[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"technologies":3,"\u002Fblog\u002Fai-code-audit-findings":167,"team-members":639,"blog-topics":982,"mdc--12ftuw-key":1023,"glossary":1142},[4,10,15,21,26,32,38,43,48,53,58,63,68,73,77,82,87,92,97,103,108,113,118,123,128,133,138,143,147,152,157,162],{"title":5,"description":6,"slug":7,"category":8,"icon":9},"Android","Every app we ship reaches Android — platform APIs, background execution, permissions, and the store requirements that come with them.","android","framework","logos:android-icon",{"title":11,"description":12,"slug":13,"category":8,"icon":14},"Angular","The front-end framework we work in when a product is already Angular — a batteries-included structure that suits large, long-lived apps.","angular","logos:angular-icon",{"title":16,"description":17,"slug":18,"category":19,"icon":20},"Dart","The language every Flutter app we ship is written in — sound null safety, real pattern matching, and a compiler that targets native and the web.","dart","language","logos:dart",{"title":22,"description":23,"slug":24,"category":8,"icon":25},"Django","The Python framework we use when a product needs an admin, auth and a real data model on day one rather than a hand-rolled service.","django","logos:django-icon",{"title":27,"description":28,"slug":29,"category":30,"icon":31},"Docker","Every service we build ships as a container, so what runs on a laptop, in CI and in production is one artefact rather than three of them.","docker","infrastructure","logos:docker-icon",{"title":33,"description":34,"slug":35,"category":36,"icon":37},"Fastlane","The release automation behind our mobile work — signing, builds and store uploads run from CI instead of from one engineer's laptop on release day.","fastlane","tools","logos:fastlane",{"title":39,"description":40,"slug":41,"category":8,"icon":42},"Flutter","Our primary mobile stack since 2018 — one Dart codebase shipping to iOS, Android, web and desktop without a separate team per platform.","flutter","logos:flutter",{"title":44,"description":45,"slug":46,"category":36,"icon":47},"Git","Every project we touch lives in Git — reviewed pull requests, CI on every branch, and a history that still makes sense months later.","git","logos:git-icon",{"title":49,"description":50,"slug":51,"category":19,"icon":52},"Go","Our backend language for real-time APIs and services under load — small binaries, fast builds, and concurrency that stays readable.","go","logos:gopher",{"title":54,"description":55,"slug":56,"category":30,"icon":57},"Google Cloud","The cloud our production workloads run on — managed Kubernetes, storage and networking, without hand-built servers nobody wants to maintain.","gcp","logos:google-cloud",{"title":59,"description":60,"slug":61,"category":36,"icon":62},"Gradle","The build system every Android release goes through — product flavours, signing configs, and the dependency wiring under a Flutter app.","gradle","logos:gradle",{"title":64,"description":65,"slug":66,"category":30,"icon":67},"Helm","How we package a Kubernetes deployment — service, config, secrets and ingress as one versioned unit that can be promoted and rolled back.","helm","logos:helm",{"title":69,"description":70,"slug":71,"category":19,"icon":72},"Kotlin","What we reach for when a Flutter app needs real Android underneath it — platform channels, background work, and native SDK integrations.","kotlin","logos:kotlin-icon",{"title":74,"description":75,"slug":76,"category":8,"icon":72},"Kotlin Multiplatform","Sharing business logic across iOS and Android while each platform keeps its own native UI — the alternative when Flutter is not the right fit.","kmp",{"title":78,"description":79,"slug":80,"category":30,"icon":81},"Kubernetes","How we run services in production — Helm-packaged deployments, rollouts that can be rolled back, and scaling that does not need a person at 3am.","kubernetes","logos:kubernetes",{"title":83,"description":84,"slug":85,"category":30,"icon":86},"NATS","Lightweight messaging between services — publish\u002Fsubscribe and request\u002Freply without the operational weight of a full broker cluster.","nats","logos:nats-icon",{"title":88,"description":89,"slug":90,"category":8,"icon":91},"Nuxt","Vue with server rendering, routing and SEO handled — how we build marketing sites and web apps that must be fast and indexable on first load.","nuxt","logos:nuxt-icon",{"title":93,"description":94,"slug":95,"category":19,"icon":96},"PHP","Where we work with an existing PHP backend — extending it, integrating with it, and building the mobile and web clients it has to serve.","php","logos:php",{"title":98,"description":99,"slug":100,"category":101,"icon":102},"PostgreSQL","Our default database — the one we reach for unless a product gives us a specific reason not to, from schema design through to index tuning.","postgres","database","logos:postgresql",{"title":104,"description":105,"slug":106,"category":19,"icon":107},"Python","Our language for backends, data work and AI integrations — including the Python bindings we ship for our own Rust tooling.","python","logos:python",{"title":109,"description":110,"slug":111,"category":8,"icon":112},"React","The front-end library we work in when a product is already React — components, hooks, and the ecosystem that has grown around them.","react","logos:react",{"title":114,"description":115,"slug":116,"category":101,"icon":117},"Redis","Where we put data that has to be fast and can be rebuilt — caches, sessions, rate limits, and the queues behind a product's slow paths.","redis","logos:redis",{"title":119,"description":120,"slug":121,"category":19,"icon":122},"Ruby","The language our mobile release automation is written in — Fastlane lanes, custom actions, and the CI glue that ships builds to the stores.","ruby","logos:ruby",{"title":124,"description":125,"slug":126,"category":19,"icon":127},"Rust","Where we go when performance and correctness both matter — document rendering, CLI tooling, and services that have to stay fast and predictable.","rust","simple-icons:rust",{"title":129,"description":130,"slug":131,"category":101,"icon":132},"SQLite","The database that ships inside the app — local caches, offline-first storage, and anything that still has to work with no network.","sqlite","logos:sqlite",{"title":134,"description":135,"slug":136,"category":8,"icon":137},"Strapi","A headless CMS we reach for when editors need to own the content — a real admin and a clean API, without building either from scratch.","strapi","logos:strapi-icon",{"title":139,"description":140,"slug":141,"category":19,"icon":142},"Swift","What we reach for when a Flutter app needs real iOS underneath it — platform channels, native SDK integrations, widgets and App Clips.","swift","logos:swift",{"title":144,"description":145,"slug":146,"category":8,"icon":142},"SwiftUI","Apple's UI framework, where we build the native surfaces a Flutter app cannot own — widgets, App Clips, extensions and system integrations.","swiftui",{"title":148,"description":149,"slug":150,"category":8,"icon":151},"Tailwind CSS","How we style every front end we build — utility classes and design tokens instead of a stylesheet that only ever grows and is never deleted.","tailwind","logos:tailwindcss-icon",{"title":153,"description":154,"slug":155,"category":19,"icon":156},"TypeScript","The default for everything we write for the browser and for Node services — types that catch integration bugs before they reach a review.","typescript","logos:typescript-icon",{"title":158,"description":159,"slug":160,"category":8,"icon":161},"Vue","Our front-end framework for admin panels, merchant dashboards and product web apps that have to stay maintainable for years, not sprints.","vue","logos:vue",{"title":163,"description":164,"slug":165,"category":36,"icon":166},"Whisper","OpenAI's open-source speech recognition model — the transcription engine behind voice input, running as both a backend service and on-device in the app.","whisper","simple-icons:openai",{"id":168,"title":169,"author":170,"body":171,"description":620,"extension":621,"hero":622,"meta":625,"metaDescription":626,"metaTitle":627,"navigation":628,"ogDescription":629,"path":630,"seo":631,"slug":632,"stem":633,"summary":634,"timestamp":635,"topic":636,"updated":637,"__hash__":638},"blog_en\u002Fblog\u002Fai-code-audit-findings.md","AI Code Audit Findings: 11 Problems in Almost Every AI-Built Codebase","nixan",{"type":172,"value":173,"toc":598},"minimark",[174,235,238,243,250,254,261,264,267,269,273,281,287,297,301,310,315,320,324,327,332,337,341,348,351,356,361,365,368,373,378,382,390,395,400,404,410,415,420,424,427,430,435,440,444,451,454,459,468,472,479,486,491,496,500,503,510,515,520,522,526,537,541,549,553,564,567,569,573,577,581,584],[175,176,177,181,182,186,187,190,191,194,195,190,198,190,201,190,204,190,207,190,210,190,213,190,216,219,220,223,224,229,230,234],"p",{},[178,179,180],"strong",{},"TL;DR."," We run a lot of audits on apps built with Cursor, Claude Code, Bolt, Lovable, and long ChatGPT sessions. The codebases differ wildly, but the ",[183,184,185],"em",{},"findings"," almost never do. Eleven problems show up again and again, roughly in the order they tend to hurt: ",[178,188,189],{},"hardcoded secrets and credentials",", ",[178,192,193],{},"no input validation"," (the injection surface), ",[178,196,197],{},"authentication that checks the box but not the request",[178,199,200],{},"zero test coverage",[178,202,203],{},"no error handling on the unhappy path",[178,205,206],{},"N+1 queries and performance left to chance",[178,208,209],{},"stale dependencies with known CVEs sitting unpatched",[178,211,212],{},"duplicated variables and functions",[178,214,215],{},"no consistent architecture",[178,217,218],{},"complex async state collapsed into callback hell instead of streams",", and ",[178,221,222],{},"no awareness of the deployment environment",". None of these are exotic. All of them are predictable — and all of them are fixable without a rewrite. This is the engineering companion to our ",[225,226,228],"a",{"href":227},"\u002Fblog\u002Fai-prototype-to-production","founder's guide to shipping an AI prototype","; if you want it handled, that is what an ",[225,231,233],{"href":232},"\u002Fservices\u002Fai-code-audit","AI code audit"," does.",[236,237],"hr",{},[239,240,242],"h2",{"id":241},"what-an-audit-is-and-isnt","What an Audit Is — and Isn't",[175,244,245,246,249],{},"An audit is not a rewrite, and it is not a verdict on whether you should have used AI to build the thing. It is a structured read of a working codebase that answers one question: what happens the first time this meets a real attacker, a real spike in traffic, or a real change six months from now? The findings below are not hypothetical categories from a checklist — every one of them is something we have found, redacted, and fixed in a real engagement. We reference our sample audit report and the ",[225,247,248],{"href":232},"AI code audit service"," throughout, because that is where the fix actually happens; this post is the evidence for why the fix is needed.",[239,251,253],{"id":252},"why-the-findings-repeat","Why the Findings Repeat",[175,255,256,257,260],{},"AI coding tools optimize for one thing: the shortest path to code that ",[183,258,259],{},"runs",". That is genuinely useful — you get an idea into a working state in hours. But \"runs in the demo\" and \"maintainable and safe in production\" are different targets, and the gap between them is remarkably consistent across projects.",[175,262,263],{},"The reason is structural. A model generating code has a narrow window of context and no memory of the decisions it made three files ago. It cannot test the thing it just wrote, it has no sense of your runway or your security posture, and it has no incentive to keep the codebase coherent over time. So it makes the locally optimal choice every time — and the sum of locally optimal choices is a codebase that works today and resists every change tomorrow.",[175,265,266],{},"After enough audits, the failures cluster into the same eleven buckets. Here they are.",[236,268],{},[239,270,272],{"id":271},"_1-hardcoded-secrets-and-credentials","1. Hardcoded Secrets and Credentials",[175,274,275,276,280],{},"Every audit finds this, and it is exactly the smell that costs real money: ",[277,278,279],"code",{},".env"," files committed to the repository, API keys and database credentials hardcoded directly in source, third-party tokens baked into client bundles that ship to every browser that loads the app. One leaked OpenAI or Stripe key can run up thousands of dollars in unauthorized charges within hours — or hand an attacker your data store outright.",[175,282,283,286],{},[178,284,285],{},"Why AI does this."," Hardcoding a key works immediately; wiring up a secrets manager or environment injection does not, and the model has no reason to prefer the slower path when the faster one also \"runs.\" The shortest path to a working feature is almost never the secure one.",[175,288,289,292,293,296],{},[178,290,291],{},"How we fix it."," Secrets come out of source and into proper environment management. Anything that was ever committed to git is treated as already compromised and rotated, not just removed — a ",[277,294,295],{},"git rm"," without rotation leaves the old key valid in every clone and every commit history. This is the non-negotiable part of any audit: a leaked key is an emergency, and it gets fixed first.",[239,298,300],{"id":299},"_2-no-input-validation-the-injection-surface","2. No Input Validation — the Injection Surface",[175,302,303,304,309],{},"SQL injection, XSS, and ",[305,306,308],"term",{"slug":307},"prompt-injection","prompt injection"," are pervasive in AI-built code, and the root cause is the same one every time: user input goes straight into a query, a template, or an LLM prompt with no validation or sanitization in between. A single vulnerable endpoint can compromise your entire database or let an attacker manipulate what your own AI features do.",[175,311,312,314],{},[178,313,285],{}," Validation is a second request the model was never asked to make. It generates the code that satisfies the happy-path prompt — \"take the user's message and save it\" — and the happy path never mentions what to reject.",[175,316,317,319],{},[178,318,291],{}," Every boundary where untrusted input enters the system gets explicit validation and parameterized queries or templates, not string concatenation. For AI features specifically, that means treating the prompt construction itself as an injection-prone boundary, not just the database layer.",[239,321,323],{"id":322},"_3-auth-that-checks-the-box-not-the-request","3. Auth That Checks the Box, Not the Request",[175,325,326],{},"AI-generated apps often implement authentication at the surface level — a login screen exists, and it works — but the backend never actually verifies permissions per request. API endpoints accept anything that hits them. Admin routes are reachable without a role check. User A can see User B's data by changing an ID in the URL — an insecure direct object reference sitting in production.",[175,328,329,331],{},[178,330,285],{}," \"Add a login page\" and \"check that this specific request is allowed to touch this specific record\" are different problems, and the model solves the one it was asked about. Authentication is visible in a demo; authorization gaps are invisible until someone exploits them.",[175,333,334,336],{},[178,335,291],{}," We audit every endpoint against who is actually allowed to call it, not who the login screen implies is allowed, and add the per-request authorization checks that were missing — ownership checks on records, role checks on admin routes, and rate limiting on anything a script could hammer.",[239,338,340],{"id":339},"_4-no-tests-every-deployment-is-a-gamble","4. No Tests — Every Deployment Is a Gamble",[175,342,343,344,347],{},"The single most common finding: ",[178,345,346],{},"there are no tests at all."," Not a thin suite, not flaky tests — zero. The app was validated by clicking through it, and that is the entire safety net.",[175,349,350],{},"This is invisible right up until the moment it is catastrophic. With no tests, there is no way to know whether a change broke something other than shipping it and waiting for a user to complain. Every deployment becomes a manual regression pass that nobody actually performs, so refactoring becomes terrifying, dependency updates get skipped, and the codebase calcifies — not because the code is bad, but because no one dares touch it.",[175,352,353,355],{},[178,354,285],{}," Generating a feature and generating tests for that feature are two separate requests, and nobody made the second one. The model will happily write tests if asked, but left to its own devices it ships the happy path and stops.",[175,357,358,360],{},[178,359,291],{}," We do not aim for 100% coverage on day one. We add a thin layer where it pays off most: a smoke test that the app boots, tests around the money-handling and auth logic, and a regression test for every bug we fix during the audit. That alone turns deployments from a gamble into a routine.",[239,362,364],{"id":363},"_5-no-error-handling-on-the-unhappy-path","5. No Error Handling on the Unhappy Path",[175,366,367],{},"The app works exactly as demoed — as long as the network never drops, the third-party API never times out, and the user never does anything unexpected. The moment one of those things happens, the symptoms are ugly: an unhandled promise rejection crashes the whole request, a failed API call leaves the UI stuck on a spinner forever, an exception surfaces a raw stack trace to the user instead of a message that means anything to them.",[175,369,370,372],{},[178,371,285],{}," The happy path is what the prompt described and what the demo exercised. Error handling is defensive code written for situations the model was never told to imagine, and it adds lines without making the demo look any more impressive — so it is the first thing skipped under an implicit time budget.",[175,374,375,377],{},[178,376,291],{}," We walk every external call — API, database, file system — and add the failure branch: retries with backoff where retrying helps, a fallback or a clear error state where it does not, and logging that tells you what actually happened instead of a generic \"something went wrong.\" The goal is that a third-party outage degrades your app gracefully instead of taking it down.",[239,379,381],{"id":380},"_6-n1-queries-and-performance-left-to-chance","6. N+1 Queries and Performance Left to Chance",[175,383,384,385,389],{},"The list screen that loads instantly with ten rows in development grinds to a crawl with ten thousand in production. The classic cause is an N+1 query: one query to fetch a list, then a separate query per row to fetch its related data, so a screen that should cost one round trip to the database costs hundreds. Missing indexes, unbounded result sets with no pagination, and loading entire objects when only a field or two is displayed are the usual companions. Our ",[225,386,388],{"href":387},"\u002Fblog\u002Fdatabases-and-indexes","guide to databases and indexes"," covers the mechanics of why this is slow and what a healthy query plan looks like.",[175,391,392,394],{},[178,393,285],{}," The N+1 pattern is the most obvious way to write the loop, and it produces correct output — the model has no feedback loop that tells it the query count matters until someone measures it under real data volume, which a demo with a handful of rows never does.",[175,396,397,399],{},[178,398,291],{}," We profile the actual query patterns under realistic data volume, collapse the N+1 chains into joins or batched loads, add the missing indexes, and put pagination or limits on anything that returns an unbounded set. This is usually the single highest-leverage performance fix in an audit, because one bad list screen can account for most of a page's load time.",[239,401,403],{"id":402},"_7-dependency-and-cve-drift","7. Dependency and CVE Drift",[175,405,406,409],{},[277,407,408],{},"npm audit"," or its equivalent turns up a wall of known vulnerabilities the moment anyone runs it — because nobody had. Packages are pinned to whatever version was current when the AI tool scaffolded the project, transitive dependencies nobody chose directly carry their own CVEs, and there is no process for finding out when a patch ships.",[175,411,412,414],{},[178,413,285],{}," The model picks a package that solves the immediate problem and moves on; it has no ongoing relationship with your project that would prompt it to revisit that choice later. Dependency hygiene is a maintenance activity, and nothing about generating a feature triggers maintenance.",[175,416,417,419],{},[178,418,291],{}," We run a dependency vulnerability scan, patch or replace anything with a known exploit, and set up a process — even a simple scheduled scan — so this does not silently drift again the moment the audit ends.",[239,421,423],{"id":422},"_8-duplicated-variables-and-functions","8. Duplicated Variables and Functions",[175,425,426],{},"Open an AI-built codebase and search for the same date-formatting helper. You will often find it three or four times — slightly different each time, because each was generated in isolation for the screen that needed it. The same goes for validation rules, API clients, currency math, and configuration constants.",[175,428,429],{},"Duplication is not just ugly; it is a correctness time bomb. When the logic needs to change — a new tax rule, a fixed rounding bug, an updated endpoint — you have to find every copy. You will miss one. Now two parts of the app disagree about something they should agree on, and that disagreement is the next production incident.",[175,431,432,434],{},[178,433,285],{}," The model rarely searches the existing codebase for a helper it could reuse. It is cheaper, from its perspective, to regenerate the function inline than to discover and import the one that already exists. Each generation is locally reasonable; the aggregate is drift.",[175,436,437,439],{},[178,438,291],{}," We find the clusters of near-identical code, extract a single source of truth, and route every call site through it. This is one of the highest-leverage cleanups in most audits: it shrinks the codebase and removes whole categories of \"fixed here but not there\" bugs.",[239,441,443],{"id":442},"_9-no-consistent-architecture","9. No Consistent Architecture",[175,445,446,447,450],{},"This one is jarring to see for the first time. Two screens in the ",[183,448,449],{},"same project"," will be written as if by two different teams: one fetches data in the component, the other through a service layer; one holds state one way, the next does it completely differently; naming, folder structure, and error handling change from feature to feature. There is no spine.",[175,452,453],{},"A codebase with no consistent architecture is one where every file you open is a surprise. Onboarding a developer takes weeks because there is no pattern to learn — only a hundred special cases to memorize. Worse, when patterns conflict, the seams between them are exactly where bugs breed.",[175,455,456,458],{},[178,457,285],{}," The model has no persistent picture of \"how this app is built.\" Each prompt is a fresh start, so it reaches for whatever pattern fits that one request. Over a project's life that produces a patchwork — every piece sensible alone, the whole thing incoherent.",[175,460,461,463,464,467],{},[178,462,291],{}," We pick one architecture that fits the project — not a dogmatic one, a ",[183,465,466],{},"fitting"," one — and converge the codebase onto it incrementally, so a developer who learns one feature can predict how the next one works.",[239,469,471],{"id":470},"_10-stream-based-state-avoided-straight-into-callback-hell","10. Stream-Based State Avoided — Straight Into Callback Hell",[175,473,474,475,478],{},"This is the most technically interesting failure, and the one that quietly breaks the hardest features. AI-generated code tends to ",[178,476,477],{},"avoid stream- and reactive-state models"," in favor of imperative callbacks. Instead of modeling \"this value changes over time and the UI reacts,\" it wires up a callback, which triggers another callback, which sets a flag, which fires a third — and the result is callback hell.",[175,480,481,482,485],{},"For simple screens you barely notice. But the moment the state is genuinely complex — a multi-step form with cross-field validation, a live-updating dashboard, anything with debouncing, retries, cancellation, or optimistic updates — the callback approach falls apart. The classic symptom is the form that ",[183,483,484],{},"almost"," works: it validates, but the error clears at the wrong moment; it submits, but a double-tap fires it twice.",[175,487,488,490],{},[178,489,285],{}," Imperative callbacks are the most common pattern in its training data and the easiest to generate one piece at a time. Reactive and stream-based models require holding the whole state machine in mind at once — exactly what a context-limited generator is worst at.",[175,492,493,495],{},[178,494,291],{}," We identify the complex-state features and rebuild their state layer properly — as streams or a reactive state model appropriate to the stack — so the UI is a function of state rather than a pile of callbacks racing each other.",[239,497,499],{"id":498},"_11-no-awareness-of-the-deployment-environment","11. No Awareness of the Deployment Environment",[175,501,502],{},"The model writes code as if it will run as a single process on one machine — because from inside the prompt, that is the only environment it can see. It has no idea how many instances will run, what managed services already exist, or how traffic is routed. So it defaults to the simplest possible topology, and that default quietly breaks the moment the app is deployed for real.",[175,504,505,506,509],{},"The symptoms are always the same. State that lives in process memory — a cache, sessions, rate-limit counters — works perfectly on one instance and silently diverges the moment a second replica comes up behind the load balancer. Background jobs fire on ",[183,507,508],{},"every"," instance instead of once, so the email goes out three times.",[175,511,512,514],{},[178,513,285],{}," It has no picture of your infrastructure. It does not know you already have Redis, a message queue, and object storage — so it reimplements them in memory. The deployment topology is exactly the context a prompt cannot contain.",[175,516,517,519],{},[178,518,291],{}," We map the actual deployment and move shared state to where it belongs: cache, sessions, and locks into Redis or the database, files into object storage, recurring work onto a real scheduler or queue. The result is code that scales horizontally.",[236,521],{},[239,523,525],{"id":524},"how-we-find-them","How We Find Them",[175,527,528,529,532,533,536],{},"Every finding above starts with an automated pass and ends with a human reading the code. The automation — static analysis, dependency and secrets scanning, API cost profiling — is what makes an AI-accelerated audit fast: it clears the categories that are mechanical to detect (findings 1, 4, 6, and 7 above surface here almost immediately) so the time our engineers spend is concentrated on the categories that require judgment — authorization logic, architecture, and whether a given error path actually matters for your product. Neither half works alone: automation alone misses everything that requires understanding what the code is ",[183,530,531],{},"for",", and manual review alone does not scale to a real codebase in a week. The full breakdown of the process is on the ",[225,534,535],{"href":232},"AI code audit service page",".",[239,538,540],{"id":539},"what-you-get-in-the-report","What You Get in the Report",[175,542,543,544,548],{},"Findings do not arrive as a raw list. Every one is ranked by severity — critical, high, medium, low — with a plain-language explanation of the risk, proof of concept where it applies, and a specific fix recommendation, the same shape every finding above followed. If you want to see the format before committing to anything, ",[225,545,547],{"href":546},"\u002Fcontact?intent=ai-code-audit","request a redacted sample audit report"," — the same report structure a real engagement produces, with client-identifying details removed.",[239,550,552],{"id":551},"the-pattern-behind-the-pattern","The Pattern Behind the Pattern",[175,554,555,556,559,560,563],{},"Step back and the eleven findings share one root cause: ",[178,557,558],{},"AI optimizes each generation locally, and nobody is optimizing the codebase globally."," Secrets management, input validation, authorization, tests, error handling, query performance, dependency hygiene, deduplication, architecture, state modeling, and deployment awareness are all ",[183,561,562],{},"whole-system"," properties. They cannot emerge one prompt at a time, because no single prompt can see the whole. That is precisely the gap a human review closes.",[175,565,566],{},"The reassuring part is that none of this means the AI-built foundation is wasted. The features work; the product is real. What is missing is the connective tissue — and adding it is far faster than rebuilding from scratch.",[236,568],{},[239,570,572],{"id":571},"frequently-asked-questions","Frequently Asked Questions",[574,575],"questions",{":items":576},"[{\"title\": \"What does an AI code audit actually find?\", \"text\": \"Across dozens of AI-generated codebases, eleven problems recur almost every time: hardcoded secrets and credentials, no input validation, authentication that checks the box but not the request, zero automated tests, no error handling on the unhappy path, N plus one queries and performance left to chance, stale dependencies with known CVEs, heavily duplicated variables and functions, no consistent architecture across the project, complex async state implemented as callback hell instead of streams, and code written with no awareness of the deployment environment. The specific code differs from project to project, but these eleven categories show up again and again.\"}, {\"title\": \"Why does AI-generated code leave secrets and API keys exposed?\", \"text\": \"Hardcoding a key works immediately, while wiring up a secrets manager or environment injection does not, and the model has no reason to prefer the slower, correct path when the faster one also runs. The result is .env files committed to the repository, keys hardcoded in source, and tokens baked into client bundles. Anything that was ever committed to git has to be treated as already compromised and rotated, not just deleted, because the old value stays valid in every clone and every commit history.\"}, {\"title\": \"Why does AI-generated code not validate user input?\", \"text\": \"Validation is a second request the model was never explicitly asked to make. It generates code that satisfies the happy-path prompt, and the happy path never mentions what to reject, so user input often goes straight into a query, a template, or an LLM prompt with no sanitization in between. That is the direct cause of the SQL injection, XSS, and prompt injection vulnerabilities that show up in nearly every AI-built codebase we review.\"}, {\"title\": \"Why does AI-generated code have no tests?\", \"text\": \"Because writing a feature and writing tests for it are two separate requests, and the second one usually never happens. AI tools optimize for the shortest path to code that runs, which is the happy path with no test suite behind it. The model will write tests when asked, but on its own it ships the feature and stops, leaving every future deployment without a safety net.\"}, {\"title\": \"Why is there so much duplicated code in AI-built apps?\", \"text\": \"The model rarely searches the existing codebase for a helper it could reuse. Regenerating a function inline for the screen that needs it is cheaper, from its perspective, than discovering and importing one that already exists. Each generation is locally reasonable, but the result is the same logic copy-pasted several times with small differences, which becomes a correctness problem the moment that logic needs to change.\"}, {\"title\": \"Why do complex forms built by AI often not work properly?\", \"text\": \"AI-generated code tends to avoid stream-based and reactive state models in favor of imperative callbacks. For simple screens that is fine, but complex state such as multi-step forms with cross-field validation, debouncing, retries, or optimistic updates collapses into callback hell. The classic symptom is a form that almost works: errors clear at the wrong moment, or a double-tap submits twice. Modeling the state as a stream fixes it.\"}, {\"title\": \"Why does AI-generated code fall over under real traffic?\", \"text\": \"The most common cause is an N plus one query pattern: one query to fetch a list, then a separate query per row for its related data, so a screen that should cost one database round trip costs hundreds. It looks correct in development with a handful of rows and only shows up once real data volume hits it, because nothing in the generation process measures query count. Missing indexes and unbounded result sets with no pagination are the usual companions.\"}, {\"title\": \"Why does AI-generated code break when it runs on more than one instance?\", \"text\": \"Because the model has no picture of how the app is deployed. It writes code for a single process on one machine, so it keeps state in memory and writes files to local disk. That works on one instance but breaks the moment the app is parallelised behind a load balancer: in-memory caches, sessions, and rate-limit counters diverge across replicas, and background jobs fire on every instance instead of once. The fix is to move shared state to the right backing services so the app scales horizontally.\"}, {\"title\": \"Do I need to rewrite my AI-built app to fix these problems?\", \"text\": \"No. All eleven findings are fixable in place. Secrets are removed and rotated, input gets validated at every boundary, authorization checks go on every endpoint that needs them, tests are added where they pay off most, failure paths get proper error handling, N plus one queries get collapsed into batched loads, dependencies get patched, duplicated logic is extracted into a single source of truth, the codebase converges onto one consistent architecture, complex-state features get a proper reactive state layer, and shared state moves to the right backing services. This keeps the working foundation the AI produced and only fixes the connective tissue that is missing, which is far faster and cheaper than a rebuild.\"}]",[239,578,580],{"id":579},"get-the-findings-for-your-codebase","Get the Findings for Your Codebase",[175,582,583],{},"If you have an AI-built app and you recognize any of these eleven, you are not behind — you are exactly where almost every AI-generated codebase lands. The fix is not a rewrite; it is a focused audit that adds the connective tissue the AI could not.",[175,585,586,587,190,589,592,593,597],{},"Run your codebase through an ",[225,588,233],{"href":232},[225,590,591],{"href":546},"request a sample audit report"," to see the format first, or ",[225,594,596],{"href":595},"\u002Fcontact","book a free assessment"," and we will tell you which of the eleven is your biggest risk, what it takes to fix, and give you a fixed-scope quote — not a guess.",{"title":599,"searchDepth":600,"depth":600,"links":601},"",2,[602,603,604,605,606,607,608,609,610,611,612,613,614,615,616,617,618,619],{"id":241,"depth":600,"text":242},{"id":252,"depth":600,"text":253},{"id":271,"depth":600,"text":272},{"id":299,"depth":600,"text":300},{"id":322,"depth":600,"text":323},{"id":339,"depth":600,"text":340},{"id":363,"depth":600,"text":364},{"id":380,"depth":600,"text":381},{"id":402,"depth":600,"text":403},{"id":422,"depth":600,"text":423},{"id":442,"depth":600,"text":443},{"id":470,"depth":600,"text":471},{"id":498,"depth":600,"text":499},{"id":524,"depth":600,"text":525},{"id":539,"depth":600,"text":540},{"id":551,"depth":600,"text":552},{"id":571,"depth":600,"text":572},{"id":579,"depth":600,"text":580},"TL;DR. We run a lot of audits on apps built with Cursor, Claude Code, Bolt, Lovable, and long ChatGPT sessions. The codebases differ wildly, but the findings almost never do. Eleven problems show up again and again, roughly in the order they tend to hurt: hardcoded secrets and credentials, no input validation (the injection surface), authentication that checks the box but not the request, zero test coverage, no error handling on the unhappy path, N+1 queries and performance left to chance, stale dependencies with known CVEs sitting unpatched, duplicated variables and functions, no consistent architecture, complex async state collapsed into callback hell instead of streams, and no awareness of the deployment environment. None of these are exotic. All of them are predictable — and all of them are fixable without a rewrite. This is the engineering companion to our founder's guide to shipping an AI prototype; if you want it handled, that is what an AI code audit does.","md",{"type":623,"src":624},"image","\u002Fblog\u002Fai-code-audit-findings.webp",{},"We audited dozens of AI-built codebases. The same 11 problems recur — hardcoded secrets, no tests, N+1 queries, stale dependencies — and how we fix each.","What an AI Code Audit Finds: 11 Real Problems",true,"We audited dozens of AI-built codebases. The same eleven problems turned up in almost every one. Here they are, worst first, with the fix for each.","\u002Fblog\u002Fai-code-audit-findings",{"title":169,"description":620},"ai-code-audit-findings","blog\u002Fai-code-audit-findings","Your AI-built app may already be live, and the security holes are only part of the story. We audited dozens of codebases built with Cursor, Claude Code, Bolt, Lovable, and long ChatGPT sessions, and the same eleven problems recur almost every time: hardcoded secrets, no input validation, authentication that checks the box but not the request, zero tests, no error handling on the unhappy path, N+1 queries, stale dependencies with known CVEs, rampant duplication, no consistent architecture, callback hell instead of proper async patterns, and no awareness of the deployment environment. Here is what each one looks like, why AI produces it, and how we fix it.","2026-06-18T15:55:24Z","software-engineering","2026-08-06T12:00:00Z","TjMZr6H4qiHQMTFclqblXWxHMKwyei9qqCHWtcc1Y8Y",[640,697,745,795,884,936],{"id":641,"bio":642,"expertise":647,"extension":663,"links":664,"meta":668,"metaDescription":669,"name":674,"ogDescription":677,"photo":682,"role":683,"seniority":688,"skills":689,"slug":690,"specialization":691,"stem":690,"__hash__":696},"team_members\u002Fdima.yaml",{"en":643,"ru":644,"es":645,"nl":646},"Dima has been building with [Flutter](\u002Ftechnologies\u002Fflutter) since 2021, and specializes in :term[state management]{slug=\"state-management\"} and app architecture.\n\nHe has hands-on experience with real-time communication protocols — :term{slug=\"webrtc\"} for audio and video, and :term{slug=\"xmpp\"} for messaging — which makes him comfortable with the network-heavy, stateful features many teams struggle to get right.\n","Дима работает с [Flutter](\u002Ftechnologies\u002Fflutter) с 2021 года и специализируется на :term[state management]{slug=\"state-management\"} и архитектуре приложений.\n\nУ него есть практический опыт с протоколами реального времени — :term{slug=\"webrtc\"} для аудио и видео и :term{slug=\"xmpp\"} для обмена сообщениями, — поэтому ему близки сетевые stateful-фичи, которые многим командам даются с трудом.\n","Dima trabaja con [Flutter](\u002Ftechnologies\u002Fflutter) desde 2021 y se especializa en :term[gestión de estado]{slug=\"state-management\"} y arquitectura de aplicaciones.\n\nTiene experiencia práctica con protocolos de comunicación en tiempo real —:term{slug=\"webrtc\"} para audio y vídeo, y :term{slug=\"xmpp\"} para mensajería—, lo que le hace sentirse cómodo con esas funcionalidades con mucho estado y mucha red que a muchos equipos se les atragantan.\n","Dima werkt sinds 2021 met [Flutter](\u002Ftechnologies\u002Fflutter) en is gespecialiseerd in :term[state management]{slug=\"state-management\"} en applicatiearchitectuur.\n\nHij heeft praktijkervaring met protocollen voor realtime communicatie — :term{slug=\"webrtc\"} voor audio en video, en :term{slug=\"xmpp\"} voor berichten — waardoor hij zich thuis voelt bij de netwerkzware functies met veel staat waar veel teams moeite mee hebben.\n",[648,651,656,658],{"en":649,"ru":649,"es":650,"nl":649},"State management","Gestión de estado",{"en":652,"ru":653,"es":654,"nl":655},"Application architecture","Архитектура приложений","Arquitectura de aplicaciones","Applicatiearchitectuur",{"en":657,"ru":657,"es":657,"nl":657},"WebRTC",{"en":659,"ru":660,"es":661,"nl":662},"XMPP messaging","Обмен сообщениями по XMPP","Mensajería XMPP","Berichten via XMPP","yaml",[665],{"type":666,"address":667},"email","konopatov@nerdy.pro",{},{"en":670,"ru":671,"es":672,"nl":673},"Lead Flutter developer at Nerdy Production, building real-time apps since 2021 — state management, app architecture, WebRTC and XMPP.","Ведущий Flutter-разработчик Nerdy Production: приложения реального времени с 2021 года — state management, архитектура, WebRTC и XMPP.","Lead de desarrollo Flutter en Nerdy Production, construyendo apps en tiempo real desde 2021: gestión de estado, arquitectura de aplicaciones, WebRTC y XMPP.","Lead Flutter-developer bij Nerdy Production, bouwt sinds 2021 realtime-apps — state management, applicatiearchitectuur, WebRTC en XMPP.",{"en":675,"ru":676,"es":675,"nl":675},"Dima","Дима",{"en":678,"ru":679,"es":680,"nl":681},"Lead Flutter developer at Nerdy Production — real-time apps since 2021, and the state management that keeps them from falling over.","Ведущий Flutter-разработчик Nerdy Production: приложения реального времени с 2021 года и state management, на котором они держатся.","Lead de desarrollo Flutter en Nerdy Production: apps en tiempo real desde 2021 y la gestión de estado que evita que se caigan.","Lead Flutter-developer bij Nerdy Production — realtime-apps sinds 2021, en het state management dat ze overeind houdt.","\u002Fteam\u002Fdima.webp",{"en":684,"ru":685,"es":686,"nl":687},"Lead Flutter Developer","Ведущий Flutter-разработчик","Lead de desarrollo Flutter","Lead Flutter-developer","lead",[41,18,155,160,90,111,150,95],"dima",{"en":692,"ru":693,"es":694,"nl":695},"Real-time apps, state management, and architecture","Приложения реального времени, state management и архитектура","Apps en tiempo real, gestión de estado y arquitectura","Realtime-apps, state management en architectuur","1TuxUt3zjdVkQUvMf9dBITG872C0exrdZyyoKw1beiE",{"id":698,"bio":699,"expertise":704,"extension":663,"links":715,"meta":716,"metaDescription":717,"name":722,"ogDescription":725,"photo":730,"role":731,"seniority":736,"skills":737,"slug":738,"specialization":739,"stem":738,"__hash__":744},"team_members\u002Fmasha.yaml",{"en":700,"ru":701,"es":702,"nl":703},"Masha builds [Flutter](\u002Ftechnologies\u002Fflutter) apps where design and copy are treated as one job.\n\nShe specializes in UI\u002FUX — turning product requirements into clean, usable interfaces — and in the writing inside the app, from onboarding flows to the microcopy that makes a screen make sense. The result is apps that feel considered, not just functional.\n","Маша делает приложения на [Flutter](\u002Ftechnologies\u002Fflutter), где дизайн и текст — одна задача.\n\nОна специализируется на UI\u002FUX, превращая продуктовые требования в чистые и удобные интерфейсы, и на текстах внутри приложения — от онбординга до микрокопирайта, который делает экран понятным. В итоге приложения получаются продуманными, а не просто рабочими.\n","Masha crea apps en [Flutter](\u002Ftechnologies\u002Fflutter) donde el diseño y el texto se tratan como un mismo trabajo.\n\nSe especializa en UI\u002FUX —convertir requisitos de producto en interfaces limpias y usables— y en la escritura dentro de la app, desde los flujos de onboarding hasta el microcopy que hace que una pantalla se entienda. El resultado son apps que se sienten pensadas, no solo funcionales.\n","Masha bouwt [Flutter](\u002Ftechnologies\u002Fflutter)-apps waarin ontwerp en tekst als één taak worden behandeld.\n\nZe is gespecialiseerd in UI\u002FUX — productwensen omzetten in heldere, bruikbare interfaces — en in de teksten binnen de app, van onboarding tot de microteksten die een scherm begrijpelijk maken. Het resultaat zijn apps die doordacht aanvoelen en niet alleen werken.\n",[705,710],{"en":706,"ru":707,"es":708,"nl":709},"UI\u002FUX design","UI\u002FUX-дизайн","Diseño UI\u002FUX","UI\u002FUX-ontwerp",{"en":711,"ru":712,"es":713,"nl":714},"Product copywriting","Продуктовый копирайтинг","Redacción de producto","Productteksten",null,{},{"en":718,"ru":719,"es":720,"nl":721},"Flutter developer at Nerdy Production working where design meets copy — UI\u002FUX, onboarding flows, and the microcopy that makes a screen make sense.","Flutter-разработчик Nerdy Production на стыке дизайна и текста: UI\u002FUX, онбординг и микрокопирайт, который делает экран понятным.","Desarrolladora Flutter en Nerdy Production, donde el diseño se encuentra con el texto: UI\u002FUX, onboarding y el microcopy que hace que una pantalla se entienda.","Flutter-developer bij Nerdy Production op het snijvlak van ontwerp en tekst — UI\u002FUX, onboarding, en de microteksten die een scherm begrijpelijk maken.",{"en":723,"ru":724,"es":723,"nl":723},"Masha","Маша",{"en":726,"ru":727,"es":728,"nl":729},"Flutter developer at Nerdy Production working where design meets copy — onboarding flows and the microcopy that makes a screen make sense.","Flutter-разработчик Nerdy Production на стыке дизайна и текста: онбординг и микрокопирайт, который делает экран понятным.","Desarrolladora Flutter en Nerdy Production, donde el diseño se encuentra con el texto: onboarding y el microcopy que hace entender una pantalla.","Flutter-developer bij Nerdy Production op het snijvlak van ontwerp en tekst — onboarding en de microteksten die een scherm begrijpelijk maken.","\u002Fteam\u002Fmasha.webp",{"en":732,"ru":733,"es":734,"nl":735},"Flutter Developer","Flutter-разработчик","Desarrolladora Flutter","Flutter-developer","middle",[41,18],"masha",{"en":740,"ru":741,"es":742,"nl":743},"UI\u002FUX and copywriting for Flutter apps","UI\u002FUX и копирайтинг для Flutter-приложений","UI\u002FUX y redacción para apps Flutter","UI\u002FUX en teksten voor Flutter-apps","z3c64iWR39RIrn8wE0elSy00IfCITYgNkbgp_G_sslk",{"id":746,"bio":747,"expertise":752,"extension":663,"links":763,"meta":766,"metaDescription":767,"name":772,"ogDescription":775,"photo":780,"role":781,"seniority":786,"skills":787,"slug":788,"specialization":789,"stem":788,"__hash__":794},"team_members\u002Fmaxim.yaml",{"en":748,"ru":749,"es":750,"nl":751},"Maxim is a polyglot engineer who moves comfortably across [Go](\u002Ftechnologies\u002Fgo), [Flutter](\u002Ftechnologies\u002Fflutter), [Python](\u002Ftechnologies\u002Fpython), and [TypeScript](\u002Ftechnologies\u002Ftypescript), which lets him own a feature from the backend to the screen.\n\nHe came up at Ozon, one of Russia's largest marketplaces, where scale makes reliability non-negotiable — and it shows in his work: testing is a first-class part of how he builds, not an afterthought bolted on at the end.\n","Максим — полиглот-инженер, свободно работающий с [Go](\u002Ftechnologies\u002Fgo), [Flutter](\u002Ftechnologies\u002Fflutter), [Python](\u002Ftechnologies\u002Fpython) и [TypeScript](\u002Ftechnologies\u002Ftypescript), что позволяет ему вести фичу от бэкенда до экрана.\n\nОн вырос в Ozon, одном из крупнейших маркетплейсов России, где масштаб делает надёжность обязательной, — и это видно в его работе: тестирование для него первоклассная часть разработки, а не то, что прикручивают в конце.\n","Maxim es un ingeniero políglota que se mueve con soltura entre [Go](\u002Ftechnologies\u002Fgo), [Flutter](\u002Ftechnologies\u002Fflutter), [Python](\u002Ftechnologies\u002Fpython) y [TypeScript](\u002Ftechnologies\u002Ftypescript), lo que le permite hacerse cargo de una funcionalidad desde el backend hasta la pantalla.\n\nSe formó en Ozon, uno de los mayores marketplaces de Rusia, donde la escala hace que la fiabilidad no sea negociable, y se le nota: el testing es para él una parte de primera clase de cómo construye, no un añadido al final.\n","Maxim is een polyglotte engineer die zich moeiteloos beweegt tussen [Go](\u002Ftechnologies\u002Fgo), [Flutter](\u002Ftechnologies\u002Fflutter), [Python](\u002Ftechnologies\u002Fpython) en [TypeScript](\u002Ftechnologies\u002Ftypescript), waardoor hij een functie van de backend tot het scherm kan dragen.\n\nHij is opgegroeid bij Ozon, een van de grootste marktplaatsen van Rusland, waar schaal betrouwbaarheid onderhandelbaar maakt noch toestaat — en dat zie je terug in zijn werk: testen is bij hem een volwaardig onderdeel van hoe hij bouwt, geen bijzaak die er aan het eind bij komt.\n",[753,758],{"en":754,"ru":755,"es":756,"nl":757},"Automated testing","Автоматизированное тестирование","Testing automatizado","Geautomatiseerd testen",{"en":759,"ru":760,"es":761,"nl":762},"High-load backend systems","Высоконагруженные бэкенд-системы","Sistemas backend de alta carga","Backendsystemen met hoge belasting",[764],{"type":666,"address":765},"maxim@nerdy.pro",{},{"en":768,"ru":769,"es":770,"nl":771},"Senior engineer at Nerdy Production across Go, Flutter, Python and TypeScript — from backend to screen, with automated testing built in.","Старший инженер Nerdy Production: Go, Flutter, Python и TypeScript — от бэкенда до экрана, с автотестами как частью разработки.","Ingeniero senior en Nerdy Production con Go, Flutter, Python y TypeScript: del backend a la pantalla, con testing automatizado incorporado.","Senior engineer bij Nerdy Production met Go, Flutter, Python en TypeScript — van backend tot scherm, met geautomatiseerd testen ingebouwd.",{"en":773,"ru":774,"es":773,"nl":773},"Maxim","Максим",{"en":776,"ru":777,"es":778,"nl":779},"Senior engineer at Nerdy Production working from backend to screen — Go, Flutter, Python and TypeScript, with the tests written as he goes.","Старший инженер Nerdy Production, работающий от бэкенда до экрана: Go, Flutter, Python и TypeScript — и тесты, которые пишутся по ходу дела.","Ingeniero senior en Nerdy Production, del backend a la pantalla: Go, Flutter, Python y TypeScript, con los tests escritos sobre la marcha.","Senior engineer bij Nerdy Production, van backend tot scherm — Go, Flutter, Python en TypeScript, met de tests die hij onderweg schrijft.","\u002Fteam\u002Fmax.webp",{"en":782,"ru":783,"es":784,"nl":785},"Senior Software Engineer","Старший инженер-программист","Ingeniero de software senior","Senior software engineer","senior",[41,18,51,106,155,13,150],"maxim",{"en":790,"ru":791,"es":792,"nl":793},"Backend and Flutter engineering with a testing focus","Бэкенд и Flutter с фокусом на тестирование","Ingeniería backend y Flutter con foco en testing","Backend- en Flutter-engineering met focus op testen","a-8Kx1i-PQXIGU92_Rimqr3bPEur6ZwMfPKQWr2uk4I",{"id":796,"bio":797,"expertise":802,"extension":663,"links":844,"meta":856,"metaDescription":857,"name":862,"ogDescription":865,"photo":870,"role":871,"seniority":876,"skills":877,"slug":170,"specialization":878,"stem":170,"__hash__":883},"team_members\u002Fnixan.yaml",{"en":798,"ru":799,"es":800,"nl":801},"Ilya founded Nerdy Production and leads its engineering. He has been building software since 2010 and shipping production Flutter since 2018.\n\nBefore that he was CTO of QIWI, one of Russia's largest payment platforms, where he ran roughly 12 engineering teams spanning web products down to card processing, :term{slug=\"pci-dss\"} scope, and contactless payments — including building contactless card payments on Android via :term[Host Card Emulation]{slug=\"host-card-emulation\"} over ISO\u002FIEC 14443, with EMV Contactless (Visa PayWave) on top.\n\nHe was also a principal developer at Yandex, where he worked on Yandex.Auto — taking native Android deep into the vehicle, with heavy CAN-bus integration through a custom CAN shield — and a principal at Evotor, whose point-of-sale devices run on a forked :term{slug=\"aosp\"}, giving him a low-level view of Android most app developers never touch.\n\nToday he leads delivery on the agency's flagship apps — from the chart-heavy fintech UI of [ExtraETF](\u002Fportfolio\u002Fextraetf) to the fully custom design system of [Arcana](\u002Fportfolio\u002Farcana). He writes most of the essays on this blog and maintains the agency's open-source work, including the [dxpdf](\u002Fopen-source\u002Fdxpdf) DOCX-to-PDF engine.\n\nHe works across [Flutter](\u002Ftechnologies\u002Fflutter), native iOS and Android, [Go](\u002Ftechnologies\u002Fgo), [Rust](\u002Ftechnologies\u002Frust), [TypeScript](\u002Ftechnologies\u002Ftypescript), [Kotlin](\u002Ftechnologies\u002Fkotlin), [Kubernetes](\u002Ftechnologies\u002Fkubernetes), and [Docker](\u002Ftechnologies\u002Fdocker), with a focus on app architecture, cross-platform delivery, and building teams that ship.\n","Илья основал Nerdy Production и руководит инженерной командой. Он занимается разработкой с 2010 года и выпускает продакшн-приложения на Flutter с 2018-го.\n\nДо этого он был CTO QIWI — одной из крупнейших платёжных платформ России, — где руководил примерно 12 инженерными командами: от веб-продуктов до карточного процессинга, зоны :term{slug=\"pci-dss\"} и бесконтактных платежей, включая бесконтактную оплату картой на Android через :term[Host Card Emulation]{slug=\"host-card-emulation\"} поверх ISO\u002FIEC 14443, с платёжным протоколом EMV Contactless (Visa PayWave).\n\nОн также был принципал-разработчиком в Яндексе, где работал над Яндекс.Авто, уводя нативный Android глубоко в автомобиль, с серьёзной интеграцией по шине CAN через собственный CAN-шилд, и принципалом в Эвоторе, чьи кассовые устройства работают на форке :term{slug=\"aosp\"}, что дало ему низкоуровневый взгляд на Android, недоступный большинству прикладных разработчиков.\n\nСейчас он ведёт поставку флагманских приложений агентства — от насыщенного графиками финтех-интерфейса [ExtraETF](\u002Fportfolio\u002Fextraetf) до полностью кастомной дизайн-системы [Arcana](\u002Fportfolio\u002Farcana). Он пишет большую часть материалов этого блога и поддерживает open-source агентства, включая движок [dxpdf](\u002Fopen-source\u002Fdxpdf) для конвертации DOCX в PDF.\n\nРаботает с [Flutter](\u002Ftechnologies\u002Fflutter), нативными iOS и Android, [Go](\u002Ftechnologies\u002Fgo), [Rust](\u002Ftechnologies\u002Frust), [TypeScript](\u002Ftechnologies\u002Ftypescript), [Kotlin](\u002Ftechnologies\u002Fkotlin), [Kubernetes](\u002Ftechnologies\u002Fkubernetes) и [Docker](\u002Ftechnologies\u002Fdocker); его фокус — архитектура приложений, кросс-платформенная поставка и построение команд, которые доводят продукт до релиза.\n","Ilya fundó Nerdy Production y dirige su ingeniería. Lleva construyendo software desde 2010 y entregando Flutter en producción desde 2018.\n\nAntes fue CTO de QIWI, una de las mayores plataformas de pago de Rusia, donde dirigió alrededor de 12 equipos de ingeniería que abarcaban desde productos web hasta procesamiento de tarjetas, alcance :term{slug=\"pci-dss\"} y pagos contactless, incluida la construcción de pagos contactless con tarjeta en Android mediante :term[Host Card Emulation]{slug=\"host-card-emulation\"} sobre ISO\u002FIEC 14443, con EMV Contactless (Visa PayWave) por encima.\n\nTambién fue principal developer en Yandex, donde trabajó en Yandex.Auto —llevando Android nativo hasta el interior del vehículo, con una integración intensiva por bus CAN a través de un CAN shield propio— y principal en Evotor, cuyos terminales de punto de venta funcionan sobre un fork de :term{slug=\"aosp\"}, lo que le dio una visión de bajo nivel de Android que la mayoría de desarrolladores de apps nunca llega a tocar.\n\nHoy lidera la entrega de las apps insignia de la agencia, desde la interfaz fintech cargada de gráficos de [ExtraETF](\u002Fportfolio\u002Fextraetf) hasta el sistema de diseño totalmente a medida de [Arcana](\u002Fportfolio\u002Farcana). Escribe la mayoría de los artículos de este blog y mantiene el trabajo de código abierto de la agencia, incluido el motor de conversión de DOCX a PDF [dxpdf](\u002Fopen-source\u002Fdxpdf).\n\nTrabaja con [Flutter](\u002Ftechnologies\u002Fflutter), iOS y Android nativos, [Go](\u002Ftechnologies\u002Fgo), [Rust](\u002Ftechnologies\u002Frust), [TypeScript](\u002Ftechnologies\u002Ftypescript), [Kotlin](\u002Ftechnologies\u002Fkotlin), [Kubernetes](\u002Ftechnologies\u002Fkubernetes) y [Docker](\u002Ftechnologies\u002Fdocker), con foco en arquitectura de aplicaciones, entrega multiplataforma y la construcción de equipos que entregan.\n","Ilya richtte Nerdy Production op en leidt de engineering. Hij bouwt software sinds 2010 en levert sinds 2018 Flutter in productie.\n\nDaarvoor was hij CTO van QIWI, een van de grootste betaalplatforms van Rusland, waar hij zo'n 12 engineeringteams aanstuurde die reikten van webproducten tot kaartverwerking, :term{slug=\"pci-dss\"}-scope en contactloos betalen — waaronder het bouwen van contactloze kaartbetalingen op Android via :term[Host Card Emulation]{slug=\"host-card-emulation\"} over ISO\u002FIEC 14443, met EMV Contactless (Visa PayWave) daarbovenop.\n\nHij was ook principal developer bij Yandex, waar hij aan Yandex.Auto werkte — native Android diep de auto in brengen, met zware integratie over de CAN-bus via een eigen CAN-shield — en principal bij Evotor, waarvan de kassa-apparaten op een fork van :term{slug=\"aosp\"} draaien, wat hem een blik op Android op laag niveau gaf die de meeste app-ontwikkelaars nooit krijgen.\n\nVandaag leidt hij de oplevering van de vlaggenschipapps van het bureau — van de grafiekzware fintech-UI van [ExtraETF](\u002Fportfolio\u002Fextraetf) tot het volledig eigen designsysteem van [Arcana](\u002Fportfolio\u002Farcana). Hij schrijft de meeste artikelen op deze blog en onderhoudt het opensourcewerk van het bureau, waaronder de DOCX-naar-PDF-motor [dxpdf](\u002Fopen-source\u002Fdxpdf).\n\nHij werkt met [Flutter](\u002Ftechnologies\u002Fflutter), native iOS en Android, [Go](\u002Ftechnologies\u002Fgo), [Rust](\u002Ftechnologies\u002Frust), [TypeScript](\u002Ftechnologies\u002Ftypescript), [Kotlin](\u002Ftechnologies\u002Fkotlin), [Kubernetes](\u002Ftechnologies\u002Fkubernetes) en [Docker](\u002Ftechnologies\u002Fdocker), met de nadruk op applicatiearchitectuur, cross-platform oplevering en het bouwen van teams die opleveren.\n",[803,808,813,818,823,828,833,838,840,842],{"en":804,"ru":805,"es":806,"nl":807},"iOS development","Разработка под iOS","Desarrollo iOS","iOS-ontwikkeling",{"en":809,"ru":810,"es":811,"nl":812},"Software architecture","Архитектура ПО","Arquitectura de software","Softwarearchitectuur",{"en":814,"ru":815,"es":816,"nl":817},"Engineering team leadership","Руководство инженерными командами","Liderazgo de equipos de ingeniería","Leidinggeven aan engineeringteams",{"en":819,"ru":820,"es":821,"nl":822},"Payment systems","Платёжные системы","Sistemas de pago","Betaalsystemen",{"en":824,"ru":825,"es":826,"nl":827},"Card processing","Карточный процессинг","Procesamiento de tarjetas","Kaartverwerking",{"en":829,"ru":830,"es":831,"nl":832},"PCI-DSS compliance","Соответствие PCI-DSS","Cumplimiento de PCI-DSS","Naleving van PCI-DSS",{"en":834,"ru":835,"es":836,"nl":837},"NFC and contactless payments","NFC и бесконтактные платежи","NFC y pagos contactless","NFC en contactloos betalen",{"en":839,"ru":839,"es":839,"nl":839},"Host Card Emulation",{"en":841,"ru":841,"es":841,"nl":841},"EMV Contactless",{"en":843,"ru":843,"es":843,"nl":843},"AOSP",[845,848,851,854],{"type":846,"url":847},"github","https:\u002F\u002Fgithub.com\u002Fthenixan",{"type":849,"url":850},"linkedin","https:\u002F\u002Fwww.linkedin.com\u002Fin\u002Fthenixan\u002F",{"type":852,"url":853},"telegram","https:\u002F\u002Ft.me\u002Fthenixan",{"type":666,"address":855},"nixan@nerdy.pro",{},{"en":858,"ru":859,"es":860,"nl":861},"Founder and lead developer at Nerdy Production, former CTO of QIWI. Flutter architecture, payments infrastructure, and engineering teams that ship.","Основатель и ведущий разработчик Nerdy Production, экс-CTO QIWI. Архитектура на Flutter, платёжная инфраструктура и команды, которые доводят до релиза.","Fundador y lead developer en Nerdy Production, ex-CTO de QIWI. Arquitectura Flutter, infraestructura de pagos y equipos de ingeniería que entregan.","Oprichter en lead developer bij Nerdy Production, oud-CTO van QIWI. Flutter-architectuur, betaalinfrastructuur en teams die opleveren.",{"en":863,"ru":864,"es":863,"nl":863},"Ilya Nixan","Илья Никсан",{"en":866,"ru":867,"es":868,"nl":869},"Founder and lead developer at Nerdy Production, former CTO of QIWI — Flutter architecture, payments infrastructure, and teams that ship.","Основатель и ведущий разработчик Nerdy Production, экс-CTO QIWI: архитектура на Flutter, платёжная инфраструктура и команды, которые доводят до релиза.","Fundador y lead developer en Nerdy Production, ex-CTO de QIWI: arquitectura Flutter, infraestructura de pagos y equipos que entregan.","Oprichter en lead developer bij Nerdy Production, oud-CTO van QIWI — Flutter-architectuur, betaalinfrastructuur en teams die opleveren.","\u002Fteam\u002Fnixan.webp",{"en":872,"ru":873,"es":874,"nl":875},"Founder & Lead Developer","Основатель и ведущий разработчик","Fundador y lead developer","Oprichter & lead developer","founder_lead",[41,18,71,141,76,146,51,126,121,155,160,90,13,150,136,7,29,80],{"en":879,"ru":880,"es":881,"nl":882},"Flutter architecture and leading delivery teams","Архитектура на Flutter и руководство командами поставки","Arquitectura Flutter y liderazgo de equipos de entrega","Flutter-architectuur en het leiden van opleverteams","BmeQZ7JyhRFIx8527WO2t1-WklP8AAvevAxiN9U4TEs",{"id":885,"bio":886,"expertise":891,"extension":663,"links":903,"meta":908,"metaDescription":909,"name":914,"ogDescription":917,"photo":922,"role":923,"seniority":786,"skills":928,"slug":929,"specialization":930,"stem":929,"__hash__":935},"team_members\u002Froma.yaml",{"en":887,"ru":888,"es":889,"nl":890},"Roman works across native iOS and Android and [Flutter](\u002Ftechnologies\u002Fflutter), and pairs that mobile depth with [Python](\u002Ftechnologies\u002Fpython) and applied AI.\n\nMuch of his background is in ERP and CRM development — complex, data-heavy business systems where getting the domain model right matters more than the UI — which gives him a pragmatic eye for how an app fits the process behind it.\n","Роман работает с нативными iOS и Android и с [Flutter](\u002Ftechnologies\u002Fflutter), дополняя мобильную экспертизу [Python](\u002Ftechnologies\u002Fpython) и прикладным AI.\n\nЗначительная часть его опыта — разработка ERP и CRM, сложных систем с большим объёмом данных, где правильная доменная модель важнее интерфейса, — что даёт ему прагматичный взгляд на то, как приложение встраивается в процесс за ним.\n","Roman trabaja con iOS y Android nativos y con [Flutter](\u002Ftechnologies\u002Fflutter), y combina esa profundidad móvil con [Python](\u002Ftechnologies\u002Fpython) e IA aplicada.\n\nBuena parte de su trayectoria está en el desarrollo de ERP y CRM —sistemas de negocio complejos y con mucho dato, donde acertar con el modelo de dominio importa más que la interfaz—, lo que le da una mirada pragmática sobre cómo encaja una app en el proceso que hay detrás.\n","Roman werkt met native iOS en Android en met [Flutter](\u002Ftechnologies\u002Fflutter), en combineert die mobiele diepgang met [Python](\u002Ftechnologies\u002Fpython) en toegepaste AI.\n\nEen groot deel van zijn achtergrond ligt in ERP- en CRM-ontwikkeling — complexe, datazware bedrijfssystemen waarin het domeinmodel goed krijgen zwaarder weegt dan de interface — wat hem een pragmatische blik geeft op hoe een app in het proces erachter past.\n",[892,893,898],{"en":804,"ru":805,"es":806,"nl":807},{"en":894,"ru":895,"es":896,"nl":897},"Applied AI","Прикладной AI","IA aplicada","Toegepaste AI",{"en":899,"ru":900,"es":901,"nl":902},"ERP and CRM systems","ERP- и CRM-системы","Sistemas ERP y CRM","ERP- en CRM-systemen",[904,906],{"type":849,"url":905},"https:\u002F\u002Fwww.linkedin.com\u002Fin\u002Fromanbatler\u002F",{"type":666,"address":907},"roma@nerdy.pro",{},{"en":910,"ru":911,"es":912,"nl":913},"Senior mobile developer at Nerdy Production — native iOS and Android, Flutter, applied AI, and a background in data-heavy ERP and CRM systems.","Старший мобильный разработчик Nerdy Production: нативные iOS и Android, Flutter, прикладной AI и опыт в ERP- и CRM-системах.","Desarrollador móvil senior en Nerdy Production: iOS y Android nativos, Flutter, IA aplicada y experiencia en sistemas ERP y CRM con gran volumen de datos.","Senior mobiele developer bij Nerdy Production — native iOS en Android, Flutter, toegepaste AI, en een achtergrond in datazware ERP- en CRM-systemen.",{"en":915,"ru":916,"es":915,"nl":915},"Roman","Рома",{"en":918,"ru":919,"es":920,"nl":921},"Senior mobile developer at Nerdy Production — native iOS and Android, Flutter, applied AI, and years of data-heavy ERP and CRM behind him.","Старший мобильный разработчик Nerdy Production: нативные iOS и Android, Flutter, прикладной AI и годы работы с нагруженными ERP и CRM.","Desarrollador móvil senior en Nerdy Production: iOS y Android nativos, Flutter, IA aplicada y años de ERP y CRM con mucha carga de datos.","Senior mobiele developer bij Nerdy Production — native iOS en Android, Flutter, toegepaste AI, en jaren datazware ERP en CRM achter zich.","\u002Fteam\u002Froma.webp",{"en":924,"ru":925,"es":926,"nl":927},"Senior Mobile Developer","Старший мобильный разработчик","Desarrollador móvil senior","Senior mobiele developer",[7,41,18,141,146,106],"roma",{"en":931,"ru":932,"es":933,"nl":934},"Mobile, AI, and ERP\u002FCRM systems","Мобильная разработка, AI и системы ERP\u002FCRM","Móvil, IA y sistemas ERP\u002FCRM","Mobiel, AI en ERP\u002FCRM-systemen","caPSPO2BX35G9lEjNb6p3U4uF_V7yh8cexCe6l5hm8Y",{"id":937,"bio":938,"expertise":943,"extension":663,"links":715,"meta":954,"metaDescription":955,"name":960,"ogDescription":963,"photo":968,"role":969,"seniority":786,"skills":974,"slug":975,"specialization":976,"stem":975,"__hash__":981},"team_members\u002Fxsox.yaml",{"en":939,"ru":940,"es":941,"nl":942},"Eugene builds the systems that apps depend on. His background is in backend engineering — designing and running the APIs, data models, and services behind a product, primarily in [Python](\u002Ftechnologies\u002Fpython) and [Django](\u002Ftechnologies\u002Fdjango).\n\nHe also works in [Flutter](\u002Ftechnologies\u002Fflutter), so he can reason about a feature from the database to the device and build the backend so the app that consumes it stays simple.\n","Женя строит системы, на которые опираются приложения. Его основной опыт — бэкенд-инженерия: проектирование и эксплуатация API, моделей данных и сервисов за продуктом, в первую очередь на [Python](\u002Ftechnologies\u002Fpython) и [Django](\u002Ftechnologies\u002Fdjango).\n\nОн также работает с [Flutter](\u002Ftechnologies\u002Fflutter), поэтому может рассуждать о фиче от базы данных до устройства и строить бэкенд так, чтобы потребляющее его приложение оставалось простым.\n","Eugene construye los sistemas de los que dependen las apps. Su trayectoria está en la ingeniería backend: diseñar y operar las APIs, los modelos de datos y los servicios que hay detrás de un producto, principalmente en [Python](\u002Ftechnologies\u002Fpython) y [Django](\u002Ftechnologies\u002Fdjango).\n\nTambién trabaja con [Flutter](\u002Ftechnologies\u002Fflutter), así que puede razonar sobre una funcionalidad desde la base de datos hasta el dispositivo y construir el backend de forma que la app que lo consume siga siendo simple.\n","Eugene bouwt de systemen waar apps op leunen. Zijn achtergrond ligt in backend-engineering: de API's, datamodellen en services achter een product ontwerpen en draaien, vooral in [Python](\u002Ftechnologies\u002Fpython) en [Django](\u002Ftechnologies\u002Fdjango).\n\nHij werkt daarnaast met [Flutter](\u002Ftechnologies\u002Fflutter), zodat hij over een functie kan nadenken van de database tot het toestel en de backend zo kan bouwen dat de app die hem verbruikt eenvoudig blijft.\n",[944,949],{"en":945,"ru":946,"es":947,"nl":948},"API design","Проектирование API","Diseño de APIs","API-ontwerp",{"en":950,"ru":951,"es":952,"nl":953},"Data modelling","Моделирование данных","Modelado de datos","Datamodellering",{},{"en":956,"ru":957,"es":958,"nl":959},"Senior backend developer at Nerdy Production building the APIs, data models and services behind our apps, primarily in Python and Django.","Старший бэкенд-разработчик Nerdy Production: API, модели данных и сервисы за нашими приложениями, в первую очередь на Python и Django.","Desarrollador backend senior en Nerdy Production: las APIs, modelos de datos y servicios detrás de nuestras apps, sobre todo en Python y Django.","Senior backenddeveloper bij Nerdy Production die de API's, datamodellen en services achter onze apps bouwt, vooral in Python en Django.",{"en":961,"ru":962,"es":961,"nl":961},"Eugene Xsox","Женя Xsox",{"en":964,"ru":965,"es":966,"nl":967},"Senior backend developer at Nerdy Production — the APIs, data models and services our apps run on, mostly in Python and Django.","Старший бэкенд-разработчик Nerdy Production: API, модели данных и сервисы, на которых работают наши приложения, в основном на Python и Django.","Desarrollador backend senior en Nerdy Production: las APIs, modelos de datos y servicios sobre los que corren nuestras apps, en Python y Django.","Senior backenddeveloper bij Nerdy Production — de API's, datamodellen en services waarop onze apps draaien, vooral in Python en Django.","\u002Fteam\u002Fxsox.webp",{"en":970,"ru":971,"es":972,"nl":973},"Senior Backend Developer","Старший бэкенд-разработчик","Desarrollador backend senior","Senior backenddeveloper",[106,24,41,18,155,160,90,150],"xsox",{"en":977,"ru":978,"es":979,"nl":980},"Python\u002FDjango backends, plus Flutter","Бэкенды на Python\u002FDjango и Flutter","Backends en Python\u002FDjango, además de Flutter","Backends in Python\u002FDjango, plus Flutter","w_QAKKq_Mh_dtMvAxFpAJBC10PW1I7zgVOxELwRHwO8",[983,992,999,1004,1014],{"id":984,"extension":663,"meta":985,"name":986,"slug":990,"stem":990,"__hash__":991},"blog_topics\u002Fcybersecurity.yaml",{},{"en":987,"ru":988,"es":989,"nl":987},"Cybersecurity","Кибербезопасность","Ciberseguridad","cybersecurity","kt1rdsMy5W4b9MvGHm6mZVCr0inHidEuqaosPYmmk4E",{"id":993,"extension":663,"meta":994,"name":995,"slug":997,"stem":997,"__hash__":998},"blog_topics\u002Fdevops.yaml",{},{"en":996,"ru":996,"es":996,"nl":996},"DevOps","devops","D3mxlZuFHKCGeszKZuWCiQmHmP5EiCvzg1qEAIQhnyU",{"id":1000,"extension":663,"meta":1001,"name":1002,"slug":41,"stem":41,"__hash__":1003},"blog_topics\u002Fflutter.yaml",{},{"en":39,"ru":39,"es":39,"nl":39},"OOeALAmwFuEqByuJvTGk4g15FIHENPfYMdpfZh_HTAE",{"id":1005,"extension":663,"meta":1006,"name":1007,"slug":1012,"stem":1012,"__hash__":1013},"blog_topics\u002Ffor-founders.yaml",{},{"en":1008,"ru":1009,"es":1010,"nl":1011},"For Founders","Для основателей","Para fundadores","Voor oprichters","for-founders","lp2u6Ol2qF4DGxpB83HxbbGzWioT-e40mJhD4lr28-U",{"id":1015,"extension":663,"meta":1016,"name":1017,"slug":636,"stem":636,"__hash__":1022},"blog_topics\u002Fsoftware-engineering.yaml",{},{"en":1018,"ru":1019,"es":1020,"nl":1021},"Software Engineering","Разработка ПО","Ingeniería de software","Software-engineering","aZMb3aUDptoFQk_cEE6l5H4wrYcgZuBYUubmKqOAaaU",{"data":1024,"body":1025},{},{"type":1026,"children":1027},"root",[1028,1035,1053,1064,1093],{"type":1029,"tag":175,"props":1030,"children":1031},"element",{},[1032],{"type":1033,"value":1034},"text","Ilya founded Nerdy Production and leads its engineering. He has been building software since 2010 and shipping production Flutter since 2018.",{"type":1029,"tag":175,"props":1036,"children":1037},{},[1038,1040,1044,1046,1051],{"type":1033,"value":1039},"Before that he was CTO of QIWI, one of Russia's largest payment platforms, where he ran roughly 12 engineering teams spanning web products down to card processing, ",{"type":1029,"tag":305,"props":1041,"children":1043},{"slug":1042},"pci-dss",[],{"type":1033,"value":1045}," scope, and contactless payments — including building contactless card payments on Android via ",{"type":1029,"tag":305,"props":1047,"children":1049},{"slug":1048},"host-card-emulation",[1050],{"type":1033,"value":839},{"type":1033,"value":1052}," over ISO\u002FIEC 14443, with EMV Contactless (Visa PayWave) on top.",{"type":1029,"tag":175,"props":1054,"children":1055},{},[1056,1058,1062],{"type":1033,"value":1057},"He was also a principal developer at Yandex, where he worked on Yandex.Auto — taking native Android deep into the vehicle, with heavy CAN-bus integration through a custom CAN shield — and a principal at Evotor, whose point-of-sale devices run on a forked ",{"type":1029,"tag":305,"props":1059,"children":1061},{"slug":1060},"aosp",[],{"type":1033,"value":1063},", giving him a low-level view of Android most app developers never touch.",{"type":1029,"tag":175,"props":1065,"children":1066},{},[1067,1069,1075,1077,1083,1085,1091],{"type":1033,"value":1068},"Today he leads delivery on the agency's flagship apps — from the chart-heavy fintech UI of ",{"type":1029,"tag":225,"props":1070,"children":1072},{"href":1071},"\u002Fportfolio\u002Fextraetf",[1073],{"type":1033,"value":1074},"ExtraETF",{"type":1033,"value":1076}," to the fully custom design system of ",{"type":1029,"tag":225,"props":1078,"children":1080},{"href":1079},"\u002Fportfolio\u002Farcana",[1081],{"type":1033,"value":1082},"Arcana",{"type":1033,"value":1084},". He writes most of the essays on this blog and maintains the agency's open-source work, including the ",{"type":1029,"tag":225,"props":1086,"children":1088},{"href":1087},"\u002Fopen-source\u002Fdxpdf",[1089],{"type":1033,"value":1090},"dxpdf",{"type":1033,"value":1092}," DOCX-to-PDF engine.",{"type":1029,"tag":175,"props":1094,"children":1095},{},[1096,1098,1103,1105,1110,1111,1116,1117,1122,1123,1128,1129,1134,1135,1140],{"type":1033,"value":1097},"He works across ",{"type":1029,"tag":225,"props":1099,"children":1101},{"href":1100},"\u002Ftechnologies\u002Fflutter",[1102],{"type":1033,"value":39},{"type":1033,"value":1104},", native iOS and Android, ",{"type":1029,"tag":225,"props":1106,"children":1108},{"href":1107},"\u002Ftechnologies\u002Fgo",[1109],{"type":1033,"value":49},{"type":1033,"value":190},{"type":1029,"tag":225,"props":1112,"children":1114},{"href":1113},"\u002Ftechnologies\u002Frust",[1115],{"type":1033,"value":124},{"type":1033,"value":190},{"type":1029,"tag":225,"props":1118,"children":1120},{"href":1119},"\u002Ftechnologies\u002Ftypescript",[1121],{"type":1033,"value":153},{"type":1033,"value":190},{"type":1029,"tag":225,"props":1124,"children":1126},{"href":1125},"\u002Ftechnologies\u002Fkotlin",[1127],{"type":1033,"value":69},{"type":1033,"value":190},{"type":1029,"tag":225,"props":1130,"children":1132},{"href":1131},"\u002Ftechnologies\u002Fkubernetes",[1133],{"type":1033,"value":78},{"type":1033,"value":219},{"type":1029,"tag":225,"props":1136,"children":1138},{"href":1137},"\u002Ftechnologies\u002Fdocker",[1139],{"type":1033,"value":27},{"type":1033,"value":1141},", with a focus on app architecture, cross-platform delivery, and building teams that ship.",[1143,1155,1168,1183,1197,1211,1227,1239,1253,1266,1280,1293,1309,1322,1338,1351,1362,1372,1385,1395,1406,1421,1430,1443,1456,1463,1474,1486,1497,1512,1524,1537,1549,1561,1573,1584,1595,1606,1617,1628,1640,1650,1661,1674,1686,1695,1707,1719,1729,1740,1753,1762,1773],{"slug":1060,"term":843,"definition":1144,"category":1145,"aliases":1146,"links":1148,"related":1152,"readMore":-1,"target":1153,"hasArticle":1154},"The Android Open Source Project — Android without the Google layer on top, which anyone may fork. Point-of-sale terminals, kiosks and in-car systems run on forks of it, and working at that level exposes parts of the OS an app developer never sees.","platform",[1147],"Android Open Source Project",[1149],{"kind":1150,"url":1151},"website","https:\u002F\u002Fsource.android.com\u002F",[1048],"\u002Fglossary#aosp",false,{"slug":1156,"term":1157,"definition":1158,"category":1145,"aliases":1159,"links":1160,"related":1164,"readMore":-1,"target":1167,"hasArticle":1154},"app-clips","App Clips","An Apple feature that runs a small slice of an iOS app — under 15 MB — without installing the whole thing. Invoked from a QR code, an NFC tag or a link, for when the first thing a user does should not require a store visit.",[],[1161],{"kind":1162,"url":1163},"documentation","https:\u002F\u002Fdeveloper.apple.com\u002Fapp-clips\u002F",[1165,1166],"deep-linking","install-referrer","\u002Fglossary#app-clips",{"slug":1169,"term":1170,"definition":1171,"category":1145,"aliases":1172,"links":1173,"related":1179,"readMore":-1,"target":1182,"hasArticle":1154},"bigquery","BigQuery","Google Cloud's analytics warehouse. You point SQL at billions of rows and it scans them in seconds, on storage held separately from the machines doing the querying — which is what keeps reporting and exploration off the database that is serving live traffic.",[],[1174,1176],{"kind":1150,"url":1175},"https:\u002F\u002Fcloud.google.com\u002Fbigquery",{"kind":1177,"url":1178},"wikipedia","https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FBigQuery",[1180,1181],"object-storage","elasticsearch","\u002Fglossary#bigquery",{"slug":1184,"term":1185,"definition":1186,"category":1187,"aliases":1188,"links":1192,"related":1195,"readMore":-1,"target":1196,"hasArticle":1154},"ci-cd","CI\u002FCD","Automation that builds, tests and ships every change without anyone running commands by hand. On mobile it is what turns a release into a button press instead of an afternoon of someone else being unavailable.","practice",[1189,1190,1191],"CI","continuous integration","continuous delivery",[1193],{"kind":1177,"url":1194},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FCI\u002FCD",[],"\u002Fglossary#ci-cd",{"slug":1198,"term":1199,"definition":1200,"category":1201,"aliases":1202,"links":1204,"related":1207,"readMore":-1,"target":1210,"hasArticle":1154},"crud","CRUD","Create, read, update, delete — the four operations behind almost every form and admin screen. Shorthand for the routine data-management half of an app, as opposed to the parts carrying real domain logic.","architecture",[1203],"Create, Read, Update, Delete",[1205],{"kind":1177,"url":1206},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FCreate,_read,_update_and_delete",[1208,1209],"rest","graphql","\u002Fglossary#crud",{"slug":1212,"term":1213,"definition":1214,"category":1201,"aliases":1215,"links":1220,"related":1223,"readMore":-1,"target":1226,"hasArticle":1154},"container-registry","Container registry","A hosted store for container images, addressed by name and tag — Docker Hub, GitHub Container Registry, or a cloud provider's own. Pushing a build there turns 'works on my machine' into an image anyone can pull and run unchanged.",[1216,1217,1218,1219],"image registry","Docker registry","GHCR","ghcr.io",[1221],{"kind":1162,"url":1222},"https:\u002F\u002Fdocs.github.com\u002Fen\u002Fpackages\u002Fworking-with-a-github-packages-registry\u002Fworking-with-the-container-registry",[1224,1225],"dev-container","multi-arch-image","\u002Fglossary#container-registry",{"slug":1165,"term":1228,"definition":1229,"category":1145,"aliases":1230,"links":1234,"related":1237,"readMore":1238,"target":1238,"hasArticle":628},"Deep linking","A link that opens a specific screen inside an installed app instead of its home screen or a web page. Deferred deep linking survives an install, so a tap that leads through the app store still lands on the right screen.",[1231,1232,1233],"deferred deep linking","universal links","Android App Links",[1235],{"kind":1177,"url":1236},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FMobile_deep_linking",[1156,1166],"\u002Fglossary\u002Fdeep-linking",{"slug":1224,"term":1240,"definition":1241,"category":1187,"aliases":1242,"links":1246,"related":1251,"readMore":-1,"target":1252,"hasArticle":1154},"Dev Container","A development environment described once in devcontainer.json — the OS, tools, and runtime versions a project needs — and opened identically inside a container by every contributor's editor, instead of a setup guide everyone interprets differently.",[1243,1244,1245],"devcontainer.json","Dev Containers","VS Code Dev Containers",[1247,1249],{"kind":1150,"url":1248},"https:\u002F\u002Fcontainers.dev\u002F",{"kind":1162,"url":1250},"https:\u002F\u002Fcode.visualstudio.com\u002Fdocs\u002Fdevcontainers\u002Fcontainers",[1212],"\u002Fglossary#dev-container",{"slug":1181,"term":1254,"definition":1255,"category":1145,"aliases":1256,"links":1259,"related":1264,"readMore":-1,"target":1265,"hasArticle":1154},"Elasticsearch","A search and analytics engine that indexes records so they can be filtered and searched interactively instead of scanned. What you reach for when the question is \"show me these particular sessions, narrowed six ways\" rather than \"sum this column\".",[1257,1258],"Elastic","ELK",[1260,1262],{"kind":1150,"url":1261},"https:\u002F\u002Fwww.elastic.co\u002Felasticsearch",{"kind":1177,"url":1263},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FElasticsearch",[1169],"\u002Fglossary#elasticsearch",{"slug":1267,"term":1268,"definition":1269,"category":1201,"aliases":1270,"links":1273,"related":1276,"readMore":-1,"target":1279,"hasArticle":1154},"end-to-end-encryption","End-to-end encryption","Encryption applied on the sending device and undone only on the receiving one, so the service carrying the message cannot read it — not under subpoena, not after a breach. It protects the content and never the metadata.",[1271,1272],"E2EE","end-to-end encrypted",[1274],{"kind":1177,"url":1275},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FEnd-to-end_encryption",[1277,1278],"tls","jwt","\u002Fglossary#end-to-end-encryption",{"slug":1281,"term":1282,"definition":1283,"category":1201,"aliases":1284,"links":1287,"related":1288,"readMore":-1,"target":1292,"hasArticle":1154},"fan-out","Fan-out","Reading an upstream source once and delivering each update to every client subscribed to it. The naive version writes to subscribers in a loop and stalls the moment one socket is slow; a real one buffers per client and drops whoever cannot keep up.",[1285,1286],"fanout","broadcast",[],[1289,1290,1291],"websocket","pub-sub","server-sent-events","\u002Fglossary#fan-out",{"slug":1294,"term":1295,"definition":1296,"category":1187,"aliases":1297,"links":1301,"related":1304,"readMore":-1,"target":1308,"hasArticle":1154},"feature-flags","Feature flags","Switches that turn functionality on or off from configuration rather than from a release. They let one binary behave differently per brand, market or user, and let a risky feature be shut off without shipping a new build through review.",[1298,1299,1300],"feature flag","feature toggle","feature gating",[1302],{"kind":1177,"url":1303},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FFeature_toggle",[1305,1306,1307],"staged-rollout","white-label","multi-tenancy","\u002Fglossary#feature-flags",{"slug":1310,"term":1311,"definition":1312,"category":1201,"aliases":1313,"links":1317,"related":1320,"readMore":-1,"target":1321,"hasArticle":1154},"floating-point","Floating point","The IEEE 754 binary format behind double and float. It cannot hold 0.1 exactly, so 0.1 + 0.2 is 0.30000000000000004 — invisible in graphics and fatal in money, which belongs in integer minor units or a decimal type instead.",[1314,1315,1316],"IEEE 754","double","floating-point arithmetic",[1318],{"kind":1177,"url":1319},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FIEEE_754",[],"\u002Fglossary#floating-point",{"slug":1323,"term":1324,"definition":1325,"category":1187,"aliases":1326,"links":1329,"related":1334,"readMore":-1,"target":1337,"hasArticle":1154},"gdpr","GDPR","The EU regulation covering personal data of people in the EU: a lawful basis for collecting it, real consent for tracking, and rights to see and delete it. It follows your users, not your servers, so it applies wherever the company is registered.",[1327,1328],"General Data Protection Regulation","data protection",[1330,1332],{"kind":1150,"url":1331},"https:\u002F\u002Fgdpr.eu\u002F",{"kind":1177,"url":1333},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FGeneral_Data_Protection_Regulation",[1042,1335,1336],"soc-2","hipaa","\u002Fglossary#gdpr",{"slug":1339,"term":1340,"definition":1341,"category":1187,"aliases":1342,"links":1346,"related":1349,"readMore":-1,"target":1350,"hasArticle":1154},"golden-test","Golden test","A test that renders a widget and compares the result pixel for pixel against a stored reference image. In Flutter it is the cheapest way to answer whether a redesign broke the empty state at 320pt, in dark mode, at 200% text scale.",[1343,1344,1345],"golden tests","screenshot test","snapshot test",[1347],{"kind":1162,"url":1348},"https:\u002F\u002Fapi.flutter.dev\u002Fflutter\u002Fflutter_test\u002FmatchesGoldenFile.html",[1184],"\u002Fglossary#golden-test",{"slug":1209,"term":1352,"definition":1353,"category":1201,"aliases":1354,"links":1355,"related":1360,"readMore":-1,"target":1361,"hasArticle":1154},"GraphQL","A query language for APIs where the client names exactly the fields it wants and gets one response shaped to match. It removes the over-fetching REST endpoints drift into, and adds a failure mode of its own: an unbounded query that walks the whole data model.",[],[1356,1358],{"kind":1150,"url":1357},"https:\u002F\u002Fgraphql.org\u002F",{"kind":1177,"url":1359},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FGraphQL",[1208],"\u002Fglossary#graphql",{"slug":1336,"term":1363,"definition":1364,"category":1187,"aliases":1365,"links":1367,"related":1370,"readMore":-1,"target":1371,"hasArticle":1154},"HIPAA","The US law governing protected health information — how it may be stored, transmitted, logged and disclosed. Like PCI-DSS it is an architectural constraint chosen at the start, not a policy document added before launch.",[1366],"Health Insurance Portability and Accountability Act",[1368],{"kind":1177,"url":1369},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FHealth_Insurance_Portability_and_Accountability_Act",[1042,1323,1335],"\u002Fglossary#hipaa",{"slug":1373,"term":1374,"definition":1375,"category":1201,"aliases":1376,"links":1379,"related":1382,"readMore":-1,"target":1384,"hasArticle":1154},"headless-cms","Headless CMS","A content system with an editor and an API but no front end of its own. Editors publish in one place, and the site or app renders that content itself — so the presentation layer is yours rather than the CMS vendor's.",[1377,1378],"headless content management system","content API",[1380],{"kind":1177,"url":1381},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FHeadless_content_management_system",[1383,1208],"server-side-rendering","\u002Fglossary#headless-cms",{"slug":1048,"term":839,"definition":1386,"category":1145,"aliases":1387,"links":1390,"related":1393,"readMore":-1,"target":1394,"hasArticle":1154},"Letting an Android phone act as a contactless card over NFC in software, with no hardware secure element. It is how a wallet app pays at a terminal: the phone speaks the same EMV contactless protocol the plastic card would have.",[1388,841,1389],"HCE","contactless payments",[1391],{"kind":1162,"url":1392},"https:\u002F\u002Fdeveloper.android.com\u002Fdevelop\u002Fconnectivity\u002Fnfc\u002Fhce",[1042,1060],"\u002Fglossary#host-card-emulation",{"slug":1396,"term":1397,"definition":1398,"category":1145,"aliases":1399,"links":1400,"related":1403,"readMore":-1,"target":1405,"hasArticle":1154},"impeller","Impeller","The rendering engine Flutter uses today, default on iOS since 2023 and on Android since 2024. It compiles its shaders ahead of time instead of during the first animation, which removed the shader-compilation jank that was Flutter's most visible production problem.",[],[1401],{"kind":1162,"url":1402},"https:\u002F\u002Fdocs.flutter.dev\u002Fperf\u002Fimpeller",[1404],"skia","\u002Fglossary#impeller",{"slug":1407,"term":1408,"definition":1409,"category":1410,"aliases":1411,"links":1415,"related":1418,"readMore":-1,"target":1420,"hasArticle":1154},"in-app-purchase","In-app purchase","Selling digital goods or a subscription through the Apple or Google billing that both stores require for digital content and take a commission on. The hard part is never the purchase; it is restoring it on a new device and keeping entitlement state honest.","business",[1412,1413,1414],"IAP","in-app purchases","in-app subscription",[1416],{"kind":1162,"url":1417},"https:\u002F\u002Fdeveloper.apple.com\u002Fin-app-purchase\u002F",[1419],"product-market-fit","\u002Fglossary#in-app-purchase",{"slug":1166,"term":1422,"definition":1423,"category":1145,"aliases":1424,"links":1425,"related":1428,"readMore":-1,"target":1429,"hasArticle":1154},"Install Referrer","A Google Play API that hands a freshly installed Android app the campaign parameters from the link that led to the install. The Android half of deferred deep linking, and the dependable way to attribute where a user came from.",[],[1426],{"kind":1162,"url":1427},"https:\u002F\u002Fdeveloper.android.com\u002Fgoogle\u002Fplay\u002Finstallreferrer",[1165,1156],"\u002Fglossary#install-referrer",{"slug":1278,"term":1431,"definition":1432,"category":1433,"aliases":1434,"links":1436,"related":1441,"readMore":-1,"target":1442,"hasArticle":1154},"JWT","A signed token carrying its own claims, so a server can tell who a request belongs to without looking a session up. Standard for mobile authentication. The signature proves it was not altered; it does not hide what is inside.","protocol",[1435],"JSON Web Token",[1437,1439],{"kind":1150,"url":1438},"https:\u002F\u002Fjwt.io\u002F",{"kind":1177,"url":1440},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FJSON_Web_Token",[1042],"\u002Fglossary#jwt",{"slug":1444,"term":1445,"definition":1446,"category":1187,"aliases":1447,"links":1451,"related":1454,"readMore":-1,"target":1455,"hasArticle":1154},"kyc","KYC","Know Your Customer — the identity checks a regulated financial product runs before it lets anyone move money: document capture, liveness, sanctions and anti-money-laundering screening. It shapes onboarding more than any design decision does.",[1448,1449,1450],"Know Your Customer","AML","KYC\u002FAML",[1452],{"kind":1177,"url":1453},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FKnow_your_customer",[1042,1323],"\u002Fglossary#kyc",{"slug":76,"term":74,"definition":1457,"category":1145,"aliases":1458,"links":1460,"related":1461,"readMore":1462,"target":1462,"hasArticle":1154},"Sharing business logic written in Kotlin across Android, iOS and the server while each platform keeps its own native UI. The alternative to Flutter when the interface has to be native but the rules behind it do not.",[1459],"KMP",[],[],"\u002Ftechnologies\u002Fkmp",{"slug":1464,"term":1465,"definition":1466,"category":1410,"aliases":1467,"links":1469,"related":1472,"readMore":-1,"target":1473,"hasArticle":1154},"mvp","MVP","The smallest version of a product that can go in front of real users and still answer the question you built it to answer. A decision about scope, not about quality — an MVP still has to work.",[1468],"minimum viable product",[1470],{"kind":1177,"url":1471},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FMinimum_viable_product",[1306],"\u002Fglossary#mvp",{"slug":1225,"term":1475,"definition":1476,"category":1201,"aliases":1477,"links":1481,"related":1484,"readMore":-1,"target":1485,"hasArticle":1154},"Multi-architecture image","A single image tag that resolves to different binaries per CPU architecture — linux\u002Famd64 and linux\u002Farm64 are the common pair — so the same docker pull works unchanged on Intel\u002FAMD servers and Apple Silicon laptops.",[1478,1479,1480],"multi-arch build","multi-platform image","linux\u002Famd64 + linux\u002Farm64",[1482],{"kind":1162,"url":1483},"https:\u002F\u002Fdocs.docker.com\u002Fbuild\u002Fbuilding\u002Fmulti-platform\u002F",[1212],"\u002Fglossary#multi-arch-image",{"slug":1307,"term":1487,"definition":1488,"category":1201,"aliases":1489,"links":1492,"related":1495,"readMore":-1,"target":1496,"hasArticle":1154},"Multi-tenancy","One deployment serving many customers, each seeing only its own data, configuration and enabled features because tenant context is resolved per request. It is what makes a fleet of branded apps one product instead of many forks.",[1490,1491],"multi-tenant","tenant",[1493],{"kind":1177,"url":1494},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FMultitenancy",[1306,1294],"\u002Fglossary#multi-tenancy",{"slug":1498,"term":1499,"definition":1500,"category":1433,"aliases":1501,"links":1505,"related":1510,"readMore":-1,"target":1511,"hasArticle":1154},"oauth","OAuth","The standard behind Sign in with Apple, Google and the rest: the user authorises your app at a provider they already trust, and your app receives a token instead of their password. Nobody invents a new credential and you never store one.",[1502,1503,1504],"OAuth 2.0","social login","Sign in with Apple",[1506,1508],{"kind":1150,"url":1507},"https:\u002F\u002Foauth.net\u002F2\u002F",{"kind":1177,"url":1509},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FOAuth",[1278],"\u002Fglossary#oauth",{"slug":1180,"term":1513,"definition":1514,"category":1201,"aliases":1515,"links":1519,"related":1522,"readMore":-1,"target":1523,"hasArticle":1154},"Object storage","Storage that holds a whole file under a key rather than in a filesystem tree — Amazon S3 and the many services that speak its API. Cheap, effectively unlimited, and the usual home for raw events, backups and media: written once, read rarely, kept forever.",[1516,1517,1518],"S3","S3-compatible storage","blob storage",[1520],{"kind":1177,"url":1521},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FObject_storage",[1169],"\u002Fglossary#object-storage",{"slug":1042,"term":1525,"definition":1526,"category":1187,"aliases":1527,"links":1530,"related":1535,"readMore":-1,"target":1536,"hasArticle":1154},"PCI-DSS","The card industry security standard binding anyone who stores, processes or transmits card data. Most apps stay out of its scope on purpose, by handing card entry to a certified payment provider instead.",[1528,1529],"PCI DSS","Payment Card Industry Data Security Standard",[1531,1533],{"kind":1150,"url":1532},"https:\u002F\u002Fwww.pcisecuritystandards.org\u002F",{"kind":1177,"url":1534},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FPayment_Card_Industry_Data_Security_Standard",[1278],"\u002Fglossary#pci-dss",{"slug":1538,"term":1539,"definition":1540,"category":1145,"aliases":1541,"links":1544,"related":1547,"readMore":-1,"target":1548,"hasArticle":1154},"platform-channels","Platform channels","The bridge a Flutter app uses to call native iOS and Android code — Keychain and Keystore, biometrics, payment sheets, any SDK without a Dart package. Routine work but real work, and the first place an engineer who never left Dart will stall.",[1542,1543],"platform channel","method channel",[1545],{"kind":1162,"url":1546},"https:\u002F\u002Fdocs.flutter.dev\u002Fplatform-integration\u002Fplatform-channels",[76],"\u002Fglossary#platform-channels",{"slug":1550,"term":1551,"definition":1552,"category":1433,"aliases":1553,"links":1556,"related":1559,"readMore":-1,"target":1560,"hasArticle":1154},"post-quantum-cryptography","Post-quantum cryptography","Encryption algorithms built to stay secure against a future quantum computer, now standardized by NIST. The migration is urgent ahead of the hardware because traffic captured today can be decrypted once such a machine exists.",[1554,1555],"PQC","post-quantum crypto",[1557],{"kind":1177,"url":1558},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FPost-quantum_cryptography",[1277,1267],"\u002Fglossary#post-quantum-cryptography",{"slug":1419,"term":1562,"definition":1563,"category":1410,"aliases":1564,"links":1567,"related":1570,"readMore":-1,"target":1572,"hasArticle":1154},"Product-market fit","The point at which a product has demonstrably found people who want it — they use it, come back, and pay. Before it, engineering answers a question; after it, engineering answers demand.",[1565,1566],"PMF","product\u002Fmarket fit",[1568],{"kind":1177,"url":1569},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FProduct-market_fit",[1464,1571],"time-to-market","\u002Fglossary#product-market-fit",{"slug":307,"term":1574,"definition":1575,"category":1187,"aliases":1576,"links":1578,"related":1581,"readMore":-1,"target":1583,"hasArticle":1154},"Prompt injection","An attack where text supplied by a user is read by a language model as instructions rather than as data, steering it past its own rules. The LLM-era sibling of SQL injection, and it appears wherever user input is concatenated into a prompt.",[1577],"injection attack",[1579],{"kind":1177,"url":1580},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FPrompt_injection",[1582],"rate-limiting","\u002Fglossary#prompt-injection",{"slug":1290,"term":1585,"definition":1586,"category":1201,"aliases":1587,"links":1590,"related":1593,"readMore":-1,"target":1594,"hasArticle":1154},"Pub\u002FSub","A messaging pattern where a producer publishes an event and any number of consumers read it independently, with a broker in between. The producer never waits for them, which is how a request path stays fast while slower work happens behind it.",[1588,1589],"publish\u002Fsubscribe","Google Cloud Pub\u002FSub",[1591],{"kind":1177,"url":1592},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FPublish%E2%80%93subscribe_pattern",[],"\u002Fglossary#pub-sub",{"slug":1208,"term":1596,"definition":1597,"category":1201,"aliases":1598,"links":1601,"related":1604,"readMore":-1,"target":1605,"hasArticle":1154},"REST","The conventional style for HTTP APIs: a URL names a resource and the HTTP verb says what to do with it. The default way an app talks to a backend, and what most third-party integrations expect to find.",[1599,1600],"REST API","Representational State Transfer",[1602],{"kind":1177,"url":1603},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FREST",[1289,1291],"\u002Fglossary#rest",{"slug":1582,"term":1607,"definition":1608,"category":1187,"aliases":1609,"links":1612,"related":1615,"readMore":-1,"target":1616,"hasArticle":1154},"Rate limiting","A cap on how many requests one caller may make in a given window. It is what stops a single enthusiastic user, a scraper or a bot from spending a month of paid API budget in an afternoon, and it has to live on your side of the integration.",[1610,1611],"rate limit","throttling",[1613],{"kind":1177,"url":1614},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FRate_limiting",[307],"\u002Fglossary#rate-limiting",{"slug":1335,"term":1618,"definition":1619,"category":1187,"aliases":1620,"links":1623,"related":1626,"readMore":-1,"target":1627,"hasArticle":1154},"SOC 2","An external auditor report on how an organisation handles customer data — security, availability, confidentiality — rather than a certificate you buy. Enterprise buyers ask for it, and it constrains architecture long before the audit itself does.",[1621,1622],"SOC2","System and Organization Controls",[1624],{"kind":1177,"url":1625},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FSystem_and_Organization_Controls",[1042,1323,1336],"\u002Fglossary#soc-2",{"slug":1629,"term":1630,"definition":1631,"category":1410,"aliases":1632,"links":1635,"related":1638,"readMore":-1,"target":1639,"hasArticle":1154},"saas","SaaS","Software sold as an ongoing subscription to a hosted product rather than as a one-off license the customer installs and runs. The vendor operates the servers, ships updates continuously, and bills per seat or per usage.",[1633,1634],"Software as a Service","software-as-a-service",[1636],{"kind":1177,"url":1637},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FSoftware_as_a_service",[1307,1306],"\u002Fglossary#saas",{"slug":1291,"term":1641,"definition":1642,"category":1433,"aliases":1643,"links":1645,"related":1648,"readMore":-1,"target":1649,"hasArticle":1154},"Server-Sent Events","A one-way stream from server to client over an ordinary HTTP connection. Simpler than a WebSocket and enough wherever only the server has something to say — a progress feed, an AI response arriving token by token.",[1644],"SSE",[1646],{"kind":1177,"url":1647},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FServer-sent_events",[1289,1208],"\u002Fglossary#server-sent-events",{"slug":1383,"term":1651,"definition":1652,"category":1201,"aliases":1653,"links":1656,"related":1659,"readMore":-1,"target":1660,"hasArticle":1154},"Server-side rendering","Building a page as finished HTML on the server, so the first response already carries the content, headings, meta tags and structured data. Crawlers, link previews and slow devices read it without running JavaScript.",[1654,1655],"SSR","server-rendered",[1657],{"kind":1177,"url":1658},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FServer-side_scripting",[1373],"\u002Fglossary#server-side-rendering",{"slug":1404,"term":1662,"definition":1663,"category":1145,"aliases":1664,"links":1667,"related":1672,"readMore":-1,"target":1673,"hasArticle":1154},"Skia","The open-source 2D graphics library from Google that draws Chrome, Android and — until Impeller — every Flutter frame. It renders to PDF as well as to a screen, which is what print-to-PDF in Chrome is doing.",[1665,1666],"Skia Graphics Engine","skia-safe",[1668,1670],{"kind":1150,"url":1669},"https:\u002F\u002Fskia.org\u002F",{"kind":1177,"url":1671},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FSkia_Graphics_Engine",[1396],"\u002Fglossary#skia",{"slug":1675,"term":1676,"definition":1677,"category":1410,"aliases":1678,"links":1682,"related":1683,"readMore":-1,"target":1685,"hasArticle":1154},"staff-augmentation","Staff augmentation","A hiring model where engineers from an outside partner join your team and work under your management — in your repository, your sprints, your process — instead of delivering a project of their own. You buy capacity; the code and the context stay with you.",[1679,1680,1681],"team augmentation","dedicated developers","outstaffing",[],[1684,1571],"total-cost-of-ownership","\u002Fglossary#staff-augmentation",{"slug":1305,"term":1687,"definition":1688,"category":1187,"aliases":1689,"links":1692,"related":1693,"readMore":-1,"target":1694,"hasArticle":1154},"Staged rollout","Releasing a build to a small percentage of users first and widening only once the crash-free rate holds. A bad build caught at ten percent is a bad afternoon; the same build at a hundred percent is a bad week.",[1690,1691],"phased release","canary release",[],[1294,1184],"\u002Fglossary#staged-rollout",{"slug":1696,"term":649,"definition":1697,"category":1201,"aliases":1698,"links":1702,"related":1705,"readMore":-1,"target":1706,"hasArticle":1154},"state-management","How an app decides where a value lives, who is allowed to change it, and which parts of the screen redraw when it does. In Flutter the choice between Riverpod, BLoC and Provider is among the first architectural decisions and the hardest to revisit.",[1699,1700,1701],"state management","BLoC","Riverpod",[1703],{"kind":1162,"url":1704},"https:\u002F\u002Fdocs.flutter.dev\u002Fdata-and-backend\u002Fstate-mgmt\u002Foptions",[1339],"\u002Fglossary#state-management",{"slug":1277,"term":1708,"definition":1709,"category":1433,"aliases":1710,"links":1714,"related":1717,"readMore":-1,"target":1718,"hasArticle":1154},"TLS","The encryption layer underneath HTTPS. It proves the server is who its certificate says, agrees a fresh key for the session, and encrypts everything after that — so the network in between sees ciphertext it cannot quietly alter.",[1711,1712,1713],"SSL","HTTPS","Transport Layer Security",[1715],{"kind":1177,"url":1716},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FTransport_Layer_Security",[1267,1278],"\u002Fglossary#tls",{"slug":1571,"term":1720,"definition":1721,"category":1410,"aliases":1722,"links":1724,"related":1727,"readMore":-1,"target":1728,"hasArticle":1154},"Time to market","How long it takes to get a product from decision to real users. Most stack and scope arguments are really arguments about this number, because every week saved is a week of revenue, feedback and competitive position.",[1723,1571],"TTM",[1725],{"kind":1177,"url":1726},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FTime_to_market",[1464,1684],"\u002Fglossary#time-to-market",{"slug":1684,"term":1730,"definition":1731,"category":1410,"aliases":1732,"links":1735,"related":1738,"readMore":-1,"target":1739,"hasArticle":1154},"Total cost of ownership","What a product costs across its whole life rather than to build once: maintenance, upgrades, annual OS and store migrations, and the second team you staff to keep two codebases in step. Usually larger than the build quote, and almost never inside it.",[1733,1734],"TCO","cost of ownership",[1736],{"kind":1177,"url":1737},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FTotal_cost_of_ownership",[1571],"\u002Fglossary#total-cost-of-ownership",{"slug":1741,"term":657,"definition":1742,"category":1433,"aliases":1743,"links":1745,"related":1750,"readMore":-1,"target":1752,"hasArticle":1154},"webrtc","The browser and mobile standard for sending audio, video and data directly between two devices, with servers involved only in introducing them to each other. It is what an in-app video call is built on when it is not a rented SDK.",[1744],"Web Real-Time Communication",[1746,1748],{"kind":1150,"url":1747},"https:\u002F\u002Fwebrtc.org\u002F",{"kind":1177,"url":1749},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FWebRTC",[1751,1289],"xmpp","\u002Fglossary#webrtc",{"slug":1289,"term":1754,"definition":1755,"category":1433,"aliases":1756,"links":1757,"related":1760,"readMore":-1,"target":1761,"hasArticle":1154},"WebSocket","A protocol that holds one connection open between client and server so either side can send at any moment, instead of the client asking over and over. What live prices, chat and presence indicators run on.",[],[1758],{"kind":1177,"url":1759},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FWebSocket",[1291,1208],"\u002Fglossary#websocket",{"slug":1306,"term":1763,"definition":1764,"category":1410,"aliases":1765,"links":1768,"related":1771,"readMore":1772,"target":1772,"hasArticle":628},"White-label","One product shipped under many brands. A white-label mobile platform builds each client a store-ready app with its own name, design and content from a single shared codebase, instead of forking the project per customer.",[1766,1767],"white label","multi-tenant app",[1769],{"kind":1177,"url":1770},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FWhite-label_product",[1464],"\u002Fglossary\u002Fwhite-label",{"slug":1751,"term":1774,"definition":1775,"category":1433,"aliases":1776,"links":1779,"related":1784,"readMore":-1,"target":1785,"hasArticle":1154},"XMPP","An open, federated messaging protocol, and the long-standing alternative to writing a chat backend or renting one. It extends to presence, typing indicators and file transfer, and it is old enough that every platform has a mature client library.",[1777,1778],"Jabber","Extensible Messaging and Presence Protocol",[1780,1782],{"kind":1150,"url":1781},"https:\u002F\u002Fxmpp.org\u002F",{"kind":1177,"url":1783},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FXMPP",[1741,1289],"\u002Fglossary#xmpp"]