DIY security
API keys in plaintext, homemade auth, secrets in the codebase. One known vulnerability and everything is exposed.
For founders and domain experts shipping with Cursor, Claude Code, Lovable, Bolt — and feeling something will break in production.
Apps built with AI hit an invisible wall between 50 and 500 users. Six fragilities show up almost every time:
API keys in plaintext, homemade auth, secrets in the codebase. One known vulnerability and everything is exposed.
It works in the demo. At 100 users latency explodes, bugs cascade, and nothing is traceable anymore.
No cache, no rate limit, no token monitoring. The OpenAI bill doubles every month.
Personal data flowing freely, implicit consent, sub-processors outside the EU. One audit and it's over.
Heavy code, cascading queries, blocking loads. The app crawls where it should shine.
Schema patched together prompt by prompt, impossible to evolve cleanly. Every new feature becomes a nightmare.
« I start from what you've already built, I solidify it, and you keep building on top — but on foundations that hold. You focus on what you do best, I take care of what needs senior expertise. »
Full read of the code, schema, and infrastructure. Mapping of risks across security, performance, GDPR, costs.
We fix what's critical, harden authentication, structure the architecture, wire up monitoring. Without breaking your flow.
Production deployment with you, monitoring connected, documentation ready. You leave self-sufficient with clean foundations.
An honest overview of what holds, what breaks, and what needs to happen before you really go to production.
I code the foundations — architecture, backend, security — while you keep building the surface. Three intensities, depending on what your project needs.
To level up on your own, with your team, or in a cohort — from a quick assist to a structured program.
Three pillars I apply on every engagement. Non-negotiable, because they make the difference between a prototype that runs and an app you can entrust to real users.
Continuous scan for vulnerabilities and exposed secrets, error monitoring in production, automated security checks, protected branches. Wired in from day one, included in the quote.
1 to 2 weeks before going live, I have your code audited by an independent senior backend engineer (8-15 years of experience). Full audit — authentication, permissions, secrets management, data validation, architecture, GDPR. Written report 5-10 pages, billed pass-through transparently. Included for your peace of mind and compliance.
Optional. When an architecture decision or a complex technical point justifies it, we bring in a senior backend engineer over video (2-3h). Used case by case, never systematically.
You have an MVP running on Lovable, Bolt, v0, Cursor or Claude Code. Now it needs to be reliable, fast, defensible.
Post-MVP · pre-Series AConsultants, coaches, SMBs. You know your craft better than anyone, and you're finally building the tool you always wished you had.
Consultants · coaches · SMBsScale-ups that need senior tech eyes without hiring a CTO. To unblock, arbitrate, secure.
Scale-ups · pre-Series BYou build your own internal tools with AI. I help you cross the gap between "it works" and "we can rely on it".
Internal tools · production usage
« I've spent my career coding, shipping, debugging in production. Today I help AI builders do the same — but in half the time. »
Senior Production Engineer + Embedded Fractional CTO. Co-founder of Docunify (B2B SaaS, 5 developers managed, FEDIL Innovation Start-up Award 2018, sold). 20 years specialized in senior frontend — React, Next.js, TypeScript.
Daily on Cursor, Claude Code, Lovable and Bolt — I use the same tools you do, but with 26 years of production behind me. Rare posture: hands-on senior engineer and approachable, pedagogical coach. Based in Belgium, international market FR / EN.
Sensing the « what if it scales? » wall coming — let's talk. 30 minutes, no commitment, and you leave with a clear direction.
I reply within 24 hours. We schedule 30 minutes over video, no commitment, and you leave with a first diagnostic.