For products built with Lovable, Bolt, v0, Cursor or Replit
We build products that ship, scale and get acquired.
We take the product you built with AI the rest of the way.
Async. A short recorded review, three to five blockers named. You keep the findings.
What we do
Strategy, production, agents.
Product Strategy
Decide what to build
Together we decide what to keep and what to rebuild, then make the architecture calls you will live with for the next year. Keeping what you built is the default; any rebuild we propose is justified in writing in the Blueprint.
Production Engineering
The last 20%
The production layer AI coding tools do not reach. We make your product secure and ready to scale, with code you, and any engineer you hire later, can trust.
Autonomous AI Agents
AI that ships
LLM features fail in ways ordinary code does not. We build the evals, guardrails and orchestration that make the AI already in your product dependable: reliable answers, safe failures, costs you can predict.
Why us
Shipped, scaled, acquired.
We work daily in the same AI stack you built with, so we know where AI-built apps break at first paid launch, and what an acquirer's diligence team will look for later. OneFlow, Pronoun and Culture Connect were built by this team and carried through to acquisition.
"They took Pronoun through Macmillan's technical due diligence. A brilliant team. You'll hardly find any better."
The work
What actually changes
Lovable, Bolt, v0 and Cursor get a working product in front of users fast. The distance from there to production is specific, known engineering work. We keep what you built and do that work underneath it.
- anon key reads every table; secrets in the client
- schema the AI guessed; backups never restored
- server-side auth and row-level security (RLS), tested per table
- typed schema, versioned migrations, backups you can restore
- N+1 queries; a traffic spike takes the app down
- no monitoring; users report your outages first
- indexes, connection pooling, work moved to background jobs
- error tracking and alerts before a user notices
- push to main; no tests; it lives in one head
- AI calls with no limits, evals or fallback
- CI, staging, and tests on auth and payments, so nothing untested reaches users
- cost controls, docs, and a codebase ready for due diligence
Engagements
In practice.
An enterprise customer sent a security questionnaire before signing.
OutcomePassed the security review. The deal signed. Nothing the users saw changed.
What we found
Row-level security (RLS) was off, so any logged-in user could read every customer's rows. Stripe and LLM keys were committed to the repo.
First paid launch. The demo had already crashed twice in front of prospects.
OutcomeHeld up through launch week. The one incident was caught by an alert before any user noticed.
What we found
Unindexed queries, a shared connection limit exhausted under demo load, no alerting. The founder heard about outages from users in Slack.
A term sheet in hand, with technical due diligence scheduled.
OutcomeWalked into due diligence with a clean risk register, and an honest account of what was left.
What we found
No migrations, tests or CI. AI spend was unbounded, with no way to tell which feature or customer was burning it. The schema had been edited by hand in production.
Composite engagements, drawn from real work and anonymised. No named clients, and no metrics we have not measured.
How we work
Each step stands alone.
Start free. Stop at any step. Keep what each step produced.
Everything stays in your name: your repo, your accounts, your product. We work in what you built and you own all of it at every step.
Teardown
A short recorded review of your app. We name the three to five things that will block production.
Get a free teardown →Blueprint
A review of architecture, security, scale and cost. You get a prioritised plan and your exact price to production. The $3k comes off your build price.
Build
We build it with our own engineers. Scope and price come straight from your Blueprint. The codebase is documented for whoever you hire next.
Contact
Send the repo.
Read-only access is enough, and we sign an NDA first if you want. We read it and tell you where you stand. Or book a short call.
Built in Lovable, Bolt or v0 and not sure where your code lives? A link to your app is enough to start, and we will walk you through read-only access in a few minutes.
Async. A short recorded review, three to five blockers named. You keep the findings.