I'm Bryce Watson. I build, fix and harden software for solo founders and teams of every size, at whatever stage you're in.
Launching an app built with Lovable, Replit, Bolt or Cursor? Three ways to start:
- FreeA security check of your repo, a usability check, or a 15-minute call.
- $400 reviewA written report on what could hurt you, in 2 business days from the agreed start date, once I have your code and a test login. See a sample report.
- Launch-Ready SprintThe review, then I fix every problem it ranks Medium or worse for one fixed price, and re-check your app.
I confirm every finding myself and explain what matters for your app. It's a code and configuration review, not a penetration test.
Not sure which? I'll reply with the simplest first step, before you pay anything.
I spent 11 years at eBay, and I'm now contracting with Portland State University on Akaya, an AI knowledge tool.
Where are you now?
-
Idea
Nothing built yet.
I build your first version, for a fixed price and finish date I quote before I start.
→ Tell me what you want built -
Prototype
About to launch.
The Launch-Ready Sprint: a $400 review, fixes at one fixed price, then a re-check. Or just the review, or the one thing that's broken.
→ What the sprint covers -
Growing
Launched and growing.
Fixes, new features, performance or AI features, each at a fixed price before I start. Heading into a raise? The review works here too.
→ Tell me what you need -
Established
You need another senior engineer.
I join your team's tracker, pull requests and code review, and quote per engagement.
→ Tell me about your team
Before The prototype: it works
- 1User B can see user A's orders.
- 2Any signed-in user can reach the admin tools.
- 3Any visitor can run up your AI bill, with no cap.
- 4Failed payments are recorded nowhere.
After Ready for real users
- User B asks for user A's orders and gets an error.
- Admin tools only open for admins.
- AI use is capped.
- Failed payments are recorded, and you're told.
The kinds of problems a review looks for. Each fix gets a plain test you approve first.
See a sample report → An anonymized review of a public open-source Lovable app.
The Watson Standard
A standard is something you can check. Here are six things you can hold me to.
- You talk to the person doing the work.
- You get a fixed price before any work starts.
- Every finding says where it is, why it matters in plain words, and what to do about it.
- If I couldn't check something, the report says what and why.
- Every fix comes with a plain test you approve first.
- I never test your live app or touch real user data without your written OK.
Proof
- Akaya, now
- Current work. I'm contracting with Portland State University on Akaya, an AI knowledge tool, taking it from prototype toward production: its deploys, safe database changes and privacy-safe logging.
- eBay, 2013 to 2024
- Production at scale. 11 years as a software engineer. I helped rebuild charity.ebay.com and shipped the item page's bidding-flow redesign.
Details, if you're deciding
Open what you need.
The Launch-Ready Sprint
Review, fixes and a re-check. Step one is the $400 review, and you can stop there.
Your app reviewed, fixed and checked again before you put real users and real money on it.
- The review, $400. A written report in 2 business days. You can stop here and keep the report.
- The fixes, at one fixed price and finish time set in the report. They cover every Critical, High and Medium problem in the report, as quoted there, and the $400 comes off their price if you book them within 14 days of the report. The finish time counts from the start date we agree when you book, not counting days I'm waiting on you. Each fix has a plain test you approve first.
- The re-check. After the fixes, I re-run the review's checks on the version with my fixes in it, and read my changes and any other changes to the code the review covered. You get a short, dated summary of what I checked and fixed, which you can show investors or customers. Like the report, it says it isn't a certificate that the app is secure. If the re-check finds a Critical or High problem in the code or settings I reviewed that the report didn't list, or ranked lower, I fix it free, and it counts toward the same cap as the 30 days of cover. Anything else new gets its own quote. The re-check and the extras below come only with the full sprint, when you book the fixes for every Critical, High and Medium problem in the report, and they're included in that price.
For a small app, I'd expect about two weeks from the agreed start date to the re-check, and the report sets the exact finish time. See how the sample report prices its fixes →
Only with the full sprint (you book the fixes for every Critical, High and Medium problem in your report), and these are included in the fix price:
- Guardrails for your AI builder. A rules file for Lovable, Cursor, Claude Code or whatever you build with, written from your report, that tells it not to put the same holes back. AI builders don't always follow their rules, so I can't promise the holes stay closed.
- Launch-day cover. On the day you launch, I reply within an hour during US Pacific working hours, and if a change I made breaks that day, I fix it free. I'm one person, so it's one day, booked ahead.
- 30 days of cover. If a Critical or High problem the report didn't list, or ranked lower, turns up within 30 days of the re-check summary, I fix it free.
Both covers have limits, and they're spelled out in the guarantee.
Step one, the review, gives you:
- Every finding ranked Critical, High, Medium or Low: where it is, what I saw, why it matters in plain words and how to fix it.
- A short answer at the top: can you put real users on this now, only after the must-fix items, or not yet? If I couldn't check something, the report says what and why.
- A 30-minute call to walk through it, included. You can share the report with investors or a new hire, and they're welcome on the call.
$400 for now; the price is locked when you book.
What $400 covers: one app with one database, the kind a single builder project creates. If yours is bigger, I'll tell you the price before you pay anything. Built in a no-code tool without a code export, like Bubble? Tell me first and I'll say whether I can review it. Before you pay, I'll give you a start date, the earliest I have free, and hold it for 3 business days while you decide. The 2 business days count from that date, once I have the code and a test login.
What I'll ask you for: the code (read access to your GitHub repository, or an export from your builder) and a test login, ideally one ordinary user and one admin. Read-only access to your database and hosting settings helps but isn't required. If your database holds real customer or patient records, we set up a test copy with made-up data instead, so I never see real records. I'll send step-by-step instructions, and I never need live keys.
Already live? The report marks anything you should switch off or work around now, while the fixes happen.
See a sample report → An anonymized review of a public open-source Lovable app.
What I check
Eight areas, from security to code health.
I read your code and settings and test with accounts you set up for me. I don't attack your live app or touch real user data unless you've agreed in writing first.
B.1SecurityCovered
Secret keys in the code or sent to visitors' browsers. Database rules (in Supabase, row-level security) that let one user read or change another's data. Server code that trusts whatever the browser sends. Libraries with known security holes.
B.2Sign-in and accountsCovered
Sign-up, login, password reset and logout, and whether a user can reach records or admin tools that aren't theirs.
B.3Data and privacyCovered
What personal data the app collects, where it's stored, who can read it, which outside services get it, and whether you can delete it or restore from a backup.
B.4ReliabilityCovered
What happens when a payment, email or AI service fails or runs slowly, whether you'll see the errors, and whether orders can be lost or charged twice.
B.5DeploymentCovered
How a change reaches your live app, where keys are kept, how fast you can undo a bad release, and whether you could run the app without your builder.
B.6Cost risksCovered
Paid services any visitor can trigger with no cap, and plans that will bill you unexpectedly as you grow.
B.7AI features and agentsCovered
If your app uses AI: what it can see and do on a user's behalf, whether a message, email or web page can trick it into doing something it shouldn't, and whether actions that matter wait for a person to approve them.
B.8Code healthCovered
How hard the code will be to change safely, and what's most likely to break next.
How deep each area goes depends on the access you give me, and the report says plainly what I couldn't check. It's a code and configuration review, not a penetration test, legal advice, a compliance certificate or a promise that the app has no bugs.
Fixes and new work
Fixes, first versions and small builds: a fixed price before I start, and a test you approve.
Every piece of work gets a fixed price before I start, not an hourly meter.
- Before the fixWhen user B asks for user A's orders, they get them.Fails
- After the fixWhen user B asks for user A's orders, they get an error.Passes
- Each item comes with a plain test of what "fixed" or "done" means, for example "when user B asks for user A's orders, they get an error". You approve the tests first.
- If you built it with Lovable, Replit or Bolt, you keep building there afterwards: I make changes so they sync back, usually through its GitHub connection. If your builder can't take outside changes cleanly, I'll say so in the quote, before you pay.
- You get a handover note: what was done, what's still open and what to watch.
- Anything new gets its own short quote. I won't quietly grow the job or the bill.
First versions, quoted per project: if you haven't built it yet, I can build the first version for you. Tell me what it has to do, and before I start I'll quote a fixed price and a finish date, and say whether it's meant for real users or as a prototype to test the idea.
Small builds, from $175: a script, a spreadsheet automation, a browser extension or a connection between two tools you already use.
Guarantee
A full refund on the review if it wasn't worth it, and cover with the full sprint.
If the report is late, finds nothing you can act on, or you don't think it was worth what you paid, tell me within 7 days of delivery and I'll refund the review in full. If the $400 comes off your fixes, it can't also come back to you as a "wasn't worth it" refund. It's one or the other. If a fix fails its agreed test within 14 days of delivery, and nobody has changed that code since, I'll fix it again at no charge.
Launch-day cover (full sprint only, as set out in section A). We pick one launch day together, from the dates I have open, at least 5 business days ahead and within 30 days after the re-check summary. I never cover two launches on the same day. That day, from 9 AM to 5 PM US Pacific time, I reply within an hour to your emails, or on another channel we agree on. If something fails that day because of a change I made in the sprint, and nobody else has changed that code since the re-check, I fix it free. Anything else gets its own quote first.
30 days of cover (full sprint only, as set out in section A). If a Critical or High problem the report didn't list, or ranked lower, turns up, I fix it free, within these limits:
- The 30 days start on the date of the re-check summary. You need to tell me in writing before they end.
- The summary records the version of your code and settings I checked. The cover applies only to problems present in that version.
- It covers only the code and settings the review covered, and not anything the report or the re-check summary says I couldn't check.
- Severity uses the report's own scale. The severity, and whether the problem was in the version I checked, are my call, and I give you my reasons in writing.
- It doesn't cover weaknesses in outside code or services, such as a library or your hosting, that were made public after the re-check.
- In total, the free work, including any free fix from the re-check, is capped at the price of the sprint's fixes in your report, before the $400 comes off. I price each free fix as I'd have quoted it and keep a running total you can see. Beyond the cap, I quote first.
Questions
Builder scans, sensitive data, studios, your code, and stopping partway.
- My builder or ChatGPT already scans my code. Why pay you?
- Run it; it'll catch some things. A scanner gives you a list, sometimes with draft fixes. I add judgment on what matters for your app and your launch, confirm every finding myself and give you a fixed price to fix each one. With the sprint, I also make the fixes and re-check them. In the sample report, the finding that looks scariest to a scanner mattered least, and the real risk was a database rule that depended on one dashboard setting.
- My app handles health or other personal data. Can you work on it?
- Yes. I work from test data, never real patient or customer records, and we'll agree how your data is handled before I start. I don't provide compliance certification. If you need me to sign a business associate agreement or another data agreement, send it first: I'll read it and tell you whether I can work under it.
- I run a studio or agency. Can you review client work?
- Yes. I can deliver the report unbranded and without my fix quote, so you price the fixes. I never contact your clients, and we can arrange pricing for repeat work.
- What happens to my code?
- I keep it confidential, and I'll sign your NDA once I've checked it allows the AI tools I use. I use AI coding tools (Claude Code and OpenAI Codex) to read code faster. Before I use them on your code, I check that their model-training controls are switched off, including Codex's separate Include environments setting. Your production database and your users' records never go into them, and within 7 days of the job ending (for a review on its own, 14 days after the report; for the sprint, when the 30 days of cover end), I delete my copies of your code and data and the session logs my AI tools keep for your project, and tell you when it's done. I keep the report and our emails. Codex also keeps a shared history on my computer that can't be cleared for a single project, so parts of what it read can stay there. Please send test keys, not live ones.
- Can I stop partway, or ask about a charge?
- Yes. You can end a job at any time by email. You pay for the work done up to then, measured against the quote, and I refund anything you've paid beyond that. Refunds go back to the card or bank account you paid from. Questions about a charge? Email bryce@watsonstandardco.com.
Tell me where you are.
Tell me what you're building and what's coming up, like a launch or an investor demo. I'll reply within 2 business days with the simplest first step. Rather talk first? Book a free 15-minute call. I work US Pacific hours.
Thanks, it's on its way to me. I'll reply within 2 business days from bryce@watsonstandardco.com. If it's urgent, email me directly.
Web3Forms relays your message, and the Feedback link's notes, to my inbox. I use them only to reply, and I don't share them. This site counts visits and clicks with Cloudflare's analytics and a small counter of my own, without cookies, and never records who you are or what you type.
Health or other sensitive data? Tell me first, and we'll agree how it's handled. I work from test data, not real records.