Production Audit
De-Risk the Build.
Written diagnosis + Production-Readiness Score in 3 days. No code changes. Free if you build.
actually get
Your AI-generated app has 10,000 paying users next month, and the only person who knows what's broken is you. Three days, one architect, one written PDF — every gap ranked critical / high / moderate / low, with a reproducible demo for each of the top three criticals (not "you might have an RLS issue" — a screen capture of your actual data being read). The cover carries your Production-Readiness Score: your app, 0–100, against the bar production demands.
Every finding comes with a fix-effort estimate, so the report doubles as a budget document — take it to Soatech, your own engineer, or a CTO you're hiring; it's defensible either way. Within 30 days you also get a free re-scan to verify the fixes landed, whoever made them. And the €1,500 fee credits toward any build committed within 30 days — the €3,500 Production Lift, a Feature Sprint, or an MVP Sprint. Worst case: you keep the diagnosis and walk. Best case: the diagnosis was free and you're production-ready a week later.
Hard limits
- Codebase size≤ 50K LOC
- Routes / pages≤ 15
- Integrations≤ 5 third-party
- Tenancy modelSingle or multi-tenant
In every Production Audit
- Production-Readiness Score (0–100) — your app vs the production bar
- Severity-ranked findings with reproducible demos for the top 3 criticals
- Fix-effort estimate per finding — a budget doc any engineer can quote against
- Repo + deployed app review against the 5-pattern checklist (auth, multi-tenant, e2e, security, deploy)
- Written PDF report (10–15 pages) + 30-min walkthrough call
- Free re-scan within 30 days to verify your fixes — yours or anyone's
- Fee credits in full toward any build within 30 days
Explicit exclusions
- Code changes or implementation
- Mobile-native review (responsive web only)
- Compliance certifications (SOC 2, HIPAA, PCI — separate engagement)
- Performance benchmarking beyond Lighthouse defaults
The plan
Day-by-day, week-by-week
- 1Day 1
Repo + infrastructure review
- Dependency audit (npm audit + Snyk)
- Auth flow walkthrough
- Database schema + RLS policy review
- Webhook signature verification check
- 2Day 2
Deployed-app security + observability scan
- Security headers scan (CSP, HSTS, X-Frame-Options)
- Error tracking presence check
- Rate limiting verification
- Lighthouse + axe-core a11y scan
- 3Day 3
Report + walkthrough
- Written PDF report — Production-Readiness Score on the cover, severity-ranked findings, fix-effort estimates
- 30-min Zoom walkthrough call
- 30-day re-scan window opens (free verification of your fixes)
- Optional: scoping proposal for the credited build conversion
What ships at the end
Concrete deliverables
No slide deck. No "phase 2 proposal." The list below is what hits your repo, your inbox, and your stack on the last day of the engagement.
Founders who want a written, defensible diagnosis before committing to the €3,500 Production Lift. Buyers who like to verify before they trust.
Anyone who already knows their prototype needs the Lift — book the Lift directly and save €1,500 of friction time. Compliance-driven audits (SOC 2 etc.) — that's a separate engagement.
This Production Audit fee (€1,500) converts toward a Production Lift (€3,500) if you commit within 30 days.
Frequently asked
Questions, answered
- What's the 5-pattern production checklist?
- Auth security (NextAuth cookie locking, password reset enumeration, magic-link single-use), multi-tenant data isolation (Row-Level Security at DB layer vs application-layer), e2e test coverage (critical-path Playwright specs), security hardening (CSP, CSRF, rate limiting), and deployment/observability (Vercel/Railway config + error tracking + analytics).
- Will you actually fix what you find?
- Not in the Audit — the Audit is diagnosis only. To fix the findings, convert the €1,500 Audit fee toward the €3,500 Production Lift (1 week, fixed-price implementation of the audit recommendations) — or toward a Feature Sprint or MVP Sprint if the findings call for a bigger build.
- How does the conversion work?
- If you commit to any build within 30 days of receiving the Audit report — Production Lift, Feature Sprint, or any MVP Sprint tier — the €1,500 Audit fee becomes a credit toward that build. Example: net Production Lift cost €2,000, net MVP Sprint Standard cost €11,400. After 30 days the credit expires.
- Other studios offer free audits. Why is this one paid?
- Look at what the free ones actually are: a 30-minute qualifying call or a bucket estimate — a sales motion, not a diagnosis. The Production Audit is three architect-days producing a written, severity-ranked report with a Production-Readiness Score, reproducible demos of the top critical issues, and a fix-effort estimate per finding — a document you can hand to an investor, a CTO, or any engineer you hire instead of us. And if you do proceed to a build within 30 days, the fee credits in full, so for buyers who build, the diagnosis ends up free. If you want a taste first, ask for the free 5-bullet mini-teardown of your live app — no call required.
- Can't I just ask Claude or Cursor to audit my code?
- You should — it's a useful first pass, and it's how many clients find us. What self-serve AI can't give you: verification against your live deployed app (not just the repo), reproducible demos of actual exploits rather than hypothetical warnings, fix-effort estimates calibrated by someone who ships production systems, and a named senior architect accountable for the findings — a report an investor or technical co-founder will accept. The Audit is what you use when the answer has to be right.
Keep reading
Related from the blog
5 Ways Bolt & Lovable Apps Fail in Production
Real anti-patterns from Bolt/Lovable exports that fail when paying users arrive: app-layer tenancy, mock auth, missing webhook verification, generic error handlers, no a11y. Each with the production fix.
AI-Generated Code Quality: What Founders Need to Know
AI generated code quality varies wildly. Learn about security vulnerabilities, technical debt, testing gaps, and why code review matters more than ever.
The Best Vibe Coding Tools in 2026: A Founder's Guide
Compare the best vibe coding tools in 2026: Cursor, Bolt, v0, Replit Agent, Claude Code, and more. Find the right tool for your project.
07Book · Direct, no SDR
Scope your project. Same architect who shipped wintura.ai.
30-minute scoping call. We map your scope to a published tier — Production Audit €1,500, Production Lift €3,500, MVP Sprint from €8,500. No custom quotes. No discovery-call upsell. Walk away with a price and a date.
30-min scoping call
Direct line to the Architect. No SDR. No nurture sequence. No custom quotes. Walk away with a price and a date.
Architect calendar opens 14 days out · Average reply within 4 business hours · CET overlap with UK / Western Europe / Nordics
- CET available · async time-zone friendly
- Calendar invite + Google Meet auto-sent
- Blueprint fee converts to Sprint One
- 30 minutes · free
All tracks