Phil Kurth
/ Services / Prototype to Production

Prototype to Production

You built your app idea with Lovable, Bolt, Cursor or something like them. It works, people like it, and now you're wondering what's underneath. I review the code, look for the problems that tend to bite once real users and real data arrive, and tell you whether to fix it or rebuild it. Then, if you want, I do the work.

What is a prototype review?

A fixed-price developer review of an app built with an AI app builder. I go through the code and the database rules, and give you a ranked list of the problems I find in plain English, with a recommendation to fix the app or rebuild it.

  • Who it's for: business owners who built a tool to run their business, and founders with an MVP they want to take to real customers.
  • What it costs: $1,500 + GST for a small app, taken off the price if I rebuild it for you within six months.
  • What you get back: a findings report, a fix-or-rebuild recommendation, a rough rebuild estimate, and a call to walk through it.
What you can't
  • who can read which data
  • keys in the code
  • payments trusted from the browser
  • backups, logging, ownership

Your prototype is the brief

Building it yourself was the right move. You found out what you actually want, cheaply, and you have something people can click. That makes it the best brief a developer can be handed.

  1. 1

    You've done the hard part

    The screens, the flow, what users need and what they ignore. Most software projects spend weeks of meetings getting to where your prototype already is.

  2. 2

    AI got you most of the way

    App builders are good at the parts you can see. The parts you can't see, like access control, data rules and payment handling, are where they fall short. I wrote about where that gap sits.

  3. 3

    I find what's missing in yours

    Not a generic checklist. The specific problems in your app, what each one means for you, and what it takes to fix.

What I look for

The problems in AI-built apps are remarkably consistent. These are the areas I go through, roughly in order of how often they turn out to be broken.

Illustration: the kind of thing I find
-- supabase/migrations/0001_init.sql
create table invoices (
id uuid primary key, customer_id uuid, total numeric
);
alter table invoices enable row level security;
create policy "Allow all" on invoices1
for all using (true);
 
// src/lib/stripe.ts
const stripe = new Stripe("sk_live_51Hx…");3
 
// src/pages/Admin.tsx
{user.role === 'admin' && <AdminPanel />}2
 
// supabase/functions/checkout/index.ts
const total = req.body.total;6
  1. Who can see what data

    Whether one user can read or change another user's records, whether the database rules (Supabase row level security, for example) are switched on and actually restrict anything, and whether anyone can delete data using the public key that ships inside your app.

  2. Logins and permissions

    Whether admin and paid features are protected on the server or just hidden in the interface. Password resets, email verification, and sessions that never expire.

  3. Keys and secrets

    API keys, service keys and payment credentials that have ended up in the browser code or the repository, where anyone who looks can read them.

  4. How it's built

    Where the business logic lives, how much code was duplicated by repeated prompting, whether testing and live are kept apart, and how tightly the app is tied to the platform it was built on.

  5. The database

    Whether the structure will cope with your next feature, how personal information is stored and who can reach it, and whether anything is being backed up.

  6. Production basics

    Payment webhooks that are actually verified, errors that are caught and logged, email that arrives, rate limits, known vulnerabilities in the packages it uses, and what it costs to run at ten times the users.

  7. Who owns what

    Whose name the database, Stripe, domain and email accounts are in, and whether the app can leave the platform it was built on. Easy to sort out now, painful later.

What you get

A report written for the person who owns the app, not for another developer.

Findings reportIllustration of the format, not a real client
Critical Any signed-in user can read every customer's invoices

The invoices table has a policy that allows every request. One owner-scoped policy per table fixes it.

High The admin page is only hidden in the interface

Anyone who finds the address can open it.

Worth fixing Nothing is being backed up

One bad prompt away from losing the data.

RecommendationFix what you haveRough estimate if rebuilt: included
  • Every finding ranked Critical, High or Worth fixing
  • Each one in plain English: what it is, why it matters, what it takes to fix
  • A recommendation: fix what you have, or rebuild it properly
  • A rough estimate for the rebuild, if that's the recommendation
  • A call to walk through the findings and answer your questions
  • The report is yours. Take it to any developer you like

What this review is not

I want to be clear about this upfront.

A sign-off to launch

I find problems. I don't tell you your app is safe, and nobody honestly can from a review. A section with no findings means I didn't find a problem there, not that there isn't one.

A penetration test

I read the code and database rules you share with me. I don't attack your live app, and I won't test it at all without your written permission.

Permanent

The review covers the code as it was on the day you shared it. Every prompt after that changes the app, and the findings start to age.

Sized for large apps

The fixed price covers a small app, up to around 15 screens and 3 integrations. Bigger apps get a quote first, so neither of us is surprised.

How it works

The review takes about two weeks, and you have a clear, ranked picture of what I found before anyone talks about building.

1

You share the code

Read access to the repository, plus the database structure (structure only, no customer data). Lovable, Bolt, v0 and Replit can all push a project to GitHub. I never need your passwords or live keys, and if I find live keys in the code I'll tell you straight away so you can change them.

2

I review it

AI-assisted, because it's the fastest way to read every file of a generated codebase. Every finding is then checked and judged by me. The AI does the reading, and the calls are mine.

3

You get the report

About two weeks after I have access: every finding ranked, explained in plain English, with a fix-or-rebuild recommendation. Then a call to go through it.

4

Fix it or rebuild it

If the bones are good, I fix what matters. If they're not, I rebuild it properly with your prototype as the brief, and the $1,500 comes off the rebuild if you go ahead within six months.

$1,500 + GST

One fixed price for a small app.

That covers the code and database review, the ranked findings report, the fix-or-rebuild recommendation, a rough rebuild estimate, and a call to walk through it.

If you go ahead with a rebuild with me within six months of the review, the full $1,500 comes off the rebuild price. Apps bigger than around 15 screens or 3 integrations are quoted first.

What clients say

5.0 from 22 Google reviews
Alastair Beaumont
Suncoast Express
★★★★★

Phil recently completed a full website re-hash and online quote, booking and payment system. We provided our outline and rate template which Phil put into practice without the need for constant questioning or how, he knew and understood the final outcome requirement and made it work. Throughout the process we had several online hookups to hash out progress which was very beneficial. We've already put him to task on another project. Thanks Phil

View on Google
Tim Kenington
Tim Kenington
WhichCar
★★★★★

Phil is an absolute pro to work with and undertook a website migration for us that seemed near impossible. Phil’s ability to understand our previous Sanity-based CMS and AWS-based tech stack was key to enabling a migration to a WordPress solution. His broad understanding of website development ensured we were able to migrate thousands of WhichCar, Wheels, Motor and 4X4 Australia articles and images to a WordPress solution whilst retaining the pre-existing site design, SEO performance and business-critical features. Phil’s very easy to deal with, has the knack of being able to explain technical issues in a simple way, and is a pleasure to work with. Highly recommended.

View on Google
David McDonald
DMC Web
★★★★★

Have had the pleasure of working with Phil many times over the years and have always found him knowledgeable, detail oriented and easy to get along with. He is an highly skilled developer with a wealth of experience and expertise.

View on Google

Frequently asked questions

What people ask before they send me their app. If yours isn't here, ask me directly.

Yes. Lovable syncs your project to GitHub for free, and if you use Supabase that includes the database structure and access rules. Bolt, v0, Replit and Cursor projects can be shared the same way. Base44 is the hardest, because much of the backend stays on its platform, so the review there is narrower.

Read access to the code repository, the database structure (no customer data), and a short call about what the app does and who uses it. I never need your passwords, your live API keys or admin access to anything.

No, and be wary of anyone who does. A review finds problems. It can't prove there are no others. What you get is a clear list of what I found, ranked by how much it matters.

Yes. AI is very good at reading a large generated codebase quickly and flagging patterns worth a closer look. Every finding in the report is then checked and judged by me, and the recommendation is mine. It's the same way I use AI in my own development work.

About two weeks from when I have access to the code. A larger or messier codebase can take longer, and I'll tell you upfront if yours will.

It depends on what's underneath. If the data model is sound and the problems are mostly missing protections, fixing is usually cheaper. If access rules, data and business logic are tangled together, rebuilding is often faster than untangling. The review tells you which one your app is, and why.

Not for the review. If I rebuild your app, the new version lives in your own accounts on a stack that suits it, and you can keep using your prototype to try out new ideas.

It depends on the app. The review includes a rough estimate before you commit to anything. If I rebuild it for you within six months of the review, the $1,500 review fee comes off the rebuild.

Built something with AI?
Let's look at it.

Send me a short note about what your app does and what it was built with. I'll reply within a business day with what I need to get started.

Phil Kurth, web designer and developer in Geelong