The three things that would hurt you first
Ranked, not listed. If your database is readable by anyone holding the key that ships in your own JavaScript, that goes at the top and the other two wait behind it.
Free teardown
You got it to roughly 90% with Lovable, Cursor, Claude Code or something like it. It runs. You are not sure whether it survives contact with real users. Paste a link below and I will spend about an hour reading it, then write back the three things that would hurt you first — with the file each one lives in and what to change it to.
No pitch deck, no discovery questionnaire, no procurement process. One link and one sentence.
Ranked, not listed. If your database is readable by anyone holding the key that ships in your own JavaScript, that goes at the top and the other two wait behind it.
File paths, the actual policy or config that is wrong, and what to change it to. Not "consider improving your security posture".
Just as useful. If your auth is solid and your data model holds up, you should know that instead of paying someone to rewrite it.
It arrives as a document you can read and act on alone. Book a call if you want to talk it through, but nothing is withheld until you do.
Because I am building this practice and I need reference work and testimonials more than I need your money right now. That is the whole reason. You are getting an hour of senior engineering time in exchange for permission to say we worked together, and I am fine with that trade.
I am doing a limited number of these. When I stop, this page comes down.
An hour finds the things that matter most. It is not a full audit and I will not pretend otherwise.
If you want the complete version — every route read, every gap costed, a written plan you can actually execute against — that is the paid review at €750, and it comes off the build price if you continue. If you just want the free teardown and then to fix everything yourself, that is a completely fine outcome.
A written document naming the three most serious things standing between your build and real users, ranked, each with the file or setting it lives in and what to change it to. Usually a page and a half. It arrives by email within two business days.
No. That is the point. Send the repo, read what comes back, and decide afterwards whether talking is worth your time. Plenty of people take the findings and fix everything themselves, which is a completely fine outcome.
A GitHub link with read access, or a zip. If it is deployed, the URL helps. One line on what the app does and who is meant to use it. Nothing else — no questionnaire, no discovery form.
I will sign an NDA before you send anything, if you ask. I only read what you give me — no probing or testing your live systems. You keep your repo, your IP and your accounts, and nothing about your build is ever published without your approval.
Because three is what an hour of honest reading produces, and because a list of forty is a way of hiding that none of them were prioritised. If there are only two things wrong, you get two.
I am building this practice and need reference work and testimonials more than I need your money right now. You get an hour of senior engineering time; I get permission to say we worked together. If you want the complete version afterwards, that is the paid review — and if you do not, nothing happens.
Four fields, one of them a link. I reply within one business day, usually with a question or two, and send the findings within two.
Want an NDA first? Say so in the box and I will send one before you share anything.
Prefer to talk first? Book 30 minutes or email kristian.dienes@ladient.sk.