Your AI-built app works. Is it safe to launch?
A fixed-price review of the parts you cannot see: keys, logins, database rules, backups and privacy. You get a written report in plain language and a clear next step.
Fixed price, no obligation. Fixes are quoted separately, after the audit.
Six areas that matter when real users and real data are involved
We check each one against a written checklist and tell you what we found, most important first.
Keys and secrets
Are API keys, tokens and passwords kept out of the browser and out of the code repository?
Login and sessions
Who can sign in, what can they see, and can anyone reach another person's account?
Database access rules
Do the database rules actually stop one user from reading or changing another user's data?
Backups and recovery
Can you get your data back if something breaks or is deleted by mistake?
Privacy and GDPR basics
Do your privacy policy, cookies and third-party services match what the app really does?
Monitoring and updates
Will you notice when something fails, and are the parts your app relies on kept up to date?
Understand. Audit. Improve.
The same order we use for everything: first understand, then build, then improve.
Understand
A free 30-minute call. What does the app do, who uses it, what data does it hold and what worries you? We agree the scope and a fixed price before any work starts.
Audit
We review the code, the configuration and the live setup against the checklist. You receive a written report, ordered by what matters first, with a clear view on fix or rebuild. Most audits take about a week once access is in place.
Improve
You decide what happens next. We can fix the findings for a separate fixed quote, you can hand the report to your own developers, or you can leave it there.
What you get, and what this is not
What you get
- A written report in plain language, not a list of tool output.
- Findings ordered by importance, so you know what to fix first.
- A clear view on whether to fix the app or rebuild parts of it.
- A walkthrough call to explain the report and answer questions.
What this is not
- A structured review against a defined checklist. It is not a guarantee that nothing can go wrong.
- Not a penetration test or a certification. If you need one, we will say so.
- Not legal advice. We flag privacy issues we see; your legal adviser decides what they mean for you.
- Only for systems you own or have written permission to have reviewed.
Audit from €750
Fixed price, excl. VAT, agreed after the scoping call. Fixes are quoted separately and only if you want them.
Who this is for
Frequently asked questions
Which tools and platforms do you work with?
Apps built with AI tools such as Lovable, Bolt, v0 or Cursor, and hand-written code. If you are not sure what your app runs on, the scoping call finds out.
Do you need access to my code and accounts?
Yes: read access to the code and to the hosting and database settings. We ask for the minimum needed, sign an NDA if you wish, and you can remove access afterwards.
How long does it take?
Most audits take about a week once access is in place. Larger apps take longer; we tell you at the scoping call.
Is this a penetration test?
No. It is a structured review against a defined checklist. If your situation calls for a penetration test, we say so and explain why.
What if you find something serious?
We tell you straight away, before the report is finished, so you can act on the urgent items first.
Will you also fix the problems?
Only if you want. You get a separate fixed quote after the report, or you can take the report to your own developers.
Do you also redesign or rebuild?
Yes. Dryfkrag builds websites and web applications. If the review shows that a redesign or rebuild is the better route, we quote that separately.
Start with a conversation, not a quote
A free 30-minute scoping call. You leave with a clearer view of your app's risks, whether or not we work together.