wwff.tech Let's talk
AI-BUILT APP HARDENING

You built it with AI. Now make sure it won't blow up in your hands.

Independent security and architecture review for apps built with Lovable, Bolt, Replit, Cursor and friends — with a straight answer on whether to keep, fix, or rebuild.

The same handful of mistakes, over and over.

AI coding tools let you ship in a weekend what used to take a team a quarter. They also ship the same handful of mistakes, over and over: keys in the browser, databases anyone can read, logins that only look like they check anything. Most of it is invisible until a customer, an investor, or an attacker finds it first.

Here's the thing most consultants won't tell you: you've already done the hard part. You've worked out what the product should do, and real users have proved it right. That's a matter of taste and judgement, and on that you're the authority, not me. What's left is engineering: making the thing you designed safe, solid, and able to grow.

I find it first. Then I help you fix it — without taking the tools away.

Who it's for

  • Founders whose AI-built MVP now has paying users, or a funding round coming
  • Teams whose internal tool has quietly become business-critical

You probably need this if

  • A customer has sent you a security questionnaire and you don't know the answers
  • Your AI or cloud bill jumped and you can't explain why
  • It works for 10 users and falls over at 50
  • Every fix the AI makes breaks something else
  • You couldn't say where your users' personal data actually lives

How it works

  1. 01

    Defuse

    Automated scans plus expert manual review. You get a prioritised findings report and a Keep / Fix / Rebuild verdict.

    Length
    2–3 days
    Price
    £950, fixed
  2. 02

    Remediate

    I close the critical and high findings, working in your repo with your tools.

    Length
    1–2 weeks
    Price model
    Fixed scope, time-boxed
  3. 03

    Stabilise

    Proper data model, migrations, tests, CI, logging and backups — or a managed rebuild if that was the verdict.

    Length
    2–6 weeks
    Price model
    Scoped per engagement
  4. 04

    Guardrails

    CI security gates, AI rules files tuned to your codebase, and a monthly review so you can keep building fast, safely.

    Length
    Ongoing
    Price model
    Monthly retainer

Most clients start with Defuse, at a fixed £950. It stands on its own: you own the report and can take it to any developer.

What you get from Defuse

It's a full assessment, not a scanner dump — the work and the evidence, for a fixed £950.

  • Attack-surface recon — exposed services, DNS and email, TLS and security headers, and secrets left in public places
  • Automated scanning — static analysis, secret scanning, and a dependency audit for known-vulnerable libraries
  • Manual code and architecture review — a person reading the code, config and data model, for the logic flaws scanners miss
  • A findings report, risk-ranked in plain English, with a Keep / Fix / Rebuild verdict and the reasoning shown
  • A remediation plan your AI tool can follow, in fix order
  • Every scan and recon artefact, annotated — each result marked and explained, so you own the evidence, not just the conclusions
  • A 45-minute walkthrough call, and the report is yours to take to any developer

Want to see one first? Read a sample Defuse report, run against a deliberately flawed demo app.

Questions people ask

Will you tell me to stop using AI?

No. AI-built software is fine; unreviewed software isn't. I help you keep the speed and reduce the risk.

Do you need access to live customer data?

Ideally not. I prefer a staging copy or anonymised data. Where production access is unavoidable, we sign a data processing agreement first. If you have other requirements, talk to me.

Is this a penetration test?

It's broader and earlier: code, configuration, and architecture review. If you need a formal pen test for compliance, I'll tell you, and help you get value from it.

Do you guarantee the app is secure afterwards?

Nobody honestly can. You get a thorough, expert assessment and a clear record of what was checked and what was found or fixed.