You built it with Lovable, Replit, Cursor or Claude Code and it works on the screen. I check the parts you can’t see, the code, the data and the security, and tell you in plain words what to fix first.
Fixed price for one app, or the part that matters most
The price is agreed in writing before any work starts. Send what you built and I reply with a quote. An enquiry does not charge you or approve a release.
Sound familiar?
It works on the screen. You can’t see how it was built.
Bring the app and what "ship" means to you. I read the code, run it where access allows, and check where your customers’ data goes, who can reach it, and whether the app will hold up as more people use it. We agree the boundary before I start.
What’s included in the agreed scope
Each problem in fix-first order, with what it means for you and a suggested fix.
A written list of what I did not check, so a short report is not mistaken for an all-clear.
A 30-minute call to go over the report.
Who it suits
A good fit, and the limits.
An app you can describe, and someone authorised to grant read access once the scope is agreed. Built with Cursor, Claude Code, Copilot, Lovable, Replit, Bolt or v0 is fine.
What this does not promise
No guarantee of finding every defect. A check is a bounded review of the agreed app, and you keep the release decision.
Not a penetration test, a security certification or compliance sign-off. The security-readiness variant reviews against a named checklist and says so in writing.
A review rather than a repair. I quote repairs separately, so the price never quietly grows.
No surprise booking
What happens after you enquire.
01
Tell me the situation.
Your email and a few sentences are enough to start. No files or account access needed.
02
I’ll check the fit.
I’ll reply by email about the task, scope and price. If it isn’t a fit, I’ll say so.
03
Decide whether to go ahead.
We arrange the work only after agreeing what is included. Sending this form does not book or charge you.
Fixed price for one app, or the part that matters most. The price is agreed in writing before any work starts. Send what you built and I reply with a quote. An enquiry does not charge you or approve a release.
Variant
Security-readiness review
The same check, scoped against a named checklist: OWASP Application Security Verification Standard Level 1 and the OWASP Web Security Testing Guide. You get the checklist items I covered, what I found, and the items I did not cover. It is not a penetration test, a security certification or compliance sign-off, and the report says so.
Quoted with the app check. Ask for it in your enquiry.
The same rules on every job
How I work.
One agreed scope, in writing, before work starts.
Reproduce first. A finding I cannot reproduce is an opinion, and I label it as one.
I say what I did not check. A passing screen does not prove the data was saved.
No credentials in messages. We agree the minimum access needed.
I use AI tools in my own work where they help, and I check their output the same way I check anything else.
Who you’ll work with
I’m Calvin.
I’m a software developer based in Newcastle, Australia. You’ll work with me directly. Newcastle, the Central Coast and Sydney, and remote everywhere.
Start with your task. I’ll check whether it fits my experience and explain the scope before you decide to go ahead.
Open-source review and quality tooling I built and maintain. Public repositories you can read before you decide whether my check would be worth having.
Evidence capture for checks: screenshots, console logs and network requests at every step.
These are my own open-source projects, not client work, and I am not claiming they have a user base. They are MIT licensed and documented so you can read the code and judge the standard of it before you trust me with yours. There are 57 more in the open.
Finding example · my own website
One finding. What it means. How to verify it.
A finding from my own enquiry form shows the difference between a screen that says "sent" and data that was actually saved.
Finding
The form reported success as soon as the request left the browser, before the server confirmed the record was written.
What it means
A dropped connection could show a visitor "sent" while nothing reached the inbox, and the enquiry would be lost without anyone knowing.
Verification
Submit with the server unreachable. The form must report the failure, keep the text, and only show "sent" once the server returns a receipt.
This finding comes from my own site and its fix is in the site’s code. It demonstrates the report format, not a paid client outcome or a complete security assessment.
What would stay outside this finding
This finding covers one form’s save path. It says nothing about authentication, payments or the rest of the application. A useful report names those limits instead of turning one passing check into an all-clear.
Is this worth it for you?
Before you spend time or money.
AI already reviewed my code. Why pay a person?
A tool’s list of issues is only useful if it helps you decide. I reproduce each finding, say what it would cost you if ignored, and tell you what can wait. If the AI list is already enough for you, you do not need this.
I’m not technical. Will I understand the report?
Yes. Each problem says what it means for you and your customers before it says anything about code. The technical detail sits underneath for whoever fixes it, and the call is there for questions.
Am I paying for a check or for fixes?
The quote covers findings and a suggested fix for each, for one app or the part that matters most. Repairs are separate work with their own quote. Small ones can be done by the hour under guided build.
The practical details
Scope, preparation and next steps.
What counts as one app?
A small app in full, or the part of a larger one that matters most, such as sign-up and payment. If it will not fit the quote, I say so before starting and we narrow the scope or agree a second part.
Do you run the code or just read it?
Both, where access and environment allow; we agree that before I start. The report says which findings I reproduced by running and which came from reading.
Will you fix what you find?
Not inside the check. The deliverable is findings in fix-first order with a suggested fix for each. Repairs are separate: small ones by the hour under guided build, larger ones quoted.
Is this a security audit?
No. I check the security basics and flag what I see, and the security-readiness variant reviews against OWASP ASVS Level 1 and the OWASP Web Security Testing Guide. Neither is a penetration test, a certification or compliance sign-off.
How much does it cost?
A fixed price for one app or the part that matters most, agreed in writing before any work starts. Send what you built and I reply with a quote. A second part, or a re-check after you apply fixes, is quoted before starting. Nothing is charged for sending an enquiry.
Does a passing check mean it is safe to launch?
No. It is a bounded assessment and it cannot promise that every defect was found. You keep the release decision, with the checked areas and the unchecked ones written down.
What should I send?
Read-only repository access or a zip, how to run it, what "ship" means to you, and anything already checked. No credentials in the message; we agree the minimum access separately.