Skip to content
offer.mdx
withdarsh / offer · production hardening for AI-built apps

Your AI-built app, production-safe in 7 days.

I find and fix what the AI skipped — database access rules, auth, leaked keys, Stripe webhooks, deploys and monitoring — so you can put real users and real money through it.

fixed prices · scope in writing · staging before production

years building
06+
production systems
24+
MIT libraries
06
first reply
<24h
production-readiness.report
sample · illustrative
  • CRITICALRLS off on 3 tables: profiles, orders, messages
  • CRITICALService-role key shipped in the browser bundle
  • HIGHStripe webhook signature never verified
  • HIGHNo database backups configured
  • MEDIUMNo error monitoring — failures are silent
5 issues · 2 criticalest. sprint: 6 working days

works with apps built on

  • Lovable
  • Bolt
  • Replit
  • Base44
  • v0
  • Cursor
  • Supabase
  • Next.js
  • Stripe
  • Vercel

01 / symptoms

Sound familiar?

If one of these happened this month, your app isn't ready for paying users yet.

  • new row violates row-level security policySaving fails for everyone — or worse, works for everyone.
  • 200 in preview · 500 in productionIt worked yesterday. It won't deploy today.
  • checkout.session.completed → ???Stripe took the money. Your app still says "Free plan".
  • credits remaining: 3The AI fixed one bug and created two more.
  • select * from profilesOne user can read every other user's data.
  • tests: 0 · alerts: 0You find out something broke when a customer emails you.
why-it-breaks.md

The AI ships the demo. It skips the parts that keep data safe.

Builders generate working screens fast. Access rules, secrets, payments and monitoring are where they cut corners — and where launches go wrong.

~10%

of 1,645 scanned Lovable-built apps let anyone read or write database tables with the app's public key.

source: CVE-2025-48757
23 of 26

AI-built apps in one firm's audits were missing tests — the most common gap it found.

source: AxonBuild audit data

02 / one sprint

What changes in one sprint

Same app, same features. Everything underneath is made safe to grow.

before

Built fast

  • Anyone with your public key can read your tables
  • Secret keys sitting in the browser
  • Paying users stuck on the free plan
  • Customers report bugs before you notice them
  • Testing happens on the live database
  • "Don't touch it, it works"
shipped

after

Built to last

  • Every table locked to the user who owns the row
  • Keys server-side, leaked ones rotated
  • Plan state always matches Stripe
  • Alerts reach you before customers do
  • Separate staging and production, deploys from Git
  • Tests on sign-up, checkout and your core flow

03 / packages

Fixed prices. No hourly meter.

Start free. Pay only once you've seen what's wrong and agreed the fix list.

Diagnostic

10-minute video

Free
  • Read-only access, with your written OK
  • Your top 3 risks, ranked
  • Fix order and a fixed quote
Request diagnostic

Production Audit

2–3 working days

$490
  • 25-point review: data, auth, payments, deploys
  • Written report, ranked by severity
  • Fee credited if you book the sprint
Book an audit
core offer

Launch-Ready Sprint

5–7 working days

from $1,500
  • Everything the audit finds, fixed
  • Access rules and secrets locked down
  • Stripe webhooks verified and tested
  • Monitoring, backups, deploy pipeline
  • Tests on your critical flows
  • Handoff doc any developer can follow
Start with a diagnostic

Care Plan

after launch · monthly

$350/month
  • Uptime and error monitoring
  • Security and dependency updates
  • Up to 3 hours of fixes a month
  • Monthly health report · cancel any month
Ask about care

prices in USD · card or bank transfer · audit fee credited to your sprint

how-it-works.mdx

04 / how it works

From link to launch

  1. 01

    2 minutes

    Send your link

    Your app URL and what's worrying you.

  2. 02

    ≤ 2 working days

    Get the video

    Your top risks, ranked, and the order to fix them.

  3. 03

    before any work

    Approve a fixed quote

    Scope and acceptance criteria, in writing.

  4. 04

    5–7 working days

    Fixes land in staging

    You review before anything touches production.

  5. Step 5

    launch day

    Go live, with a record

    A plain-English handoff. Keep it, or add the Care Plan.

zsh — whoami

$ whoami

darsh gupta — full-stack · platform architect

$ location

mumbai, india · IST (UTC+05:30)

$ stack

next.js 16 · react 19 · nestjs · prisma · postgres

$ status

available for hire · replies < 24h

$

05 / who you're hiring

Hi, I'm Darsh.

AI engineer of unreal systems.

Full-stack engineer and platform architect, 6+ years in. I've shipped 24+ production systems — including real client builds for a restaurant, a salon and a boutique hotel — and built TechZunction, my own 63-module NestJS platform.

One operator. Full stack. Zero hand-offs. Now I take what the AI built and make it hold up under real users. I've led 20+ developers and mentored 50+ engineers, and I work async from Mumbai with overlap for US mornings and UK afternoons.

  • 6+ years
  • 24+ production systems
  • 6 MIT libraries
  • 50+ engineers mentored
  • Next.js · NestJS · Postgres
  • US / UK overlap

06 / shipped

Real client builds

Live, clickable, and the source is public. This is the quality bar your app gets.

Burger Empire — restaurant · f&b website screenshotreal client build

restaurant · f&b

Burger Empire

Aggregator-free food ordering with a two-brand theme engine — PetPooja POS sync, Razorpay, WhatsApp ordering, coin loyalty and referrals.

104 features · 130+ API routes · 13 modules

  • next.js 15
  • nestjs
  • prisma
  • razorpay
Velvet — premium salon website screenshotreal client build

premium salon

Velvet

Glamour Waves Unisex Salon — dark-and-gold site with CMS-driven services, WhatsApp booking fallback and LocalBusiness schema.

90+ Lighthouse on mobile and desktop

  • next.js 16
  • react 19
  • framer motion
ViCity — boutique hotel website screenshotreal client build

boutique hotel

ViCity

Luxury hotel booking with hold-timer reservations, Razorpay checkout and ISR-powered booking pages.

12-screen admin · 50+ pages · Docker CI/CD

  • next.js 16
  • zod
  • recharts
  • docker
all 24+ systems on the portfolio→
libraries/
checklist.md
free download

The 25-point production checklist for Lovable + Supabase apps

Run it yourself in 30–45 minutes — every check is read-only. If you get stuck, send me the result.

production-checklist.md — preview
  • RLS is on for every table in public
  • No secret Supabase key in the browser
  • Webhook signatures are verified
  • Backups exist, and you've restored one
+ 21 more checks

07 / faq

Questions founders ask

Do you need my passwords?

No. You invite me as a collaborator to your repo, database and hosting — read-only for the diagnostic. You remove my access when we're done.

Will you rebuild my app?

No. I fix what you have. If moving off a builder makes sense, I'll say so and quote it separately.

Is this a penetration test?

No. It's a production-readiness review and hardening, not a formal security certification. If you need a certified pen test, I'll tell you.

What if the problem is bigger than the package?

You'll hear it before you pay for more. Scope is always agreed in writing first.

Which tools do you work with?

Apps built with Lovable, Bolt, Replit, Base44, v0 or Cursor, on React, Next.js, Supabase, Postgres, Vercel, Netlify and Stripe.

How do I pay?

Invoice in USD, payable by card or bank transfer. Sprints are 50% upfront, 50% on handoff.

diagnostic.mdx
free · no call needed

Send me your app link. Get a 10-minute video of what's wrong.

If your app is in good shape, I'll tell you that too.

Interested in
Video within 2 working days · no passwords needed

prefer to talk? book a 15-minute call · or email withdarsh@gmail.com · under 24h to first reply