A written review
What we found in your code and what we’d do about each finding, in plain English, before any fixing starts.
AI-built apps
You described an app to an AI tool and got one that works, and that is real progress. We close the gaps that matter once strangers trust it with their details and their money, and put it live at your own address.
Why the last stretch matters
In March 2025 Matt Palmer, then at Replit, tested 1,645 apps from the showcase of Lovable, another AI app builder. In 170 of them, the rules for who may read the database, where an app keeps its records, could not stop a visitor who had not signed in from asking for a whole list of them. The public catalog of security flaws lists it as CVE-2025-48757, an entry Lovable disputes: it says each customer is responsible for their own app’s data.
The builders have added a lot since. Lovable now runs a security scan every time you publish, and its documentation still says those scans “do not replace a thorough security review.” What you built stands. This page is about the stretch that is left.
We start from the assumption that what you built stays: the screens, and the way a booking flows through them. The four findings above are the ones we look for first, and your app may have none of them.
Sometimes a part is quicker to rebuild than to patch. In Stack Overflow’s 2025 survey, 66% of developers said they are frustrated by AI answers that are almost right, the most common complaint, and 45% said debugging AI-written code is more time-consuming. When a part of your app is like that, the review says which part and why, before you agree to anything.
What you’d get
What we found in your code and what we’d do about each finding, in plain English, before any fixing starts.
Each finding says what could go wrong and for whom, so the first hours go to the gap that could hurt a customer most.
Each person signs in as themselves, and the database itself refuses to hand over a record that belongs to someone else.
A booking is marked paid when the payment company tells your server so in a signed message, whatever the browser says.
Your data is copied every night, and we bring one copy back on purpose, so you know it works before you need it.
The app answers at your own address, and the domain, hosting, database, payment account and code are in your business’s name.
A customer sees a page that takes a booking. Whether it deserves their card details is settled underneath, and the tools’ own manuals say so. Lovable’s says secrets can’t be stored safely in code that runs in the browser, and that reverting a version does not roll back database data. Supabase’s says to switch on row-level rules, which decide who may read each record, for every table an app exposes. Stripe’s calls the message it sends your server the most reliable way to confirm you got paid.
In July 2025 an AI agent on Replit deleted the live database of Jason Lemkin, the founder of SaaStr, while he was testing the tool, and Replit’s chief executive called it unacceptable. Lemkin got the data back by restoring an earlier version. Replit’s documentation now says its agent cannot modify a published app’s live database. See what it takes ›
A free call. You describe the problem in your own words, and we tell you honestly whether software is the answer.
A written scope, timeline and price before any work starts.
We design, code and test in phases. You see working software at the end of each one.
We put it live: app stores, hosting, domains, the lot.
Monthly maintenance if you want it: updates, fixes and regular reviews.
It depends on what it holds. A page that keeps nothing about anyone and takes no payments carries little risk. Once it stores customers’ details or takes their money, have a person read the code first. The builders say so themselves: Lovable’s documentation tells you that you are responsible for your app’s security, and suggests a professional review for apps that handle sensitive data.
Try it, and run the checks your builder offers. As of October 2026, Lovable runs a quick security scan every time you publish, and Bolt has a security audit on its paid plans. They catch common gaps. They can’t know your own rules, such as which member of staff may see which customer. The models also still write the gaps: in Veracode’s 2026 report, AI-written code passed 56% of security tests on average, about the same as a year earlier.
We don’t start there. The first step is reading what you have. The written review then sorts it into what stays, what gets fixed and what would be quicker to rebuild, with the reason for each. You decide after reading it.
No. You can keep building new screens in it. Lovable and Bolt can both sync a project’s code with GitHub, a shared home for code, so your changes and ours meet in one place. The app can also stay on the builder’s hosting with your own domain, an address such as yourbusiness.com, attached to it. As of October 2026, Lovable and Bolt both offer that on paid plans. We move an app only when it needs something that hosting can’t give, and the review says so.
That depends on what the review finds, so we don’t guess before reading the code. After a free first call you get a written scope, timeline and price before any work starts. The review comes first, then the fixes in phases, with working software at the end of each.
Two taps and your email. No call to book, no brief to write.
Prefer email? axel.r.diaz@a2g-tech.com