What we look for
AI builds fast.
Production is a different job.
AI tools are genuinely good at getting an idea running in a weekend. The trouble starts when strangers begin using it. These are the issues that come up again and again.
Authentication & access
CRITICALAny signed-in user able to read every other user's records. Admin routes with no role check. API keys shipped inside the frontend for anyone to read.
Payments
CRITICALWebhooks that don't verify signatures, so a fake payment can unlock a paid plan. Subscriptions that never cancel. Refunds that don't reconcile.
Database & data
CRITICALRow-level security switched off or never written. Queries that scan the whole table. No backups, no migrations, no way back from a bad write.
Features that almost work
HIGHFlows that break on the second attempt. Errors that vanish instead of surfacing. Every new feature quietly breaking an old one.
Performance & cost
HIGHFine with ten users, unusable at five hundred. Calls firing in a loop. An infrastructure bill growing faster than the userbase.
Production readiness
HIGHNo error tracking, no tests, no deploy process, no documentation — so nobody, including you, can safely change anything.
Proof
What a human review
actually changes
This is one of the most common problems we find. The code below is an illustrative example — we never publish a client's real code.
The payment anyone can fake
AI-generated
- Accepts any event without checking it came from Stripe
- The same event can be replayed over and over
- Trusts an email address the user controls
Human-reviewed
- Signature verified — only real Stripe events accepted
- Replay protection
- Customer identified by Stripe's own ID
This is the difference. Not "AI code is bad" — what the AI wrote was clean, readable, and did exactly what was asked. It just wasn't asked the right questions.
The health check
Free AI-Code
health check
Send us the repository. We'll identify the issues most likely to
stop your application being production-ready — across:
- Authentication & access control
- Database structure & permissions
- Input validation
- Dependency risk
- Payment & webhook handling
- Exposed keys & credentials
- Performance & query efficiency
- Deployment & error handling
We take a limited number of free reviews each week, so we can read every one properly.
Process
How it works
Send it over
A GitHub link or a zip. Read-only access is all we need.
Our engineers review it
A senior engineer reads the architecture and the code, and identifies what's most likely to cause problems in production.
You get the health check
Written in two parts — one for you, one for a developer. It tells you what we found and what we'd fix first.
Your call
Want us to fix it? You'll get a clear scope and a fixed price in writing before any work starts. Want to hand the report to your own developer instead? Also fine.
Who reviews it
We use AI too. But a human signs off.
Plenty of code-fixing services just run your project through another model and send back whatever comes out. That's how you get a new set of bugs wearing the old ones' clothes.
We read the architecture. We read the code. We run it. AI makes our engineers faster — engineers decide what ships.
And we'll tell you honestly if a rebuild is the better answer — including when that means we're the wrong people for the job.
- Your repository
- An engineer reads itAI assists — it does not decide
- A written report you can act on
Decades of inheriting other people's code
26 years building software. 90 engineers. Two decades of taking over, fixing and maintaining code we didn't originally write.
Most of that work has been white-label for agencies in the US, UK, Canada, Singapore and Australia. AI-generated code is a new flavour of a very old problem, and one we know well.
Questions
Before you ask
Will you judge my code?
No. Genuinely. You used a tool that promised it would work, and it mostly did. That's not a character flaw, and we're not interested in lecturing anyone.
Should I just rebuild from scratch?
Usually not. You may already have 70, 80, even 90% of what you set out to build, and starting again throws away every decision that was right along with the ones that weren't. Most of what we see needs the production layer that never got written, not a rebuild. We'll tell you honestly which one you're looking at.
Do I need to understand the technical side?
No. The health check comes in two parts — one written for you, one written for a developer. Read whichever you like.
Do I keep ownership of my code?
Yes. Your code remains yours. We handle repository access confidentially and can sign an NDA before review.
What does a fix cost?
It depends on what's wrong, which is what the health check is for. You'll get a clear scope and a fixed price in writing before anyone starts work. No hourly meter.
How fast can you fix it?
Once we've reviewed the code, we'll give you a clear scope and delivery estimate. Urgent issues can be prioritised.
Am I obliged to hire you?
Not at all. Take the health check, hand it to your own developer, and we'll wish you luck. It's yours either way.
What if my code is a total mess?
Then you're in the majority, and we'll tell you plainly whether it's worth saving.