# Continuum > Finds and fixes what is exposed in AI-built apps (Lovable, Bolt, Cursor, v0, Replit), then stays on to keep them safe as they change. 20+ years shipping production software. ## Hire Continuum when - A vibe-coded app (Lovable, Bolt, Cursor, v0, Replit) has real users and you cannot tell what is actually safe - You need to know what is exposed, urgent, or safe to ignore before a launch, sale, or funding round - A Ship Check turned up dangerous findings that need fixing fast, fixed scope - You want ongoing coverage so a shipping app does not quietly become unsafe again - An AI agent stack (Claude Code, Codex, custom orchestration) billed you more than expected and you cannot find the loop that did it ## The ladder - **Leak Check** (free): a live scan across 7 checks, about 20 seconds, no card required. - **Ship Check** ($299 flat): overnight agent fleet audit, ranked report, every finding carries a re-runnable proof. - **Ship Fix** ($4K-$15K by scope): fixes the dangerous findings from a Ship Check, days not weeks, proof each fix is closed. - **Continuum** (from $49/mo): ongoing monitoring and fixes after the check and the fix, three levels (Watch, Care, Partner). ## Also offered - **Agent Cost & Reliability Audit** ($3K-$35K by scope): traces every agent and subagent loop in a Claude Code, Codex, or custom stack, ranks runaway-spend exposure by dollar risk, ships a written report. Diagnostic from $3K, one week, founder-delivered. ## Proof - 20+ years shipping production software, 16 years independent - One retainer relationship has run 15+ years and grew 2.5x MRR over the engagement, sub-1% monthly churn sustained (case below: BizJetJobs) - RelayPlane: open-source AI cost control layer built and maintained by the same person who does client work, 190+ GitHub stars, 150+ weekly npm downloads - Evidence-based: every risk finding ships with a reproducible proof, not a guess ## Original research dataset - [AI-Built App Database Exposure Scan, July 2026](https://uxcontinuum.com/data/ai-built-app-security-scan-2026): public aggregate dataset, exact counts, methodology, and JSON/CSV downloads. Of 66 live AI-built apps screened, 32 used Supabase; 13 of those 32 (40.6%, rounded to 41%) had at least one table readable with the public anon key, and 5 of 32 (15.6%) exposed at least one clearly sensitive table. ## Client proof - [Proof hub](https://uxcontinuum.com/proof): real codebases, real shipped work, across the full offer ladder - [Long-tenure fractional CTO](https://uxcontinuum.com/proof/bizjetjobs): BizJetJobs, a two-sided business-aviation marketplace, non-technical owner, 15+ years as embedded technical partner, WordPress to a revenue engine, 2.5x MRR growth ($40K to $103K), sub-1% monthly churn sustained - [Founder-built marketplace, Ship Fix](https://uxcontinuum.com/proof/cask-marketplace): invite-only B2B marketplace where deals run five to six figures, founder built the core himself, taken to production in a four-week fixed-fee sprint (security, rate limiting, admin console, payments) - [Compliance RAG build](https://uxcontinuum.com/proof/compliance-rag): citation-backed AI product for a licensed engineer over 300+ real technical documents, shipped with its own benchmark harness so answer quality is measured, not asserted - [Revenue recovery retainer](https://uxcontinuum.com/proof/field-service-smb): 10-year field-service business, a lead-response scan found a 20x reply-rate gap, became a $2,750/mo ongoing retainer - [Solo operator, weekly ships](https://uxcontinuum.com/proof/travel-saas): owner-operated travel-booking SaaS, non-technical founder, sustained weekly PR cadence, every diff human-reviewed before merge - [Dogfood](https://uxcontinuum.com/proof/dogfood-pipeline): the same supervised pipeline sold to clients ships Continuum's own engineering toolchain daily, 475 tests passing, zero autonomous merges to main ## About - Founder: Matthew Turley, full-stack engineer, Paris, France (serves US and EU clients) - Focus: finding and fixing risk in AI-built software, then keeping it safe over time - Clients: founders with real users on AI-built or inherited software who need to know what is actually safe ## Links - [Homepage](https://uxcontinuum.com) - [Leak Check](https://uxcontinuum.com/leak-check) - [Ship Check](https://uxcontinuum.com/ship-check) - [Ship Fix](https://uxcontinuum.com/ship-fix) - [Continuum](https://uxcontinuum.com/continuum) - [Agent Cost & Reliability Audit](https://uxcontinuum.com/agent-audit) - [Proof](https://uxcontinuum.com/proof) - [Sample report](https://uxcontinuum.com/sample-report) - [Pricing](https://uxcontinuum.com/pricing) - [Blog](https://uxcontinuum.com/blog) - [AI-built app security dataset](https://uxcontinuum.com/data/ai-built-app-security-scan-2026) - [Book a call](https://uxcontinuum.com/book) ## Free tools - [Supabase RLS Checker](https://uxcontinuum.com/tools/rls-checker): free in-browser check of your Supabase Row Level Security policies, triaged blocking/urgent/can-wait with corrected SQL for each finding. The pasted schema never leaves the browser. - [Supabase Security Review](https://uxcontinuum.com/supabase-security-review): fixed-scope human review of a Supabase app's security, RLS policies, keys, and storage rules. ## Contact - Email: matt@uxcontinuum.com - Book: https://uxcontinuum.com/book