A complete view of the engineering work included in your Production Hardening Sprint—from access control and billing to deployment, recovery, and the technical due diligence pack.
123 included deliverables · 13 engineering areas
$2,500 fixed price · 10 working days · One codebase
For each deliverable, you can see the work we do, the business problem it addresses, and the evidence we provide at handover.
We inspect the existing implementation, correct what is incomplete or unsafe, and build the missing controls. Work that is already correct is tested and recorded rather than replaced unnecessarily.
The scope follows your application. A control that does not apply to the product is marked with a written reason—for example, subscription reconciliation in an application with no subscriptions. This is never used to move an included item into a paid upgrade. Missing safeguards on an existing feature are part of the work.
Your final report records every item as verified or not applicable with a reason. Any unresolved applicable item remains visible and unfinished until it is corrected and retested.
Browse the areas below or search for a specific deliverable.
No matching deliverables. Try another term or browse the 13 areas below.
01. Authentication & authorization
Give every user the right access, and keep privileged actions protected.
What we deliver: Implement and test Row-Level Security or equivalent server-side scoping across all tables, with explicit rules for intentionally public data.
Why it matters: Missing data boundaries can expose one customer's records to another.
How we verify it: Run read and write tests as anonymous users, different roles, and separate tenants.
Two-factor authentication for owner and admin accounts
What we deliver: Enforce a second factor on every owner and admin account, in the application and on every provider dashboard behind it, with recovery codes stored in the owner's vault.
Why it matters: One leaked password on a dashboard account is a full takeover of the product and its data.
How we verify it: Attempt sign-in to each owner and admin account without the second factor and confirm it is refused.
02. Secrets, keys & configuration
Keep privileged credentials out of browsers, repositories, and accidental test activity.
What we deliver: Move every service the product depends on (database, hosting, payments, email, AI, domain) into an account the founder owns, with the founder as the owner role, billing in the founder's name, and any previous builder removed.
Why it matters: AI-built apps are often wired to accounts the builder created. The business does not control what it does not own.
How we verify it: Produce an inventory listing each provider, the owning account, the owner role holder, and the date the previous builder's access was removed.
What we deliver: Review and harden the settings of every managed service in the stack: auth policies, storage access rules, privileged keys kept server-side, and a plan tier adequate for backups and recovery.
Why it matters: Managed platforms ship permissive defaults so that prototypes work. Those defaults are what leaks data in production.
How we verify it: Record the before-and-after settings for each managed service, naming each risky default and its new value.
03. Input, output & application security
Protect the application's public entry points and test them from an attacker's perspective.
What we deliver: For every model-backed feature: prompt-injection defences, validation of model output before it touches data or users, per-user usage limits, and a timeout with a fallback when the provider is down.
Why it matters: Model calls are a new input surface. Unbounded ones leak data, run up bills, and fail loudly when the provider does.
How we verify it: Run injection test cases against each feature, a spend simulation that hits the limit, and a provider-outage simulation in staging.
What we deliver: Place a CDN or web application firewall in front of the origin, with rate and abuse rules that absorb floods before they reach the application.
Why it matters: Application-layer bot protection never sees a volumetric flood; it takes the app down first.
How we verify it: Send a load burst at the edge and confirm it is absorbed while the origin's health endpoint stays green.
04. Database & data
Keep records consistent, queries efficient, and recovery practical.
What we deliver: Use signed, expiring links for private files, enforce size and type limits, scan user uploads for malware, and set a retention rule for uploads.
Why it matters: File buckets are the most common place an AI-built app is publicly readable without anyone noticing.
How we verify it: Fetch a private file without a signed link and confirm refusal; upload an oversized and a disallowed file and confirm rejection. Upload a safe malware-scanner test file and confirm rejection. Verify that expired uploads are removed according to the configured retention rule.
05. Payments & billing
Keep payment events, subscriptions, and product access in agreement.
What we deliver: Keep the application in a version-controlled repository and on a hosting account the founder controls, deployable through a documented pipeline, independent of the tool that generated it.
Why it matters: An app that only exists inside the builder tool cannot be reviewed, rolled back, or handed to another engineer.
How we verify it: Deploy a fresh clone to staging through the pipeline with no step that depends on the generating tool.
What we deliver: Add structured request logs with correlation IDs and appropriate user references; exclude passwords, tokens, and unnecessary personal data.
Why it matters: Useful traces need to support investigation without creating another data leak.
How we verify it: Trace a test request across services and check log content for sensitive fields.
What we deliver: Run Lighthouse on representative pages, implement performance and accessibility improvements, and deliver a passing result against recorded acceptance targets.
Why it matters: Slow or difficult-to-use pages create avoidable friction.
How we verify it: Report the chosen pages, device profile, numerical targets, and final results; manually check key accessibility interactions.
What we deliver: Bring the core flows to WCAG AA: keyboard navigation, contrast, labels, and focus order.
Why it matters: Enterprise and public-sector buyers require it, and generated interfaces fail it by default.
How we verify it: Score 100 on an automated accessibility audit of the core pages and complete a keyboard-only walk through signup, checkout, and the main task.
10. Code health & AI development guardrails
Make the application easier for your team and AI tools to change safely.
What we deliver: Enable TypeScript strict mode and resolve errors in TypeScript applications, with an equivalent strict-checking approach for other supported stacks.
Why it matters: Stronger checks catch classes of mistakes before execution.
How we verify it: Record the strict configuration and a clean checking run without suppressing the errors being fixed.
What we deliver: Provide CLAUDE.md, AGENTS.md, Cursor rules, or equivalents describing conventions and protected patterns; add CI checks for enforceable rules.
Why it matters: Future AI-assisted changes can undo hardening unless the workflow checks them.
How we verify it: Review the guidance and demonstrate CI catching a representative forbidden regression.
What we deliver: Verify privacy and terms links and review the stated data practices against the application; document and resolve technical discrepancies with the owner.
Why it matters: The public description of data use should match what the product actually does.
How we verify it: Compare the policy statements with the data inventory and provider flows and record the owner-approved alignment.
What we deliver: Provide thirty calendar days after handover for questions about the delivered architecture, operation, and safe future changes.
Why it matters: Small questions often arise when the client starts using the handover independently.
How we verify it: Provide the channel, access instructions, and the start and end dates in the handover.
A completed checklist has evidence behind it.
Your handover report records each scope item, its implementation, and the check used to verify it. You can trace the engineering work back to the repository, test results, configuration, or delivered documentation.
For working controls:
We record the implementation and the passing verification result.
For a genuine non-applicable item:
We explain why the relevant system or condition is absent from your application.
For an unresolved applicable issue:
We keep it visible as unfinished work until it is corrected and retested. It does not become a paid upgrade or disappear into a recommendation list.
Load-test results specify the environment, data volume, workload, duration, and observed performance. Security test results specify what was tested and how. This gives your team and reviewers a concrete basis for assessing the application.
Your core features must work before the sprint begins.
We make a functioning application production ready through the published 123-point scope. Building new features or completing unfinished core workflows is separate work.
Included in this sprint
Implementing and verifying the published production controls.
Correcting security, reliability and operational weaknesses covered by those controls.
Building supporting interfaces required by the scope, including session management, account deletion and billing self-service.
Outside this sprint
Building new product features or modules.
Completing unfinished core features or business workflows.
Rebuilding core functionality that does not yet perform its intended job.
For example:
Adding webhook verification and duplicate-charge protection to a working checkout is included. Completing a checkout that cannot process an order because its core business logic is unfinished is separate feature-development work.
One fixed price.Ten working days.A documented handover.
$2,500
Engineering fee:
$2,500 USD for the complete sprint.
Third-party costs:
Hosting, paid tools and API usage are paid through your accounts. We explain any required costs before enabling them.
Payment:
$1,250 at kickoff and $1,250 at verified handover.
Start date:
Your agreed kickoff date, once repository access and the required environment credentials are available. We provide the access checklist beforehand.
Delivery:
By day ten, we demonstrate the verified application in staging, deliver the report and due diligence pack, and conduct the technical walkthrough. Production release is coordinated with your team through the included deployment process.
Included support:
Fourteen calendar days of defect cover and thirty calendar days of async questions, both beginning at handover.
Scope questions
Are the recovery drill, penetration testing, and due diligence pack extra?
No. All 123 deliverables are included in the same $2,500 package. There is no advanced tier to unlock them.
What if a control is already implemented?
We inspect and test it. If it is correct, we record the evidence. If it is incomplete, we fix it. The fixed fee buys the completed production scope, including verification of existing work.
What if our application does not use Stripe or PostgreSQL?
We apply the equivalent controls for your payment provider, database, and framework. The list describes the production capability we deliver; the implementation follows your stack.
Are the security tests an independent certification?
The targeted security tests are performed by AxonBuild and cover the five priority attack surfaces documented in your report. The package also includes the OWASP review and a controls checklist with evidence. Formal third-party certifications and independent audit opinions are separate from these engineering deliverables.
What does the privacy work cover?
We implement and document the technical data-handling controls listed above and check that the application's behavior matches its published data practices. Legal advice and certification are separate services.
Does the scope include new screens?
It includes the supporting interfaces needed for the listed controls, such as session management, account deletion, and billing self-service. New features that change the product's core capabilities are separate work.
What if a test fails?
We address the failure and retest it. The report keeps unresolved work visible, and final acceptance requires the applicable scope to be verified.
What could change the ten-working-day delivery date?
The delivery date moves by the time work is blocked by missing access, delayed approvals, or changes your team makes to the agreed code during the sprint. We explain the impact and confirm the revised date with you.
What does the post-handover support cover?
After handover, your team operates the application and receives its alerts.
Our included cover is 14 calendar days of fixes for defects in the delivered work and 30 calendar days of questions about the handover and architecture.
YOU HAVE SEEN THE COMPLETE SCOPE
Put the full production foundation behind your application.
Our engineering team implements, verifies, and hands over all the work above in one focused sprint.