A key in the browser
A secret key in a NEXT_PUBLIC_ variable or client code. Anyone can copy it from the page and use it.
You built your app with an AI coding agent. It works. But does it only work for the right people? Send me your repo and live URL. Within 5 business days you get a written report: what's critical, what can wait, and exactly how to fix each one. No call needed.
A secret key in a NEXT_PUBLIC_ variable or client code. Anyone can copy it from the page and use it.
A table without Row Level Security, or a policy that lets users edit columns they should never touch. Like their own plan.
An action that takes the user ID from the request instead of the session. Change one value, act as someone else.
The app works in every case. That's why nobody notices.
.env handling, NEXT_PUBLIC_ variables, where the secret key is used, and a scan of your Git history.
RLS on every table, a policy per action, protected columns, and whether user A can reach user B's data.
Every Server Action and API route checks login, ownership and input, and takes the user from the session.
Redirect URLs, production site URL, email sender and rate limits on sign-in and sign-up.
Webhook signatures, plan changes only from the server, AI keys server-side, limits and spending caps.
Separate dev and production, environment variables, error tracking, and whether you can roll back.
npm audit and known vulnerable packages.
supabase/migrations/20260912_profiles.sqlCheckout takes a minute.
Your live URL, repo, what the app does and what worries you most.
Add davidtacer to your repo on GitHub, or send a ZIP link without .env files.
Within 5 business days of receiving the form and access.
Secret keys, .env files, database passwords or customer data. Your code and migrations are enough. If something needs production access, I'll tell you what to check yourself.
I've spent 15 years building, shipping and fixing production software for startups and businesses. I use AI coding agents every day. Lately a lot of my work is rescuing AI-built apps that fell apart once real users showed up: leaked keys, open databases, fixes that broke three other things. None of it was the AI's fault. Nobody showed the builder the part engineers do. This guide is that part: planning, testing, security and shipping safely, written so you can do it yourself.
I made this guide the same way it teaches you to build: I set the structure, the method and the standards, AI drafted, and I reviewed, corrected and tested every step and command before it went in.
For apps on Next.js, Supabase and Vercel.
Plus VAT where applicable.
3 reviews per week. If your app isn't a fit, you get a full refund before I start. After payment you'll get a link to the short form.
No. Everything happens through the form and the report. If something in your answers is unclear, I'll email you one question instead of guessing.
Within 5 business days after I receive your form and access to your code.
I use it only for your review and never share it. On personal GitHub repositories, GitHub gives collaborators write access; I only read and never push. Remove me as soon as you get the report, or send a ZIP link instead.
Not yet. If you book anyway, I'll refund you in full before starting. If it's a larger app or a company product on another stack, I also do full audits: davidtacer.com.
The report tells you exactly what to change and gives you a prompt for each fix, so you can do it with your agent. If you'd rather have it done for you, reply to the report and I'll send a separate quote.
If your app isn't a fit, you get a full refund before I start. Once the review has started, it's non-refundable, because the work is being done for you.
No. The review follows the same method and checklists as the guide, but it stands on its own.