Skip to content

The platform is live.

Take a look
Verified Delivery

You built it with AI. I find what breaks before your users do.

The gap between a full product team you cannot afford and a no-code tool that leaves you blind. I review your AI-built product against the eight things that decide whether it holds up, then hand you the fixes as pull requests you review. My judgment on every one, in writing.

Fix PRs you review

Every change lands as a pull request into your repo. Nothing touches your main branch until you open it.

My judgment in writing

A written record of what I checked, what I changed, and what I could not verify, with my name on it.

A handoff call

A walkthrough of the changes and what to watch as you grow, so your team can own it.

The moment you need this

AI wrote the code. Someone has to read it before your users do. It works in the demo, but now real users, payments, or customer data are going behind it, and you cannot see the risk from the inside.

How it is different

AI does the work. A human is accountable for it.

Lovable, v0, and the rest hand you the output and hand you the risk. The Hardening Pass puts a senior engineer between the AI and your production.

AI does the grind

My coding agent reads your repository in an isolated sandbox and drafts the fixes. This is the labor that used to take a team.

I review and record it

I read every change myself, one of the first engineers at Parloa, and write down what I checked and what I could not verify. A tool cannot do this.

You stay in control

Each fix is a pull request you read and merge. You are never blind to what changed or why.

What I check

The trust rubric.

The eight things that decide whether an AI-built system holds up in production. Each one is a place these systems quietly fail.

Own your context

Own your context, rent the model.

Grounded or it doesn't answer

If it can't cite it, it shouldn't say it.

Untrusted content is data, not instructions

Retrieved and user content is data the model reads, never orders it follows.

The agent proposes, a human decides

Autonomy stops at anything you can't undo.

Two layers or it's one bug from a breach

Auth in the app is not isolation. Enforce it at the database too.

One boundary: API-first, validated, typed

One server boundary that validates everything. No business logic in the client.

Bounded by design

An agent with no limits is a bill and an outage waiting to happen.

You can tell when it's wrong

If you can't trace a bad answer back to its cause, you can't trust the good ones.

How it works

Review, harden, record.

Start with the audit. It is a fixed-price read that stands on its own, and it is credited in full if you go on to the Pass.

01

Trust Audit

A fixed, five-day read of your repo against the rubric. Credited toward the Pass.

02

Harden

The agent opens fix PRs, I review every one myself, you review and merge.

03

Record and handoff

A written record of what I checked and changed, and a call to hand it to your team.

Pricing

Fixed scope, fixed price.

No hourly surprises. You know the scope, the price, and the date before any work begins. Ongoing work after the Pass continues on a retainer, from €5k / month.

Trust Audit

€2,0005 days, fixed

Know exactly what is risky.

My agent reads your repo in a sandbox and judges it against the trust rubric. You get severity-ranked findings, a short walkthrough, and a fix plan. Credited in full toward a Hardening Pass.

  • Severity-ranked findings
  • A recorded walkthrough
  • A prioritized fix plan
  • 100% credited toward the Pass

The Hardening Pass

Start here
€7,00010 working days, fixed

Close the gaps the audit found.

I close the gaps the audit found. The agent opens each fix as a pull request, I read every one myself, and you get a written record of what I checked, what I changed, and what I could not verify, plus a handoff call.

  • Fix PRs you review and merge
  • A written record of what I checked
  • Grounding, injection, isolation, and human-in-the-loop rails
  • A handoff call

Not sure yet? Point your AI agent at my MCP server and ask whether the Pass fits what you built. It answers from cited facts and refuses when it does not know.

Ask my agent

What this is not

Not a penetration test, not a compliance certification, and not a guarantee. It is a point-in-time review of the code and the information you give me, judged against the rubric above, with the findings and the limits of what I could see written down. Absence of evidence is recorded as a question, never as a pass.

Why me

A named engineer's judgment, not a tool's output.

I was one of the first engineers at Parloa, from pre-seed to a company now valued at around three billion dollars. The self-serve AI builders cannot give you a person, because their whole model is that you own whatever the AI produced. I record what I checked, what I changed, and what I could not verify, and I tell you plainly where the risk still sits.

Verified Delivery

Find out what breaks before your users do.

A free 30-minute call to scope it. Bring the repo and what you are about to put behind it.