The fix. Check the session on every route that touches data, and return only what that user is allowed to see.

→

A hosting bill that keeps climbing

What it looks like. The monthly bill rises with no matching rise in users.

Why it happens. An always-on deployment, a polling loop, an autoscale setting or a growing database can each cost more than the app needs.

The fix. We find what is running and why, and right-size the deployment to the traffic you actually have.

What is a Production Readiness Review?

A Production Readiness Review is a fixed-price review of an app built with Replit, carried out by Steve and Oliver Ford at Syriant.

Within 48 hours of read-only access we test your key user journeys and check database access rules, exposed keys, logins, payments and deployment. You get a report ranked by severity, a recorded video walkthrough of your own app, and a fixed price to fix what we find. It costs US$1,950, fixed, and the full fee is credited against fix work of any size.

What you get

→

A report ranked by severity

Every finding in plain English, ranked from “fix today” to “fix eventually”, with the evidence and the fix.

→

A recorded walkthrough of your app

A video of us in your own product, showing each problem as it happens. Watch it when it suits you, and share it with your team.

→

A fixed price to fix it

Not an hourly estimate. A fixed price for the fixes, which you can take to us, your developer, or neither.

→

Fix or rebuild, with the numbers

Most AI-built apps are worth fixing. If yours isn’t, we show you why, with the cost of each path side by side.

→

A one-page summary

For a co-founder, an investor or a buyer who wants the short version.

How it works

  1. 01

    Tell us about your app

    Which tool you built it with, roughly how big it is, and what worries you. We confirm the scope and send an invoice within one business day.

  2. 02

    Share read-only access

    NDA first, then read-only access to the code, database and hosting. No production secrets needed.

  3. 03

    An optional 15-minute call

    If you want one. Otherwise the brief you sent is enough.

  4. 04

    Report and walkthrough in 48 hours

    The clock starts when we have access. We’re in Australia, so your night is our working day.

  5. 05

    You decide

    Fix it with us and the fee is credited, hand the report to your own developer, or do it yourself.

Who does the work

Two people. Both named. Nobody else touches your code.

No account managers and no hand-offs. The two people who review your app are the two who fix it. Steve signs off every report.

Steve Ford

Founder · signs off every report

More than 25 years building and running software. A serial technical co-founder who has built and run his own products, and builds with AI coding tools every day.

LinkedIn →

Oliver Ford

Developer

Builds production apps with AI coding tools every day, specialising in the databases, payments and integrations that turn a working prototype into a product people can rely on.

Who we’ve built for

Clients include
  • Luxury Escapes
  • TRIBE – Travel & Events
  • Daily Blooms
  • Global Reviews
  • Recognix
AI Solution DevelopmentTRIBE – Travel & Events

We came to Syriant with a problem we understood well and no clear idea how to solve it. Verifying event hotel and flight bookings against attendee details was slow and manual, and it needed to be fast and accurate. Steve took that starting point and built CrossChex into an AI-powered platform that solved the problem, and ultimately gave us far more than we originally set out to achieve.

Steve brought much more than technical expertise. He challenged our thinking, identified opportunities we hadn’t considered and continually enhanced the product along the way. He was patient through changes in direction, genuinely collaborative with our team and always focused on getting the best outcome.

Steve became a trusted partner throughout the project and brought expertise we simply didn’t have in-house. I genuinely enjoyed working with him, would absolutely work with him again given the opportunity, and would highly recommend him to anyone looking for both technical expertise and a genuinely collaborative partner.

Kate AshtonGeneral Manager, TRIBE – Travel & Events

Pricing

Fixed price, invoiced in US dollars
Production Readiness Review
US$1,950

One app on one backend. If yours is unusually large, we’ll say so before you pay.

  • Report and recorded walkthrough within 48 hours of read-only access.
  • A fixed price to fix what we find.
  • The full fee is credited against fix work of any size.
Book a review→

One price, whatever we find. Tell us about your app and we’ll confirm the scope before you pay.

Security and access

→

Read-only

We never need write access to review your app.

→

NDA before access

Signed before we see a line of code.

→

No production secrets

We don’t ask for live keys or passwords.

→

Access removed after delivery

You revoke it, and we confirm everything we held is deleted.

What usually goes wrong, by tool

Built with something else?
Supabase tables readable by anyone, keys in the browser, Stripe webhooks that never reach the database, edge functions without auth.
Deploys that fail, environment variables missing in production, database changes that never reached the live database, fix loops that burn tokens.
Replit
Test and live sharing one database, backups nobody has restored, secrets in code, agent changes nobody reviewed, surprise bills.
Data access rules left open, logic that only runs in the browser, integrations holding live credentials, no way out of the platform.
API routes and server actions without auth checks, secrets exposed to the client, a polished front end with nothing behind it.
Hand-rolled auth, keys in the git history, no tests, three different ways of doing the same thing across the codebase.
Thousands of agent-written lines nobody has read, tests written to pass, keys in commits, auth that was generated rather than designed.
Agent pull requests merged without a real review, tests that miss what matters, dependencies nobody chose, secrets in the repo or logs.

Common questions

What is a Production Readiness Review?

A fixed-price review of an app built with AI coding tools, to find out whether it’s safe and solid enough for real users, real money and real data. We check security, data access, logins, payments and deployment, and give you a fixed price to fix what we find.

Who actually does the work?

Steve and Oliver Ford. Two people, both named on this page, and nobody else touches your code. Steve signs off every report.

What access do you need? Is my code safe?

Read-only access to your code, database and hosting, under an NDA signed before access. We don’t need production secrets, and access is removed when we deliver.

Will you tell me to rebuild?

Only if the numbers say so. We start from fixing what you have, and the report shows the cost of fixing against the cost of rebuilding.

I’m not technical. Will I understand the report?

Yes. The findings are in plain English first, the video shows each problem in your own app, and we’ll take you through it on a call if you want.

Is it really 48 hours?

Yes, from the moment we have read-only access. An unusually large app may take longer, and we’ll tell you before you pay.

Do I have to use you for the fixes?

No. The report works for any developer. If you do use us, the full review fee is credited against the fix work, whatever its size.

What if you don’t find anything serious?

Then you have it in writing from two experienced builders, which is worth having before a launch, a fundraise or a sale.

You’re in Australia. How does that work?

Your night is our working day, billing is in US dollars, and the walkthrough is recorded, so no meeting is needed.

Can I keep building while you review?

Yes. We review a snapshot, and when we fix things we show you how to keep your AI tool from undoing the fixes.

Which tools do you cover?

Lovable, Bolt, Replit, Base44, v0, Cursor, Claude Code and Codex, and apps built with any mix of them. We build with these tools ourselves every day.

Can this help with investor due diligence?

Yes. Investors increasingly ask how an AI-built product was made. For a deeper, investor-led assessment, see our Technical Due Diligence service. Technical Due Diligence →

By Steve and Oliver Ford · Last updated 10 October 2026

Find out what’s really in your app.

Tell us which tool you built it with and what’s worrying you. We’ll confirm the scope and price within one business day.