Skip to content
CMD CNTR

AI app rescue

Your AI-built app works in the demo and breaks in production

We audit and stabilise apps built with Lovable, Bolt.new, Cursor, v0, Replit. You get a written verdict on whether to fix or rebuild before you pay for either, and you keep the repository whatever you decide.

Lovable Bolt.new Cursor v0 Replit

What we find, in the order we find it

These are not hypotheticals. Each one is something we have written up in detail, linked below, rather than a scare we invented for a sales page.

  • Auth that was never really there

    Generated auth tends to check the session in the component and nowhere else, so the API answers anyone who asks it directly. It is the first thing we look at and the most common thing we find.

  • Secrets shipped to the browser

    Service keys pasted into client code because that is where the generator put them. Anyone who opens devtools has your database.

  • Nothing tested, nothing handled

    No error handling and no tests, so the first input the demo never tried takes the app down in front of a real user.

  • Sprawl nobody can safely change

    Copy-pasted patterns and tangled state that neither you nor the next prompt can edit without breaking three other things.

How a rescue actually runs

  1. Send the repo as it is

    Half-finished branches, hardcoded keys, console logs and all. Tidying it first only hides what we need to see.

  2. We read it and tell you which it is

    A written audit that ranks what is critical, what is risky, and what can wait, and says plainly whether this is a fix or a rebuild. If it is a rebuild, we say so even though a fix would bill fewer hours.

  3. Stabilise in priority order

    Auth, secrets, and access control before anything cosmetic. Tests go on the paths that take money or data, not everywhere.

  4. Hand it back

    You get the repo, the audit, and the reasoning. If you want us to keep going we are here, and if you do not, nothing is held hostage.

Where we are different, and where we are not

Most rescue shops sell a fixed one-to-three-week sprint after a free audit. The free audit is the right idea and we do it too. The fixed sprint is where we differ.

Hours that never expire, not a sprint

The field sells fixed one-to-three-week sprints. We sell hours you spend when the work is there. If the audit says you need six hours, you buy six hours.

The person who reads the code writes the fix

The same senior engineer through audit, fix and handover. Nothing is repackaged and passed to a junior pool.

You keep the repo either way

Your code, your repository, your hosting accounts, including if you read the audit and decide to do the work yourself.

The reasoning, in public

Every failure named above is written up somewhere you can read it without talking to us. Judge the engineering before you judge the pitch.

More of the same thinking in Fix AI code, AI builder guides, and Vibe coding.

Questions we get asked

Which AI builders do you work with?

We work with apps generated by Lovable, Bolt.new, Cursor, v0, Replit. The generator matters less than the stack it emitted, and these all emit stacks we ship in production anyway.

Do you fix it or rebuild it?

We tell you after reading the code, in writing, before you commit to either. If the critical paths are too brittle to patch we say rebuild, even though a patch would bill fewer hours.

What does it cost?

We do not quote a price before reading the code, and we do not sell fixed-length rescue sprints. You buy support hours, they never expire, and you spend them on what the audit found.

Do I keep the code?

Always. Your repository, your hosting accounts, your code, including if you take the audit and do the work yourself.

What do you look at first?

Authentication, secrets, and access control, in that order. Those are the failures that turn into an incident rather than a bug report.

Send us the repo

As it is. We will read it and tell you whether it is a fix or a rebuild, in writing, before you commit to either.