Pre-Launch Review · For apps built with AI

Before real users find the holes, let an engineer look.

You built your app with an AI coding agent. It works. But does it only work for the right people? Send me your repo and live URL. Within 5 business days you get a written report: what's critical, what can wait, and exactly how to fix each one. No call needed.

For apps on Next.js, Supabase and Vercel. Limited to 3 reviews per week.
The problem

After launch, these are incidents. Before launch, they're a to-do list.

✕ SECRETS

A key in the browser

A secret key in a NEXT_PUBLIC_ variable or client code. Anyone can copy it from the page and use it.

✕ DATABASE

A database that trusts everyone

A table without Row Level Security, or a policy that lets users edit columns they should never touch. Like their own plan.

✕ SERVER

A server that believes the browser

An action that takes the user ID from the request instead of the session. Change one value, act as someone else.

The app works in every case. That's why nobody notices.

The review

What I check

01

Secrets & keys

.env handling, NEXT_PUBLIC_ variables, where the secret key is used, and a scan of your Git history.

02

Database rules

RLS on every table, a policy per action, protected columns, and whether user A can reach user B's data.

03

Server code

Every Server Action and API route checks login, ownership and input, and takes the user from the session.

04

Auth & email

Redirect URLs, production site URL, email sender and rate limits on sign-in and sign-up.

05

Payments & AI (if you have them)

Webhook signatures, plan changes only from the server, AI keys server-side, limits and spending caps.

06

Deploy & production

Separate dev and production, environment variables, error tracking, and whether you can roll back.

07

Dependencies

npm audit and known vulnerable packages.

The report

What you get

  • A written report (PDF), findings ranked Critical, Important and Nice to have.
  • For each finding: what it is, where it is (file and line), why it matters in plain words, and how to fix it.
  • A copy-ready prompt for your AI agent with every fix.
  • A short screen recording (about 10 minutes) walking through the top findings.
  • One follow-up check: fix the critical findings within 30 days, send me the commit, and I'll confirm they're fixed.
Example of the report format (not a real client)
CRITICAL · DATABASE

Users can upgrade themselves to Pro

Wheresupabase/migrations/20260912_profiles.sql
WhatThe update policy on profiles lets users change every column, including plan.
Why it mattersAnyone can open the browser console and set their own plan to "pro" without paying.
FixLimit which columns users can update with a column grant, and change plan only from the verified Stripe webhook.
Prompt for your agent
Create a new migration that revokes update on public.profiles from authenticated and grants update only on display_name and avatar_path. Show me the SQL. Do not apply it.
The process

How it works. No call needed.

  1. 01

    Book and pay.

    Checkout takes a minute.

  2. 02

    Fill in a short form.

    Your live URL, repo, what the app does and what worries you most.

  3. 03

    Share your code.

    Add davidtacer to your repo on GitHub, or send a ZIP link without .env files.

  4. 04

    Get your report.

    Within 5 business days of receiving the form and access.

Never send me

Secret keys, .env files, database passwords or customer data. Your code and migrations are enough. If something needs production access, I'll tell you what to check yourself.

This is for you if

  • Your app runs on Next.js, Supabase and Vercel.
  • You're about to launch, or just launched and want to sleep better.
  • It's one app of small to medium size (up to about 15 database tables).
  • You want to fix things yourself, with clear instructions.

It's not for you if

  • Your app uses a different stack (Firebase, PHP, native mobile).
  • You need a full audit of a large codebase. For that, see davidtacer.com.
  • You're looking for a guarantee that your app has no bugs. A review finds problems. It can't promise there are none left.
Who's behind this

David Tacer

I've spent 15 years building, shipping and fixing production software for startups and businesses. I use AI coding agents every day. Lately a lot of my work is rescuing AI-built apps that fell apart once real users showed up: leaked keys, open databases, fixes that broke three other things. None of it was the AI's fault. Nobody showed the builder the part engineers do. This guide is that part: planning, testing, security and shipping safely, written so you can do it yourself.

I made this guide the same way it teaches you to build: I set the structure, the method and the standards, AI drafted, and I reviewed, corrected and tested every step and command before it went in.

Book a review

One review. One written report.

For apps on Next.js, Supabase and Vercel.

Pre-Launch Review
$299one-time

Plus VAT where applicable.

  • Review of security, database rules, server code and deploy
  • Written report with ranked findings and file references
  • A copy-ready AI prompt for every fix
  • 10-minute screen recording of the top findings
  • One follow-up check of your critical fixes within 30 days
Book a review

3 reviews per week. If your app isn't a fit, you get a full refund before I start. After payment you'll get a link to the short form.

FAQ

Questions before you start

Do we need a call?

No. Everything happens through the form and the report. If something in your answers is unclear, I'll email you one question instead of guessing.

How long does it take?

Within 5 business days after I receive your form and access to your code.

Is my code safe with you?

I use it only for your review and never share it. On personal GitHub repositories, GitHub gives collaborators write access; I only read and never push. Remove me as soon as you get the report, or send a ZIP link instead.

My app isn't on Next.js, Supabase and Vercel. Can I still book?

Not yet. If you book anyway, I'll refund you in full before starting. If it's a larger app or a company product on another stack, I also do full audits: davidtacer.com.

Can you fix the problems for me?

The report tells you exactly what to change and gives you a prompt for each fix, so you can do it with your agent. If you'd rather have it done for you, reply to the report and I'll send a separate quote.

Can I get a refund?

If your app isn't a fit, you get a full refund before I start. Once the review has started, it's non-refundable, because the work is being done for you.

Do I need to buy Vibe Coding 101 first?

No. The review follows the same method and checklists as the guide, but it stands on its own.

Launch knowing what's behind the button.

Book a review · $299