Fixing one thing breaks another.
A small change, and something unrelated stops working.
App rescue & clean-up
Built an app with an AI tool such as Lovable, Bolt, v0, Replit or Cursor? Or inherited one that’s hard to change? I find what’s fragile, fix what matters most and hand back an app you can keep building on.
It starts with a health check: plain-English findings in priority order, and an honest view on whether to repair the app, rebuild part of it or start again. If your app holds personal data or uses AI, it also leaves you something written down you can show someone else.
£495 health checkReport within 5 working days of access · Fee deducted from fixes booked within 30 days of the report
When it helps
“Vibe coding” means describing what you want and letting an AI tool write the code. It’s a quick, sensible way to get an idea working. Making it dependable for real customers, data and payments is a different job — and once real customers and data are involved, someone often asks how it works.
A small change, and something unrelated stops working.
It keeps rewriting the same code without solving the problem.
Hosting, settings and going live have become the hard part.
Sign-in works, but could one customer reach another’s data?
Personal details, payments or AI features raise the stakes. You want it checked first.
You have the app, but not the knowledge behind it.
How a rescue works
I review the code, database, hosting and the accounts that connect them, and walk through the journeys your customers rely on, using a test copy where possible. You get prioritised findings, written for the person who owns the app.
I don’t change anything on your live app during the review without agreeing it with you first.Security and data problems come first. Then problems getting the app live, and anything stopping people using it.
You approve each batch of fixes before I start.Add tests to the critical journeys, remove duplicated and unused code, and set up a reliable way to publish updates.
Each change is tied to a finding, not a rewrite for its own sake.Notes on how the app fits together, how to publish updates and how to keep using AI tools without undoing the fixes.
Ongoing support is optional and scoped separately.The health check
£495 for one web app: one code repository, one database project and its hosting. You receive the report within 5 working days of giving me access. Larger apps are quoted before we start.
Each finding explains what could happen, how to fix it and how soon it matters, in plain English. The technical detail sits alongside, for me or any other developer. Who can see what, and what your app sends to AI providers, are in every health check, whatever your app does.
What you keep
The aim is an app that you, another developer or your AI tools can keep working on with confidence, without depending on me.
One fixed price to start. The health check is £495 for one web app, with the report within 5 working days of access. If you book fixes within 30 days of the report, the full £495 is deducted from them. Fixes are quoted from the findings in a written proposal, and you choose what to tackle and when. Larger apps, hosting, third-party subscriptions and any ongoing care are quoted separately. Prices in GBP. Any applicable VAT will be set out in your proposal before you commit.
Request a health checkA good fit
A different scope
Other languages, such as Python, and native mobile apps are assessed case by case. I’ll tell you if someone else is a better fit. If your code or data lives only inside a builder’s own platform, I can review what that platform lets me see, and what can be fixed depends on the access it gives. The health check says where that limits things.
The health check is an engineering review, not an audit, a penetration test or legal advice. No review can prove an app has no weaknesses. The report records what was checked, what was found and what remains. Tool and platform names describe how apps are built; I’m not affiliated with any of them.
Who does the work
I’m Alec. I joined Ley Hill Consultancy Group as Lead Software Engineer and moved into management systems consulting, specialising in information security and AI. Before that I was a frontend engineer in fintech at NewDay and a software engineer at Soundflow Music Academy. I build with TypeScript, React, Next.js and Node.
App rescue is a new service, so there are no rescue case studies here yet. You work directly with me, from the first review to the handover.
Before we begin
If it’s a JavaScript or TypeScript web app, usually yes; if you’re not sure, tell me which tool you used and I’ll check. The tool matters less than what it produced. Many builders let you export your code or sync it to GitHub, which is the best starting point. Building with AI is a sensible way to test an idea; the review is about what the app needs next, not how it was made.
A short description of what the app does and what’s going wrong. For the review, I usually need read access to the code and to your hosting and database dashboards. Please don’t send passwords or keys by email; we’ll agree a safe way to share access, and it’s removed when the work ends. Where possible I work on a copy with test data. Database access often includes personal data, so we’ll put data processing terms in place first. If a former developer still holds the accounts, getting them back comes first.
It’s an engineering review. It checks common security weaknesses, such as exposed keys, loose database rules and unprotected pages, alongside reliability and code quality. It isn’t a penetration test, an audit against a standard, a certification or legal advice. If a customer or insurer asks for a formal penetration test, you’ll need a specialist tester; certification comes from a certification body, not from me. Either way, it’s worth fixing the problems you already know about first.
No. It’s an engineering review of one app, and nothing in it says whether your business meets ISO 27001 or any other standard. What it can do is feed your own work: each finding explains what could happen, how to fix it and how soon it matters, with the technical detail alongside. Certification comes from a certification body, and your own auditor’s work is separate from mine. I’m here as an engineer reviewing your app, not as your auditor or your consultant.
Automated scans are a useful first step, and worth running. Some can even apply fixes for what they find. But a scan only knows the patterns it looks for; it can’t judge whether your sign-in, payment and data rules match how your business actually works. The health check covers all seven areas, and puts the findings in plain English and in priority order, written by a person who has actually looked at your app. It also leaves you a written record you can show someone else, which a scan’s dashboard doesn’t.
I’ll tell you straight away, with the immediate step to contain it, such as replacing a key or closing public access to a table. You decide what happens next. If personal data may have been exposed, I’ll explain what I found so you can decide next steps using guidance from the Information Commissioner’s Office (ICO) or legal advice. I’m not a lawyer, so I won’t advise on whether it needs reporting.
Usually, yes. Before changing anything, I check whether fixes made outside your builder can flow back into it, and we agree where future work should happen. The handover includes notes for your AI tools, so new work is less likely to undo the fixes. I use AI tools in my own work too, while checking what they produce.
The health check is £495 for one web app: one code repository, one database project and its hosting, with the report within 5 working days of access. The clock starts once the agreed access is in place and any data processing terms are signed. If you book fixes within 30 days of the report, the full £495 is deducted from them. Fixes are quoted from the findings, so you can choose what to tackle now and what can wait. Larger apps are quoted before we start, and hosting, subscriptions and any ongoing care are listed separately. Prices in GBP. Any applicable VAT will be set out in your proposal before you commit.
Your next step
Tell me what the app does, how it was built and what’s going wrong. If someone has already asked you a question about it — a customer, an insurer, your own auditor — say so. A short description is enough to start. Please don’t include passwords, keys or customer data. An enquiry is not a commitment.
Discuss my appYour privacy
With your permission, optional Google analytics tools help measure page visits and enquiry actions and may use cookies. Your message and contact details are not included. You can change your choice at any time.