crdrdev

You shipped it fast.
Let’s make it safe.

Security reviews and fixes for websites built with AI.

the problem

AI tools write code that works. They don’t always write code that’s safe. Exposed keys, open databases, logins anyone can hammer. I find them and fix them, before someone else finds them first.

services

Three ways I can help.

  • Review

    from €490

    A full, human read of your code and setup: secrets, auth, database rules, dependencies, headers. You get a plain-language report with every issue ranked by risk.

  • Fix

    from €290

    I close what the review found, directly in your code: keys moved server-side, access rules locked down, inputs validated, a strict CSP. Clean pull requests you can read.

  • Care

    €149 / month

    A security-minded developer on call as your site grows. Monthly dependency checks, a second look at new features, and help the day something looks wrong.

sample report

What you get.

Every issue comes like this: ranked by risk, explained in plain words, with the exact fix.

CRDR-01 critical fixed · re-tested example

Database readable without authentication

area
Supabase · table public.invoices
client
xxxxxxxxxxxx
found
xxxxxxxxxx

The invoices table had no row-level security. Anyone holding the public API key, which ships in every page, could list every customer’s invoices, names and amounts. No login needed.

how to fixTurn on row-level security and let each user read only their own rows.

alter table invoices enable row level security;

create policy "read own invoices"
  on invoices for select
  using (auth.uid() = user_id);

self-check

How safe is your site, really?

Seven questions. “Not sure” counts as a no, because attackers won’t be unsure. Nothing leaves your browser unless you choose to email me your results.

01 / 07

Your API keys never reach the browser.

process

Clear steps. No jargon.

  1. 01

    Talk

    A short, free call about your site and what worries you.

  2. 02

    Review

    Read-only access to your code. No production passwords.

  3. 03

    Report

    Every issue ranked and explained in plain language.

  4. 04

    Fix & verify

    You fix, or I do. Then I re-test that it’s closed.

work

Things I’ve built.

  • LoreMatch ↗

    web game

    A video game quiz: a blurred picture slowly comes into focus, and you guess the game before it is fully revealed.

  • Anonymous chat app

    real-time web app · anonymised · SvelteKit · Supabase

    An anonymous live chat with more than 50,000 visits a month. When anyone can join, abuse is the default threat: row-level security in the database, bot checks on entry, a username blocklist and a moderation dashboard.

about

I build with modern frameworks every day, and break things on purpose to understand how they fail. AI made it possible to launch a real product in a weekend. I help makers keep that speed and lose the risk.

contact

Worried about your site? Let’s take a look.

Tell me what you built and what it runs on. I’ll reply with what I’d check first, free.