Ship Check

You built it with AI. Know it is safe to ship.

You built your app with Lovable, Cursor, Bolt, or Replit. It works, but you do not know what it is hiding before real users hit it. An agent fleet scans it, a senior engineer reviews every finding, and I tell you what is fine, fixable, or a rewrite, in writing, within 48 hours of getting repo access.

Start free with a Leak Check →

Or talk it through first →

Flat price, human review
$299

One codebase. One written assessment, reviewed by a senior engineer, not just a bot.

  • In your inbox within 48 hours of repo access, or it’s free.
  • Not worth $299? Tell me within 7 days and I refund you. You keep the report.
  • Something we should have caught turns up in the code we checked within 30 days? I fix it at no charge.

Credited against a Ship Fix if you go ahead. Exact terms

The short answer

Is my AI-built app safe to launch, and what does a Ship Check cost?

A Ship Check is $299 flat. An agent fleet runs the volume scan, then a senior engineer reviews every finding and ranks it by real-world risk, so you get a verdict of fine, fixable, or rewrite, what will break first, a security and data read, and a costed plan you can take anywhere, in writing, within 48 hours of giving us repo access, or it’s free. If it was not worth $299, you get a full refund within 7 days. If something we should have caught in the code we checked turns up within 30 days, I fix it at no charge. The $299 is credited against a Ship Fix if you go ahead.

What lands in your inbox

01

The verdict

Fine, fixable, or rewrite. One of three, stated plainly on the first line.

02

What will break first

The specific things most likely to wake you up, ranked, with where they live in the code.

03

Security and data

Exposed keys, open endpoints, auth you should not trust, and what your data would survive.

04

A costed plan

What I would do, in what order, and roughly what each piece costs. Yours to take anywhere.

Every finding is reviewed and ranked by a senior engineer, not left as raw scanner output. You can hand the whole thing to another developer afterwards. Plenty of people do, and that is fine. I would rather you spend the next ten thousand dollars on the right problem.

What a client said

Matt did a really thorough security and backend audit of my app and found a handful of issues I'd missed across access control, API keys, and a few of the third-party integrations. What I found most useful was that

he didn't just dump a list on me. He sorted everything by priority so I knew what was actually launch-blocking versus what could wait, and he was straight about which bits I needed to properly understand myself rather than just hand off.

He also explained the reasoning behind each issue and offered to help implement the trickier fixes. Would recommend him to anyone wanting a proper review of their app, rather than a quick once-over.

★★★★★Stephen Forino, Concierge Compass

“Matthew has consistently demonstrated unparalleled dedication, expertise, and a profound commitment to our success.”

★★★★★Meredith Koubsky, Co-founder, BizJetJobs

“He went above and beyond at every stage. What started as a simple MVP turned into something much more complete and impressive thanks to his dedication and skill.”

★★★★★Tom van den Heuvel, Founder, StaySignal

How it works

When you grant access

You give me read access to the repo and tell me, in a paragraph, what worries you. That is when the clock starts.

The scan

An agent fleet reads the whole codebase, runs it, and breaks it on purpose to surface every candidate issue.

The human review

A senior engineer reviews every finding, throws out the noise, and ranks what is left by real-world risk. Anything genuinely serious falls back on me personally.

Within 48 hours

The written report lands within 48 hours of access, or the check is free. Then we spend thirty minutes on the phone going through it.

Then you decide, with actual information.

Ship FixI do the work the check found.$4,000 to $15,000PartnerOr I stay on and keep it healthy.Five levels
Start free with a Leak Check →
FAQ

Questions I get asked

What is a Ship Check and what does it cost?
A Ship Check is $299 flat: a written assessment of your codebase where an agent fleet runs the volume scan and a senior engineer reviews every finding by hand. You get a verdict of fine, fixable, or rewrite on the first line, what will break first, a read on security and data, and a costed plan you can take anywhere. It lands within 48 hours of repo access or it’s free, there is a 7-day money-back if it was not worth it, and the $299 is credited against a Ship Fix if you go ahead.
Is the Ship Check automated or human-reviewed?
Both, in that order, and the human part is the point. An agent fleet does the heavy volume scan across the whole codebase, then a senior engineer reads every finding, throws out the false positives, and ranks what is left by real-world risk. Anything genuinely serious falls back on me personally. A raw automated scan gives you a wall of flags with no sense of what matters; this gives you a ranked verdict you can act on.
How long does it take?
Within 48 hours of when you give us read access to the repo, which is when the clock starts. If the report is late, the $299 comes back and you still get the report. You grant read access and a paragraph on what worries you, the agent fleet scans it, a senior engineer reviews and ranks the findings, and then the written report lands and we spend thirty minutes on the phone going through it.
Do I own the report?
Yes. The costed plan is yours to take anywhere, including to another developer. Plenty of people do, and that is fine. I would rather you spend the next ten thousand dollars on the right problem.
Is it refundable? What exactly is guaranteed?
Three things. On time: the report is in your inbox within 48 hours of repo access, or the $299 comes back and you still get the report. Money-back: if it was not worth $299 to you, tell me within 7 days of getting it and I refund the full amount, no reason needed, and you keep the report. The 30-day fix: if a security or data problem of the kind the check looks for (exposed keys, open endpoints, broken login or access rules, data exposure) was in the code we checked, we missed it, and it turns up within 30 days, I fix it at no charge. If you go ahead with a Ship Fix, the $299 is credited against it. What I do not promise is that your app has no other bugs.
How is it different from a Leak Check?
A Leak Check is free and fast: send a live URL and I write back with the three biggest things costing you, from the outside. A Ship Check is the paid, in-the-code version: I read the whole codebase and give you a written verdict, a ranked list of what breaks first, security and data findings, and a costed plan.