[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"technologies":3,"\u002Fservices\u002Fai-code-audit":167,"service-parent:\u002Fservices\u002Fai-code-audit":590,"service-children:\u002Fservices\u002Fai-code-audit":597,"glossary":598},[4,10,15,21,26,32,38,43,48,53,58,63,68,73,77,82,87,92,97,103,108,113,118,123,128,133,138,143,147,152,157,162],{"title":5,"description":6,"slug":7,"category":8,"icon":9},"Android","Every app we ship reaches Android — platform APIs, background execution, permissions, and the store requirements that come with them.","android","framework","logos:android-icon",{"title":11,"description":12,"slug":13,"category":8,"icon":14},"Angular","The front-end framework we work in when a product is already Angular — a batteries-included structure that suits large, long-lived apps.","angular","logos:angular-icon",{"title":16,"description":17,"slug":18,"category":19,"icon":20},"Dart","The language every Flutter app we ship is written in — sound null safety, real pattern matching, and a compiler that targets native and the web.","dart","language","logos:dart",{"title":22,"description":23,"slug":24,"category":8,"icon":25},"Django","The Python framework we use when a product needs an admin, auth and a real data model on day one rather than a hand-rolled service.","django","logos:django-icon",{"title":27,"description":28,"slug":29,"category":30,"icon":31},"Docker","Every service we build ships as a container, so what runs on a laptop, in CI and in production is one artefact rather than three of them.","docker","infrastructure","logos:docker-icon",{"title":33,"description":34,"slug":35,"category":36,"icon":37},"Fastlane","The release automation behind our mobile work — signing, builds and store uploads run from CI instead of from one engineer's laptop on release day.","fastlane","tools","logos:fastlane",{"title":39,"description":40,"slug":41,"category":8,"icon":42},"Flutter","Our primary mobile stack since 2018 — one Dart codebase shipping to iOS, Android, web and desktop without a separate team per platform.","flutter","logos:flutter",{"title":44,"description":45,"slug":46,"category":36,"icon":47},"Git","Every project we touch lives in Git — reviewed pull requests, CI on every branch, and a history that still makes sense months later.","git","logos:git-icon",{"title":49,"description":50,"slug":51,"category":19,"icon":52},"Go","Our backend language for real-time APIs and services under load — small binaries, fast builds, and concurrency that stays readable.","go","logos:gopher",{"title":54,"description":55,"slug":56,"category":30,"icon":57},"Google Cloud","The cloud our production workloads run on — managed Kubernetes, storage and networking, without hand-built servers nobody wants to maintain.","gcp","logos:google-cloud",{"title":59,"description":60,"slug":61,"category":36,"icon":62},"Gradle","The build system every Android release goes through — product flavours, signing configs, and the dependency wiring under a Flutter app.","gradle","logos:gradle",{"title":64,"description":65,"slug":66,"category":30,"icon":67},"Helm","How we package a Kubernetes deployment — service, config, secrets and ingress as one versioned unit that can be promoted and rolled back.","helm","logos:helm",{"title":69,"description":70,"slug":71,"category":19,"icon":72},"Kotlin","What we reach for when a Flutter app needs real Android underneath it — platform channels, background work, and native SDK integrations.","kotlin","logos:kotlin-icon",{"title":74,"description":75,"slug":76,"category":8,"icon":72},"Kotlin Multiplatform","Sharing business logic across iOS and Android while each platform keeps its own native UI — the alternative when Flutter is not the right fit.","kmp",{"title":78,"description":79,"slug":80,"category":30,"icon":81},"Kubernetes","How we run services in production — Helm-packaged deployments, rollouts that can be rolled back, and scaling that does not need a person at 3am.","kubernetes","logos:kubernetes",{"title":83,"description":84,"slug":85,"category":30,"icon":86},"NATS","Lightweight messaging between services — publish\u002Fsubscribe and request\u002Freply without the operational weight of a full broker cluster.","nats","logos:nats-icon",{"title":88,"description":89,"slug":90,"category":8,"icon":91},"Nuxt","Vue with server rendering, routing and SEO handled — how we build marketing sites and web apps that must be fast and indexable on first load.","nuxt","logos:nuxt-icon",{"title":93,"description":94,"slug":95,"category":19,"icon":96},"PHP","Where we work with an existing PHP backend — extending it, integrating with it, and building the mobile and web clients it has to serve.","php","logos:php",{"title":98,"description":99,"slug":100,"category":101,"icon":102},"PostgreSQL","Our default database — the one we reach for unless a product gives us a specific reason not to, from schema design through to index tuning.","postgres","database","logos:postgresql",{"title":104,"description":105,"slug":106,"category":19,"icon":107},"Python","Our language for backends, data work and AI integrations — including the Python bindings we ship for our own Rust tooling.","python","logos:python",{"title":109,"description":110,"slug":111,"category":8,"icon":112},"React","The front-end library we work in when a product is already React — components, hooks, and the ecosystem that has grown around them.","react","logos:react",{"title":114,"description":115,"slug":116,"category":101,"icon":117},"Redis","Where we put data that has to be fast and can be rebuilt — caches, sessions, rate limits, and the queues behind a product's slow paths.","redis","logos:redis",{"title":119,"description":120,"slug":121,"category":19,"icon":122},"Ruby","The language our mobile release automation is written in — Fastlane lanes, custom actions, and the CI glue that ships builds to the stores.","ruby","logos:ruby",{"title":124,"description":125,"slug":126,"category":19,"icon":127},"Rust","Where we go when performance and correctness both matter — document rendering, CLI tooling, and services that have to stay fast and predictable.","rust","simple-icons:rust",{"title":129,"description":130,"slug":131,"category":101,"icon":132},"SQLite","The database that ships inside the app — local caches, offline-first storage, and anything that still has to work with no network.","sqlite","logos:sqlite",{"title":134,"description":135,"slug":136,"category":8,"icon":137},"Strapi","A headless CMS we reach for when editors need to own the content — a real admin and a clean API, without building either from scratch.","strapi","logos:strapi-icon",{"title":139,"description":140,"slug":141,"category":19,"icon":142},"Swift","What we reach for when a Flutter app needs real iOS underneath it — platform channels, native SDK integrations, widgets and App Clips.","swift","logos:swift",{"title":144,"description":145,"slug":146,"category":8,"icon":142},"SwiftUI","Apple's UI framework, where we build the native surfaces a Flutter app cannot own — widgets, App Clips, extensions and system integrations.","swiftui",{"title":148,"description":149,"slug":150,"category":8,"icon":151},"Tailwind CSS","How we style every front end we build — utility classes and design tokens instead of a stylesheet that only ever grows and is never deleted.","tailwind","logos:tailwindcss-icon",{"title":153,"description":154,"slug":155,"category":19,"icon":156},"TypeScript","The default for everything we write for the browser and for Node services — types that catch integration bugs before they reach a review.","typescript","logos:typescript-icon",{"title":158,"description":159,"slug":160,"category":8,"icon":161},"Vue","Our front-end framework for admin panels, merchant dashboards and product web apps that have to stay maintainable for years, not sprints.","vue","logos:vue",{"title":163,"description":164,"slug":165,"category":36,"icon":166},"Whisper","OpenAI's open-source speech recognition model — the transcription engine behind voice input, running as both a backend service and on-device in the app.","whisper","simple-icons:openai",{"id":168,"title":169,"body":170,"description":561,"extension":562,"footerCta":563,"headingCta":577,"image":582,"meta":585,"metaDescription":586,"metaTitle":587,"navigation":588,"ogDescription":589,"parent":590,"path":591,"seo":592,"slug":593,"stem":594,"updated":595,"__hash__":596},"services_en\u002Fservices\u002Fai-code-audit.md","AI Code Audit",{"type":171,"value":172,"toc":542},"minimark",[173,177,180,185,188,193,197,200,204,218,222,225,230,238,242,245,249,252,256,285,289,296,299,305,308,314,323,329,341,345,350,353,358,366,371,374,378,383,386,391,398,403,406,412,416,432,438,442,445,450,453,458,461,466,469,474,477,483,491,495,498,504,513,517,520,524,531,535,538],[174,175,176],"p",{},"An AI code audit is an independent review of a codebase — AI-generated or hand-written — that checks it for security vulnerabilities, architectural weaknesses, and production-readiness gaps before real users find them. It ends with a severity-ranked findings report and a clear path to fix what it finds.",[174,178,179],{},"Most of what we audit today started in Cursor, Bolt, Lovable, Claude, or ChatGPT — fast to prototype, rarely production-ready on day one. But the audit itself is not limited to AI output: the same categories of risk, and the same process, apply to a codebase nobody used AI to write. Whether you're a team shipping fast with AI tools and want a check before the next release, or a founder who inherited an AI-built app and needs to know what's actually in it, you get the same audit.",[181,182,184],"h2",{"id":183},"what-we-audit","What We Audit",[174,186,187],{},"Seven categories, every time — not just the security scan most \"AI code review\" tools stop at.",[189,190],"features",{":items":191,":title":192},"[{\"label\": \"Security\", \"description\": \"OWASP Top 10 vulnerabilities, injection attacks, authentication bypass, exposed secrets, and insecure data storage.\"}, {\"label\": \"Architecture\", \"description\": \"Service boundaries, data flow, and coupling — whether the design holds up under real users and real load.\"}, {\"label\": \"Performance\", \"description\": \"Database queries, N+1 problems, memory leaks, and capacity under production traffic.\"}, {\"label\": \"Correctness\", \"description\": \"Business logic, edge cases, and the bugs that only surface once real data hits the system.\"}, {\"label\": \"Dependencies\", \"description\": \"Outdated packages, known CVEs, and licensing risk sitting in the dependency tree.\"}, {\"label\": \"Test Coverage\", \"description\": \"What is tested, what is not, and what breaks silently the next time it changes.\"}, {\"label\": \"AI-Generated-Code Smells\", \"description\": \"Duplicated logic, hallucinated APIs, and the inconsistent patterns an unsupervised agent leaves behind.\"}]","What Every Audit Covers",[181,194,196],{"id":195},"what-you-get","What You Get",[174,198,199],{},"An audit is not a PDF that sits in a drawer. Three things come out of it.",[189,201],{":items":202,":title":203},"[{\"label\": \"Findings Report\", \"description\": \"Every issue ranked by severity — critical, high, medium, low — with a plain-language risk explanation and a specific fix.\"}, {\"label\": \"Sample Audit Report\", \"description\": \"A redacted example of a real audit, so you see exactly what you are paying for before you send us any code.\"}, {\"label\": \"Remediation Call\", \"description\": \"A walkthrough of every finding with our engineers, and a straight answer on what to fix first.\"}]","The Audit Deliverable",[205,206,209],"info-box",{":leading-icon":207,":title":208},"lucide:file-text","See a Sample Before You Commit",[174,210,211,212,217],{},"Want to see what a real finding looks like — severity, risk explanation, fix — before you send us your code? ",[213,214,216],"a",{"href":215},"\u002Fcontact?intent=ai-code-audit","Request a redacted sample audit report"," and we'll send one over.",[181,219,221],{"id":220},"two-ways-to-start","Two Ways to Start",[174,223,224],{},"People come to us for an audit for one of two reasons. The findings report looks the same either way — what differs is where we start looking.",[226,227,229],"h3",{"id":228},"auditing-an-ai-generated-or-vibe-coded-app","Auditing an AI-Generated or Vibe-Coded App",[174,231,232,233,237],{},"You (or a non-technical founder, or a contractor) used Cursor, Bolt, Lovable, Claude, or ChatGPT to build something that works — it demos well, early users like it, and now it needs to survive contact with the real world. We start where these tools consistently fail: hardcoded secrets, authentication that checks the box but not the request, and API usage that was never built to a budget. Our playbook for this exact handoff is in ",[213,234,236],{"href":235},"\u002Fblog\u002Fai-prototype-to-production","Shipping an AI-Built Prototype to Production",".",[226,239,241],{"id":240},"ai-accelerated-audit-of-any-codebase","AI-Accelerated Audit of Any Codebase",[174,243,244],{},"Your codebase does not have to be AI-generated for this to apply. We run the same automated analysis — static analysis, dependency scanning, secrets detection — against any stack, AI-assisted or not, which is what lets us turn an audit around in weeks instead of months. The manual review on top is where our engineers actually read your architecture and business logic; the automation just means less of the budget goes to finding the obvious stuff by hand.",[181,246,248],{"id":247},"what-goes-wrong-in-ai-generated-code","What Goes Wrong in AI-Generated Code",[174,250,251],{},"We've audited dozens of AI-generated codebases. The same categories of problems appear in nearly every one — systematic blind spots, not edge cases.",[253,254],"statistics-grid",{":items":255},"[{\"icon\": \"lucide:shield-alert\", \"value\": \"45%\", \"label\": \"Fail Security Tests\", \"description\": \"AI-generated code samples fail OWASP security checks (Veracode, 2025)\"}, {\"icon\": \"lucide:dollar-sign\", \"value\": \"5-20x\", \"label\": \"API Overspend\", \"description\": \"Typical cost overrun from unoptimized paid API usage\"}, {\"icon\": \"lucide:key\", \"value\": \"2x\", \"label\": \"More Secret Leaks\", \"description\": \"AI-assisted developers expose credentials nearly twice as often (Apiiro, 2025)\"}, {\"icon\": \"lucide:clock\", \"value\": \"2-4 weeks\", \"label\": \"Audit Timeline\", \"description\": \"Time to identify and fix critical issues\"}]",[174,257,258,259,264,265,269,270,274,275,279,280,284],{},"These numbers come from independent research: ",[213,260,263],{"href":261,"target":262},"https:\u002F\u002Fwww.veracode.com\u002Fblog\u002Fgenai-code-security-report\u002F","_blank","Veracode tested 100+ LLMs"," and found 45% of generated code fails security tests. ",[213,266,268],{"href":267,"target":262},"https:\u002F\u002Fapiiro.com\u002Fblog\u002F4x-velocity-10x-vulnerabilities-ai-coding-assistants-are-shipping-more-risks\u002F","Apiiro's 2025 analysis"," showed AI-assisted developers expose credentials nearly twice as often. ",[213,271,273],{"href":272,"target":262},"https:\u002F\u002Farxiv.org\u002Fpdf\u002F2108.09293","NYU researchers"," found ~40% of Copilot-generated programs contained vulnerabilities, while ",[213,276,278],{"href":277,"target":262},"https:\u002F\u002Fee.stanford.edu\u002Fdan-boneh-and-team-find-relying-ai-more-likely-make-your-code-buggier","Stanford's study"," confirmed developers using AI assistants produce less secure code — and are more confident it's safe. Our own review of agent-written Flutter is in ",[213,281,283],{"href":282},"\u002Fblog\u002Fai-agents-struggle-with-flutter","How AI Agents Struggle with Flutter",": duplicated state, no tests, and UI that never got a second look from a human.",[226,286,288],{"id":287},"security-vulnerabilities","Security Vulnerabilities",[290,291,292],"ol",{},[293,294,295],"li",{},"Exposed API Keys and Secrets",[174,297,298],{},"AI tools frequently hardcode API keys, database credentials, and third-party service tokens directly in source code. These end up in public repositories, client-side bundles, or environment files that ship to production. One leaked OpenAI key can generate thousands of dollars in unauthorized usage within hours.",[290,300,302],{"start":301},2,[293,303,304],{},"Missing Authentication and Authorization",[174,306,307],{},"AI-generated apps often implement authentication at the surface level — a login screen exists, but the backend doesn't actually verify permissions. API endpoints accept any request. Admin routes are accessible without role checks. User A can see User B's data by changing an ID in the URL.",[290,309,311],{"start":310},3,[293,312,313],{},"Injection Attacks",[174,315,316,317,322],{},"SQL injection, XSS, and ",[318,319,321],"term",{"slug":320},"prompt-injection","prompt injection"," are pervasive in AI-built code. AI models generate code that concatenates user input directly into queries, HTML, or LLM prompts without sanitization. A single vulnerable endpoint can compromise your entire database or allow attackers to manipulate your AI's behavior.",[290,324,326],{"start":325},4,[293,327,328],{},"Insecure Data Storage",[174,330,331,332,335,336,340],{},"Personal data stored in plain text, session tokens in localStorage, passwords hashed with MD5 or not hashed at all. AI tools default to the simplest implementation, which is rarely the secure one. ",[318,333],{"slug":334},"gdpr"," and privacy compliance is typically absent. Our guide to ",[213,337,339],{"href":338},"\u002Fblog\u002Fencryption-explained","encryption in production applications"," covers how data should actually be protected at rest and in transit.",[226,342,344],{"id":343},"api-cost-optimization","API Cost Optimization",[290,346,347],{},[293,348,349],{},"Redundant API Calls",[174,351,352],{},"The most expensive problem we find. AI-generated apps make unnecessary calls to paid third-party APIs — geocoding services, financial data providers, AI models, verification APIs. They call the same endpoint multiple times for the same data, fail to cache responses, and make requests that could be avoided entirely with simple local logic. We routinely find apps where 60-80% of API spend is wasted.",[290,354,355],{"start":301},[293,356,357],{},"Missing Rate Limiting and Budgets",[174,359,360,361,365],{},"No per-user ",[318,362,364],{"slug":363},"rate-limiting","rate limits",". No daily spend caps. No circuit breakers when API costs spike. A single user — or a bot — can burn through your entire monthly budget in a day. AI tools never implement cost controls because they have no concept of your business model or the pricing tiers of the services you integrate.",[290,367,368],{"start":310},[293,369,370],{},"No Caching or Batching",[174,372,373],{},"Fetching the same exchange rate, IP geolocation, or user profile from a paid API on every single request instead of caching it. Making individual API calls in a loop instead of using batch endpoints. Each unnecessary request costs money, and at scale these add up to thousands of dollars per month.",[226,375,377],{"id":376},"data-leaks-and-privacy","Data Leaks and Privacy",[290,379,380],{},[293,381,382],{},"Logging Sensitive Information",[174,384,385],{},"AI-generated code loves verbose logging. User emails, passwords, payment details, and personal data end up in application logs, error tracking services, and third-party analytics. These logs are often accessible without authentication and retained indefinitely.",[290,387,388],{"start":301},[293,389,390],{},"Oversharing Through APIs",[174,392,393,394,397],{},"API responses that return entire user objects — including hashed passwords, internal IDs, email addresses, and metadata — when the frontend only needs a display name. ",[318,395],{"slug":396},"graphql"," endpoints without depth limits that allow attackers to extract your entire data model.",[290,399,400],{"start":310},[293,401,402],{},"Third-Party Data Exposure",[174,404,405],{},"AI tools integrate analytics, error tracking, and monitoring services without considering what data flows to them. User behavior, personal information, and business data end up in third-party systems without consent, violating GDPR and other privacy regulations.",[407,408],"image-box",{"alt":409,"src":410,"subtitle":411},"Deploying unaudited AI-generated code to production","\u002Fservices\u002Fai-transition-example.webp","What happens when AI-generated code goes to production without an audit",[181,413,415],{"id":414},"whos-behind-the-audit","Who's Behind the Audit",[174,417,418,419,423,424,427,428,431],{},"Nerdy Production is led by ",[213,420,422],{"href":421},"\u002Fteam\u002Fnixan","Ilya Nixan",", previously CTO of QIWI, one of the largest payment platforms in its market, where he ran roughly 12 engineering teams covering everything from web products down to card processing and ",[318,425],{"slug":426},"pci-dss"," scope. That is the standard our audits are held to: not \"does the code run\", but \"would this survive a review by someone who has carried compliance scope and had to answer for a production incident.\" We do not hold PCI-DSS or ",[318,429],{"slug":430},"soc-2"," certification ourselves, and we will tell you plainly when a finding is outside what an audit can certify — but the person setting the bar for what counts as a critical finding has operated regulated infrastructure, not just read about it.",[174,433,434,435,437],{},"Our engineers work with AI coding tools daily, which is exactly why we know where they fail. ",[213,436,283],{"href":282}," walks through the specific gaps an unsupervised agent leaves behind — duplicated state, missing tests, UI that never got a second look — the same patterns we look for in every audit, regardless of language or framework.",[181,439,441],{"id":440},"how-an-audit-works","How an Audit Works",[174,443,444],{},"We deliver a complete audit with fixes you can act on, not just a list of problems.",[290,446,447],{},[293,448,449],{},"Codebase Access and Scope",[174,451,452],{},"You grant us read access to your repository and deployed environment. We define the audit scope based on your priorities: full audit or focused on specific areas (security, costs, or data privacy). No changes are made to your code during the audit phase.",[290,454,455],{"start":301},[293,456,457],{},"Automated Analysis",[174,459,460],{},"We run static analysis, dependency vulnerability scans, secrets detection, and API cost profiling against your codebase. This catches the low-hanging fruit — known vulnerabilities, exposed credentials, outdated packages with security patches, and obvious performance issues.",[290,462,463],{"start":310},[293,464,465],{},"Manual Expert Review",[174,467,468],{},"Our engineers manually review the architecture, business logic, authentication flows, API integrations, and data handling. This is where we find the problems that automated tools miss: logic flaws, authorization gaps, cost optimization opportunities, and design issues that will cause problems at scale.",[290,470,471],{"start":325},[293,472,473],{},"Severity-Ranked Report",[174,475,476],{},"We deliver a detailed report with every finding categorized by severity (critical, high, medium, low) and type (security, cost, privacy, performance). Each finding includes a clear explanation of the risk, proof of concept where applicable, and a specific fix recommendation with code examples.",[290,478,480],{"start":479},5,[293,481,482],{},"Remediation — Your Choice",[174,484,485,486,490],{},"You pick who fixes it. We can implement every fix ourselves as a fixed-scope engagement, with critical security patches first and you reviewing every change before it's merged. Or, if you'd rather your own team own the fixes, we can embed an engineer who already knows your findings report through ",[213,487,489],{"href":488},"\u002Fservices\u002Fteam-augmentation","team augmentation"," instead of handing you a document and disappearing. Either way, the result is a codebase you can deploy with confidence.",[181,492,494],{"id":493},"ai-generated-code-vs-production-ready-code","AI-Generated Code vs Production-Ready Code",[174,496,497],{},"What changes when your codebase goes through a professional audit",[499,500],"features-table",{":heading":501,":rows":502,":top-left-label":503},"[{\"label\": \"After Audit\", \"hightlightLabel\": \"Production-Ready\"}, {\"label\": \"AI-Generated Code\"}, {\"label\": \"Built from Scratch\"}]","[{\"label\": \"Security\",\"cells\": [{\"text\": \"Hardened\", \"color\": \"success\", \"icon\": \"lucide:check-circle\" },{ \"text\": \"Surface-Level\", \"color\": \"error\", \"icon\": \"lucide:x\" },{ \"text\": \"Varies by Team\", \"color\": \"warning\", \"icon\": \"lucide:minus\" }]}, {\"label\": \"API Costs\",\"cells\": [{\"text\": \"Optimized\", \"color\": \"success\", \"icon\": \"lucide:check-circle\" },{ \"text\": \"5-20x Overspend\", \"color\": \"error\", \"icon\": \"lucide:x\" },{ \"text\": \"Usually Optimized\", \"color\": \"success\", \"icon\": \"lucide:check-circle\" }]}, {\"label\": \"Data Privacy\",\"cells\": [{\"text\": \"GDPR-Compliant\", \"color\": \"success\", \"icon\": \"lucide:check-circle\" },{ \"text\": \"Data Leaks Common\", \"color\": \"error\", \"icon\": \"lucide:x\" },{ \"text\": \"Depends on Process\", \"color\": \"warning\", \"icon\": \"lucide:minus\" }]}, {\"label\": \"Time to Production\",\"cells\": [{\"text\": \"2-4 Weeks\", \"color\": \"success\", \"icon\": \"lucide:check-circle\" },{ \"text\": \"Already Running\", \"color\": \"success\", \"icon\": \"lucide:check-circle\" },{ \"text\": \"3-6 Months\", \"color\": \"error\", \"icon\": \"lucide:x\" }]}, {\"label\": \"Cost to Launch\",\"cells\": [{\"text\": \"Low (Audit Fee)\", \"color\": \"success\", \"icon\": \"lucide:check-circle\" },{ \"text\": \"Free (Risky)\", \"color\": \"error\", \"icon\": \"lucide:x\" },{ \"text\": \"High (Full Dev)\", \"color\": \"warning\", \"icon\": \"lucide:minus\" }]}, {\"label\": \"Error Handling\",\"cells\": [{\"text\": \"Graceful Recovery\", \"color\": \"success\", \"icon\": \"lucide:check-circle\" },{ \"text\": \"Crashes in Edge Cases\", \"color\": \"error\", \"icon\": \"lucide:x\" },{ \"text\": \"Usually Handled\", \"color\": \"success\", \"icon\": \"lucide:check-circle\" }]}, {\"label\": \"Scalability\",\"cells\": [{\"text\": \"Load-Tested\", \"color\": \"success\", \"icon\": \"lucide:check-circle\" },{ \"text\": \"Untested\", \"color\": \"error\", \"icon\": \"lucide:x\" },{ \"text\": \"Architected for Scale\", \"color\": \"success\", \"icon\": \"lucide:check-circle\" }]}, {\"label\": \"Monitoring\",\"cells\": [{\"text\": \"Full Observability\", \"color\": \"success\", \"icon\": \"lucide:check-circle\" },{ \"text\": \"None or Excessive\", \"color\": \"error\", \"icon\": \"lucide:x\" },{ \"text\": \"Standard Setup\", \"color\": \"success\", \"icon\": \"lucide:check-circle\" }]}]","Aspect",[205,505,506],{},[174,507,508,512],{},[509,510,511],"strong",{},"The bottom line:"," AI-generated code gets you 80% of the way there in 5% of the time. But that last 20% — security, cost optimization, data privacy, error handling — is what separates a demo from a production application. An audit bridges the gap without throwing away your AI-built foundation.",[181,514,516],{"id":515},"ai-code-audit-pricing","AI Code Audit Pricing",[174,518,519],{},"Transparent pricing based on your codebase size and audit scope",[521,522],"pricing-table",{":items":523},"[{\"title\": \"Security Focused\", \"subtitle\": \"Critical vulnerabilities only\", \"price\": \"ai-code-audit\u002Fsecurity\", \"terms\": \"1-2 weeks\", \"lines\": [\"OWASP Top 10 vulnerability scan\", \"Secrets and credentials detection\", \"Authentication & authorization review\", \"Dependency vulnerability check\", \"Prioritized findings report\", \"Fix recommendations with code examples\"], \"callToAction\": {\"to\": \"\u002Fcontact?intent=ai-code-audit\", \"label\": \"Get Started\"}},{\"title\": \"Cost Optimization\", \"subtitle\": \"Reduce your API spend\", \"price\": \"ai-code-audit\u002Fcost-optimization\", \"terms\": \"1-2 weeks\", \"lines\": [\"Paid API usage profiling\", \"Redundant call identification\", \"Caching & batching strategy design\", \"Rate limiting implementation plan\", \"Per-request cost optimization\", \"Projected monthly savings report\"], \"callToAction\": {\"to\": \"\u002Fcontact?intent=ai-code-audit\", \"label\": \"Get Started\"}},{\"highlight\": \"Popular\",\"title\": \"Full Audit\", \"subtitle\": \"Complete production readiness\", \"price\": \"ai-code-audit\u002Ffull\", \"terms\": \"2-4 weeks\", \"lines\": [\"Everything in Security Focused\", \"Everything in Cost Optimization\", \"Data privacy & GDPR review\", \"Performance & scalability analysis\", \"Infrastructure audit\", \"Detailed report + fix implementation\"], \"callToAction\": {\"to\": \"\u002Fcontact?intent=ai-code-audit\", \"label\": \"Get Started\"}},{\"title\": \"Ongoing Support\", \"subtitle\": \"Continuous audit & monitoring\", \"price\": \"ai-code-audit\u002Fretainer\", \"terms\": \"per month\", \"lines\": [\"Monthly security scans\", \"API cost monitoring & alerts\", \"Dependency update reviews\", \"New feature security review\", \"Priority incident response\", \"Direct Slack\u002FTelegram access\"], \"callToAction\": {\"to\": \"\u002Fcontact?intent=ai-code-audit\", \"label\": \"Get Started\"}}]",[205,525,528],{":leading-icon":526,":title":527},"lucide:dollar-sign","Custom Pricing Available",[174,529,530],{},"Pricing depends on codebase size, number of services and integrations, and audit scope. A small single-service app with one AI integration will be at the lower end. A multi-service platform with several AI providers, payment processing, and user data will require a more thorough review. Contact us for a free initial assessment.",[181,532,534],{"id":533},"frequently-asked-questions","Frequently Asked Questions",[174,536,537],{},"Common questions about auditing AI-generated and production codebases",[539,540],"questions",{":items":541},"[{\"title\":\"My app was built with Cursor \u002F Bolt \u002F Lovable — do you work with these?\", \"text\": \"Yes. We audit code regardless of how it was generated. Whether you used Cursor, Bolt, Lovable, Claude, ChatGPT, GitHub Copilot, or any combination of AI tools, the audit process is the same. The output is code, and that is what we review. We have experience with all major AI coding tools and know their common failure patterns.\"}, {\"title\": \"Do you audit codebases that were not built with AI?\", \"text\": \"Yes. The audit finds the same categories of risk — security, architecture, performance, correctness, dependencies, test coverage — whether or not AI wrote any of the code. What we call an AI-accelerated audit uses automated analysis to move through any codebase faster, so a hand-written app gets the same thorough review on the same timeline.\"}, {\"title\": \"Will you need to take the app down during the audit?\", \"text\": \"No. The audit is entirely non-disruptive. We review your source code and may run read-only tests against a staging environment. Your production application continues running normally throughout the process. If we find a critical vulnerability that poses immediate risk, we will notify you immediately so you can decide how to proceed.\"}, {\"title\": \"How much can I actually save on API costs?\", \"text\": \"In our experience, AI-generated applications overspend on paid API calls by 5-20x. The most common savings come from eliminating redundant calls to services like geocoding, financial data, or AI providers, implementing response caching, batching requests, and adding rate limits to prevent abuse. We have seen monthly API bills drop from $5,000 to under $500 after optimization, though results depend on your specific usage patterns.\"}, {\"title\": \"Can you also fix the issues you find, or just report them?\", \"text\": \"Both. The audit report includes specific fix recommendations with code examples for every finding. If you prefer, we can implement all fixes ourselves — this is included in the Full Audit tier and available as an add-on for other tiers. If you would rather your own team do the fixing, we can embed an engineer through staff augmentation instead. You review and approve every change before it is merged.\"}, {\"title\": \"Can I see a sample audit report before I commit?\", \"text\": \"Yes. Request a redacted sample audit report through the contact form and we will send one over — the same severity-ranked format, risk explanations, and fix recommendations a real engagement produces, with client-identifying details removed.\"}, {\"title\": \"I am not technical — will I understand the audit report?\", \"text\": \"Yes. Every finding includes a plain-language explanation of the risk and its business impact, not just technical jargon. We categorize issues by severity so you know what needs immediate attention versus what can wait. We also include an executive summary at the top of the report with the key takeaways and recommended action plan.\"}]",{"title":543,"searchDepth":301,"depth":301,"links":544},"",[545,546,547,551,556,557,558,559,560],{"id":183,"depth":301,"text":184},{"id":195,"depth":301,"text":196},{"id":220,"depth":301,"text":221,"children":548},[549,550],{"id":228,"depth":310,"text":229},{"id":240,"depth":310,"text":241},{"id":247,"depth":301,"text":248,"children":552},[553,554,555],{"id":287,"depth":310,"text":288},{"id":343,"depth":310,"text":344},{"id":376,"depth":310,"text":377},{"id":414,"depth":301,"text":415},{"id":440,"depth":301,"text":441},{"id":493,"depth":301,"text":494},{"id":515,"depth":301,"text":516},{"id":533,"depth":301,"text":534},"For teams shipping fast with Cursor, Bolt, or Claude, and for founders who inherited an AI-built app: an independent review of your codebase for security, architecture, and production-readiness.","md",{"heading":564,"text":565,"buttons":566},"Ready for an Independent Code Audit?","Tell us what you're running and how it was built — by an AI tool, by a team, or both. We'll scope the audit and send a severity-ranked findings report you can act on.",[567,572],{"to":215,"label":568,"leadingIcon":569,"color":570,"variant":571},"Request an Audit","lucide:message-circle","neutral","outline",{"to":573,"label":574,"color":575,"variant":576},"\u002Fportfolio","View our work","primary","solid",[578,579],{"to":215,"label":568,"leadingIcon":569,"color":575,"variant":576},{"to":580,"label":581,"color":570,"variant":571},"#ai-code-audit-pricing","View Pricing",{"url":583,"alt":169,"text":584},"\u002Fservices\u002Fai-code-audit.webp","From AI Prototype to Production-Ready",{},"Independent AI code audit: we review AI-generated and vibe-coded apps for security, architecture, and production-readiness. Fixed scope, real findings.","AI Code Audit Service — Security & Quality Review",true,"Shipped fast with Cursor or Claude, or inherited an app you did not write? An independent read of what is actually in the codebase, with fixed scope.",null,"\u002Fservices\u002Fai-code-audit",{"title":169,"description":561},"ai-code-audit","services\u002Fai-code-audit","2026-08-06","6-cr_EFVcQrDDXGo9UDztnd_HbT_RqWhuyrJJ_2omr8",[],[599,614,627,642,656,669,685,697,711,724,738,751,767,780,794,807,818,828,841,853,864,879,888,901,914,921,932,944,955,970,982,995,1007,1019,1031,1041,1052,1063,1074,1085,1097,1107,1118,1131,1142,1151,1164,1176,1186,1197,1211,1220,1231],{"slug":600,"term":601,"definition":602,"category":603,"aliases":604,"links":606,"related":610,"readMore":-1,"target":612,"hasArticle":613},"aosp","AOSP","The Android Open Source Project — Android without the Google layer on top, which anyone may fork. Point-of-sale terminals, kiosks and in-car systems run on forks of it, and working at that level exposes parts of the OS an app developer never sees.","platform",[605],"Android Open Source Project",[607],{"kind":608,"url":609},"website","https:\u002F\u002Fsource.android.com\u002F",[611],"host-card-emulation","\u002Fglossary#aosp",false,{"slug":615,"term":616,"definition":617,"category":603,"aliases":618,"links":619,"related":623,"readMore":-1,"target":626,"hasArticle":613},"app-clips","App Clips","An Apple feature that runs a small slice of an iOS app — under 15 MB — without installing the whole thing. Invoked from a QR code, an NFC tag or a link, for when the first thing a user does should not require a store visit.",[],[620],{"kind":621,"url":622},"documentation","https:\u002F\u002Fdeveloper.apple.com\u002Fapp-clips\u002F",[624,625],"deep-linking","install-referrer","\u002Fglossary#app-clips",{"slug":628,"term":629,"definition":630,"category":603,"aliases":631,"links":632,"related":638,"readMore":-1,"target":641,"hasArticle":613},"bigquery","BigQuery","Google Cloud's analytics warehouse. You point SQL at billions of rows and it scans them in seconds, on storage held separately from the machines doing the querying — which is what keeps reporting and exploration off the database that is serving live traffic.",[],[633,635],{"kind":608,"url":634},"https:\u002F\u002Fcloud.google.com\u002Fbigquery",{"kind":636,"url":637},"wikipedia","https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FBigQuery",[639,640],"object-storage","elasticsearch","\u002Fglossary#bigquery",{"slug":643,"term":644,"definition":645,"category":646,"aliases":647,"links":651,"related":654,"readMore":-1,"target":655,"hasArticle":613},"ci-cd","CI\u002FCD","Automation that builds, tests and ships every change without anyone running commands by hand. On mobile it is what turns a release into a button press instead of an afternoon of someone else being unavailable.","practice",[648,649,650],"CI","continuous integration","continuous delivery",[652],{"kind":636,"url":653},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FCI\u002FCD",[],"\u002Fglossary#ci-cd",{"slug":657,"term":658,"definition":659,"category":660,"aliases":661,"links":663,"related":666,"readMore":-1,"target":668,"hasArticle":613},"crud","CRUD","Create, read, update, delete — the four operations behind almost every form and admin screen. Shorthand for the routine data-management half of an app, as opposed to the parts carrying real domain logic.","architecture",[662],"Create, Read, Update, Delete",[664],{"kind":636,"url":665},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FCreate,_read,_update_and_delete",[667,396],"rest","\u002Fglossary#crud",{"slug":670,"term":671,"definition":672,"category":660,"aliases":673,"links":678,"related":681,"readMore":-1,"target":684,"hasArticle":613},"container-registry","Container registry","A hosted store for container images, addressed by name and tag — Docker Hub, GitHub Container Registry, or a cloud provider's own. Pushing a build there turns 'works on my machine' into an image anyone can pull and run unchanged.",[674,675,676,677],"image registry","Docker registry","GHCR","ghcr.io",[679],{"kind":621,"url":680},"https:\u002F\u002Fdocs.github.com\u002Fen\u002Fpackages\u002Fworking-with-a-github-packages-registry\u002Fworking-with-the-container-registry",[682,683],"dev-container","multi-arch-image","\u002Fglossary#container-registry",{"slug":624,"term":686,"definition":687,"category":603,"aliases":688,"links":692,"related":695,"readMore":696,"target":696,"hasArticle":588},"Deep linking","A link that opens a specific screen inside an installed app instead of its home screen or a web page. Deferred deep linking survives an install, so a tap that leads through the app store still lands on the right screen.",[689,690,691],"deferred deep linking","universal links","Android App Links",[693],{"kind":636,"url":694},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FMobile_deep_linking",[615,625],"\u002Fglossary\u002Fdeep-linking",{"slug":682,"term":698,"definition":699,"category":646,"aliases":700,"links":704,"related":709,"readMore":-1,"target":710,"hasArticle":613},"Dev Container","A development environment described once in devcontainer.json — the OS, tools, and runtime versions a project needs — and opened identically inside a container by every contributor's editor, instead of a setup guide everyone interprets differently.",[701,702,703],"devcontainer.json","Dev Containers","VS Code Dev Containers",[705,707],{"kind":608,"url":706},"https:\u002F\u002Fcontainers.dev\u002F",{"kind":621,"url":708},"https:\u002F\u002Fcode.visualstudio.com\u002Fdocs\u002Fdevcontainers\u002Fcontainers",[670],"\u002Fglossary#dev-container",{"slug":640,"term":712,"definition":713,"category":603,"aliases":714,"links":717,"related":722,"readMore":-1,"target":723,"hasArticle":613},"Elasticsearch","A search and analytics engine that indexes records so they can be filtered and searched interactively instead of scanned. What you reach for when the question is \"show me these particular sessions, narrowed six ways\" rather than \"sum this column\".",[715,716],"Elastic","ELK",[718,720],{"kind":608,"url":719},"https:\u002F\u002Fwww.elastic.co\u002Felasticsearch",{"kind":636,"url":721},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FElasticsearch",[628],"\u002Fglossary#elasticsearch",{"slug":725,"term":726,"definition":727,"category":660,"aliases":728,"links":731,"related":734,"readMore":-1,"target":737,"hasArticle":613},"end-to-end-encryption","End-to-end encryption","Encryption applied on the sending device and undone only on the receiving one, so the service carrying the message cannot read it — not under subpoena, not after a breach. It protects the content and never the metadata.",[729,730],"E2EE","end-to-end encrypted",[732],{"kind":636,"url":733},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FEnd-to-end_encryption",[735,736],"tls","jwt","\u002Fglossary#end-to-end-encryption",{"slug":739,"term":740,"definition":741,"category":660,"aliases":742,"links":745,"related":746,"readMore":-1,"target":750,"hasArticle":613},"fan-out","Fan-out","Reading an upstream source once and delivering each update to every client subscribed to it. The naive version writes to subscribers in a loop and stalls the moment one socket is slow; a real one buffers per client and drops whoever cannot keep up.",[743,744],"fanout","broadcast",[],[747,748,749],"websocket","pub-sub","server-sent-events","\u002Fglossary#fan-out",{"slug":752,"term":753,"definition":754,"category":646,"aliases":755,"links":759,"related":762,"readMore":-1,"target":766,"hasArticle":613},"feature-flags","Feature flags","Switches that turn functionality on or off from configuration rather than from a release. They let one binary behave differently per brand, market or user, and let a risky feature be shut off without shipping a new build through review.",[756,757,758],"feature flag","feature toggle","feature gating",[760],{"kind":636,"url":761},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FFeature_toggle",[763,764,765],"staged-rollout","white-label","multi-tenancy","\u002Fglossary#feature-flags",{"slug":768,"term":769,"definition":770,"category":660,"aliases":771,"links":775,"related":778,"readMore":-1,"target":779,"hasArticle":613},"floating-point","Floating point","The IEEE 754 binary format behind double and float. It cannot hold 0.1 exactly, so 0.1 + 0.2 is 0.30000000000000004 — invisible in graphics and fatal in money, which belongs in integer minor units or a decimal type instead.",[772,773,774],"IEEE 754","double","floating-point arithmetic",[776],{"kind":636,"url":777},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FIEEE_754",[],"\u002Fglossary#floating-point",{"slug":334,"term":781,"definition":782,"category":646,"aliases":783,"links":786,"related":791,"readMore":-1,"target":793,"hasArticle":613},"GDPR","The EU regulation covering personal data of people in the EU: a lawful basis for collecting it, real consent for tracking, and rights to see and delete it. It follows your users, not your servers, so it applies wherever the company is registered.",[784,785],"General Data Protection Regulation","data protection",[787,789],{"kind":608,"url":788},"https:\u002F\u002Fgdpr.eu\u002F",{"kind":636,"url":790},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FGeneral_Data_Protection_Regulation",[426,430,792],"hipaa","\u002Fglossary#gdpr",{"slug":795,"term":796,"definition":797,"category":646,"aliases":798,"links":802,"related":805,"readMore":-1,"target":806,"hasArticle":613},"golden-test","Golden test","A test that renders a widget and compares the result pixel for pixel against a stored reference image. In Flutter it is the cheapest way to answer whether a redesign broke the empty state at 320pt, in dark mode, at 200% text scale.",[799,800,801],"golden tests","screenshot test","snapshot test",[803],{"kind":621,"url":804},"https:\u002F\u002Fapi.flutter.dev\u002Fflutter\u002Fflutter_test\u002FmatchesGoldenFile.html",[643],"\u002Fglossary#golden-test",{"slug":396,"term":808,"definition":809,"category":660,"aliases":810,"links":811,"related":816,"readMore":-1,"target":817,"hasArticle":613},"GraphQL","A query language for APIs where the client names exactly the fields it wants and gets one response shaped to match. It removes the over-fetching REST endpoints drift into, and adds a failure mode of its own: an unbounded query that walks the whole data model.",[],[812,814],{"kind":608,"url":813},"https:\u002F\u002Fgraphql.org\u002F",{"kind":636,"url":815},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FGraphQL",[667],"\u002Fglossary#graphql",{"slug":792,"term":819,"definition":820,"category":646,"aliases":821,"links":823,"related":826,"readMore":-1,"target":827,"hasArticle":613},"HIPAA","The US law governing protected health information — how it may be stored, transmitted, logged and disclosed. Like PCI-DSS it is an architectural constraint chosen at the start, not a policy document added before launch.",[822],"Health Insurance Portability and Accountability Act",[824],{"kind":636,"url":825},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FHealth_Insurance_Portability_and_Accountability_Act",[426,334,430],"\u002Fglossary#hipaa",{"slug":829,"term":830,"definition":831,"category":660,"aliases":832,"links":835,"related":838,"readMore":-1,"target":840,"hasArticle":613},"headless-cms","Headless CMS","A content system with an editor and an API but no front end of its own. Editors publish in one place, and the site or app renders that content itself — so the presentation layer is yours rather than the CMS vendor's.",[833,834],"headless content management system","content API",[836],{"kind":636,"url":837},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FHeadless_content_management_system",[839,667],"server-side-rendering","\u002Fglossary#headless-cms",{"slug":611,"term":842,"definition":843,"category":603,"aliases":844,"links":848,"related":851,"readMore":-1,"target":852,"hasArticle":613},"Host Card Emulation","Letting an Android phone act as a contactless card over NFC in software, with no hardware secure element. It is how a wallet app pays at a terminal: the phone speaks the same EMV contactless protocol the plastic card would have.",[845,846,847],"HCE","EMV Contactless","contactless payments",[849],{"kind":621,"url":850},"https:\u002F\u002Fdeveloper.android.com\u002Fdevelop\u002Fconnectivity\u002Fnfc\u002Fhce",[426,600],"\u002Fglossary#host-card-emulation",{"slug":854,"term":855,"definition":856,"category":603,"aliases":857,"links":858,"related":861,"readMore":-1,"target":863,"hasArticle":613},"impeller","Impeller","The rendering engine Flutter uses today, default on iOS since 2023 and on Android since 2024. It compiles its shaders ahead of time instead of during the first animation, which removed the shader-compilation jank that was Flutter's most visible production problem.",[],[859],{"kind":621,"url":860},"https:\u002F\u002Fdocs.flutter.dev\u002Fperf\u002Fimpeller",[862],"skia","\u002Fglossary#impeller",{"slug":865,"term":866,"definition":867,"category":868,"aliases":869,"links":873,"related":876,"readMore":-1,"target":878,"hasArticle":613},"in-app-purchase","In-app purchase","Selling digital goods or a subscription through the Apple or Google billing that both stores require for digital content and take a commission on. The hard part is never the purchase; it is restoring it on a new device and keeping entitlement state honest.","business",[870,871,872],"IAP","in-app purchases","in-app subscription",[874],{"kind":621,"url":875},"https:\u002F\u002Fdeveloper.apple.com\u002Fin-app-purchase\u002F",[877],"product-market-fit","\u002Fglossary#in-app-purchase",{"slug":625,"term":880,"definition":881,"category":603,"aliases":882,"links":883,"related":886,"readMore":-1,"target":887,"hasArticle":613},"Install Referrer","A Google Play API that hands a freshly installed Android app the campaign parameters from the link that led to the install. The Android half of deferred deep linking, and the dependable way to attribute where a user came from.",[],[884],{"kind":621,"url":885},"https:\u002F\u002Fdeveloper.android.com\u002Fgoogle\u002Fplay\u002Finstallreferrer",[624,615],"\u002Fglossary#install-referrer",{"slug":736,"term":889,"definition":890,"category":891,"aliases":892,"links":894,"related":899,"readMore":-1,"target":900,"hasArticle":613},"JWT","A signed token carrying its own claims, so a server can tell who a request belongs to without looking a session up. Standard for mobile authentication. The signature proves it was not altered; it does not hide what is inside.","protocol",[893],"JSON Web Token",[895,897],{"kind":608,"url":896},"https:\u002F\u002Fjwt.io\u002F",{"kind":636,"url":898},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FJSON_Web_Token",[426],"\u002Fglossary#jwt",{"slug":902,"term":903,"definition":904,"category":646,"aliases":905,"links":909,"related":912,"readMore":-1,"target":913,"hasArticle":613},"kyc","KYC","Know Your Customer — the identity checks a regulated financial product runs before it lets anyone move money: document capture, liveness, sanctions and anti-money-laundering screening. It shapes onboarding more than any design decision does.",[906,907,908],"Know Your Customer","AML","KYC\u002FAML",[910],{"kind":636,"url":911},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FKnow_your_customer",[426,334],"\u002Fglossary#kyc",{"slug":76,"term":74,"definition":915,"category":603,"aliases":916,"links":918,"related":919,"readMore":920,"target":920,"hasArticle":613},"Sharing business logic written in Kotlin across Android, iOS and the server while each platform keeps its own native UI. The alternative to Flutter when the interface has to be native but the rules behind it do not.",[917],"KMP",[],[],"\u002Ftechnologies\u002Fkmp",{"slug":922,"term":923,"definition":924,"category":868,"aliases":925,"links":927,"related":930,"readMore":-1,"target":931,"hasArticle":613},"mvp","MVP","The smallest version of a product that can go in front of real users and still answer the question you built it to answer. A decision about scope, not about quality — an MVP still has to work.",[926],"minimum viable product",[928],{"kind":636,"url":929},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FMinimum_viable_product",[764],"\u002Fglossary#mvp",{"slug":683,"term":933,"definition":934,"category":660,"aliases":935,"links":939,"related":942,"readMore":-1,"target":943,"hasArticle":613},"Multi-architecture image","A single image tag that resolves to different binaries per CPU architecture — linux\u002Famd64 and linux\u002Farm64 are the common pair — so the same docker pull works unchanged on Intel\u002FAMD servers and Apple Silicon laptops.",[936,937,938],"multi-arch build","multi-platform image","linux\u002Famd64 + linux\u002Farm64",[940],{"kind":621,"url":941},"https:\u002F\u002Fdocs.docker.com\u002Fbuild\u002Fbuilding\u002Fmulti-platform\u002F",[670],"\u002Fglossary#multi-arch-image",{"slug":765,"term":945,"definition":946,"category":660,"aliases":947,"links":950,"related":953,"readMore":-1,"target":954,"hasArticle":613},"Multi-tenancy","One deployment serving many customers, each seeing only its own data, configuration and enabled features because tenant context is resolved per request. It is what makes a fleet of branded apps one product instead of many forks.",[948,949],"multi-tenant","tenant",[951],{"kind":636,"url":952},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FMultitenancy",[764,752],"\u002Fglossary#multi-tenancy",{"slug":956,"term":957,"definition":958,"category":891,"aliases":959,"links":963,"related":968,"readMore":-1,"target":969,"hasArticle":613},"oauth","OAuth","The standard behind Sign in with Apple, Google and the rest: the user authorises your app at a provider they already trust, and your app receives a token instead of their password. Nobody invents a new credential and you never store one.",[960,961,962],"OAuth 2.0","social login","Sign in with Apple",[964,966],{"kind":608,"url":965},"https:\u002F\u002Foauth.net\u002F2\u002F",{"kind":636,"url":967},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FOAuth",[736],"\u002Fglossary#oauth",{"slug":639,"term":971,"definition":972,"category":660,"aliases":973,"links":977,"related":980,"readMore":-1,"target":981,"hasArticle":613},"Object storage","Storage that holds a whole file under a key rather than in a filesystem tree — Amazon S3 and the many services that speak its API. Cheap, effectively unlimited, and the usual home for raw events, backups and media: written once, read rarely, kept forever.",[974,975,976],"S3","S3-compatible storage","blob storage",[978],{"kind":636,"url":979},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FObject_storage",[628],"\u002Fglossary#object-storage",{"slug":426,"term":983,"definition":984,"category":646,"aliases":985,"links":988,"related":993,"readMore":-1,"target":994,"hasArticle":613},"PCI-DSS","The card industry security standard binding anyone who stores, processes or transmits card data. Most apps stay out of its scope on purpose, by handing card entry to a certified payment provider instead.",[986,987],"PCI DSS","Payment Card Industry Data Security Standard",[989,991],{"kind":608,"url":990},"https:\u002F\u002Fwww.pcisecuritystandards.org\u002F",{"kind":636,"url":992},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FPayment_Card_Industry_Data_Security_Standard",[736],"\u002Fglossary#pci-dss",{"slug":996,"term":997,"definition":998,"category":603,"aliases":999,"links":1002,"related":1005,"readMore":-1,"target":1006,"hasArticle":613},"platform-channels","Platform channels","The bridge a Flutter app uses to call native iOS and Android code — Keychain and Keystore, biometrics, payment sheets, any SDK without a Dart package. Routine work but real work, and the first place an engineer who never left Dart will stall.",[1000,1001],"platform channel","method channel",[1003],{"kind":621,"url":1004},"https:\u002F\u002Fdocs.flutter.dev\u002Fplatform-integration\u002Fplatform-channels",[76],"\u002Fglossary#platform-channels",{"slug":1008,"term":1009,"definition":1010,"category":891,"aliases":1011,"links":1014,"related":1017,"readMore":-1,"target":1018,"hasArticle":613},"post-quantum-cryptography","Post-quantum cryptography","Encryption algorithms built to stay secure against a future quantum computer, now standardized by NIST. The migration is urgent ahead of the hardware because traffic captured today can be decrypted once such a machine exists.",[1012,1013],"PQC","post-quantum crypto",[1015],{"kind":636,"url":1016},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FPost-quantum_cryptography",[735,725],"\u002Fglossary#post-quantum-cryptography",{"slug":877,"term":1020,"definition":1021,"category":868,"aliases":1022,"links":1025,"related":1028,"readMore":-1,"target":1030,"hasArticle":613},"Product-market fit","The point at which a product has demonstrably found people who want it — they use it, come back, and pay. Before it, engineering answers a question; after it, engineering answers demand.",[1023,1024],"PMF","product\u002Fmarket fit",[1026],{"kind":636,"url":1027},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FProduct-market_fit",[922,1029],"time-to-market","\u002Fglossary#product-market-fit",{"slug":320,"term":1032,"definition":1033,"category":646,"aliases":1034,"links":1036,"related":1039,"readMore":-1,"target":1040,"hasArticle":613},"Prompt injection","An attack where text supplied by a user is read by a language model as instructions rather than as data, steering it past its own rules. The LLM-era sibling of SQL injection, and it appears wherever user input is concatenated into a prompt.",[1035],"injection attack",[1037],{"kind":636,"url":1038},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FPrompt_injection",[363],"\u002Fglossary#prompt-injection",{"slug":748,"term":1042,"definition":1043,"category":660,"aliases":1044,"links":1047,"related":1050,"readMore":-1,"target":1051,"hasArticle":613},"Pub\u002FSub","A messaging pattern where a producer publishes an event and any number of consumers read it independently, with a broker in between. The producer never waits for them, which is how a request path stays fast while slower work happens behind it.",[1045,1046],"publish\u002Fsubscribe","Google Cloud Pub\u002FSub",[1048],{"kind":636,"url":1049},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FPublish%E2%80%93subscribe_pattern",[],"\u002Fglossary#pub-sub",{"slug":667,"term":1053,"definition":1054,"category":660,"aliases":1055,"links":1058,"related":1061,"readMore":-1,"target":1062,"hasArticle":613},"REST","The conventional style for HTTP APIs: a URL names a resource and the HTTP verb says what to do with it. The default way an app talks to a backend, and what most third-party integrations expect to find.",[1056,1057],"REST API","Representational State Transfer",[1059],{"kind":636,"url":1060},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FREST",[747,749],"\u002Fglossary#rest",{"slug":363,"term":1064,"definition":1065,"category":646,"aliases":1066,"links":1069,"related":1072,"readMore":-1,"target":1073,"hasArticle":613},"Rate limiting","A cap on how many requests one caller may make in a given window. It is what stops a single enthusiastic user, a scraper or a bot from spending a month of paid API budget in an afternoon, and it has to live on your side of the integration.",[1067,1068],"rate limit","throttling",[1070],{"kind":636,"url":1071},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FRate_limiting",[320],"\u002Fglossary#rate-limiting",{"slug":430,"term":1075,"definition":1076,"category":646,"aliases":1077,"links":1080,"related":1083,"readMore":-1,"target":1084,"hasArticle":613},"SOC 2","An external auditor report on how an organisation handles customer data — security, availability, confidentiality — rather than a certificate you buy. Enterprise buyers ask for it, and it constrains architecture long before the audit itself does.",[1078,1079],"SOC2","System and Organization Controls",[1081],{"kind":636,"url":1082},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FSystem_and_Organization_Controls",[426,334,792],"\u002Fglossary#soc-2",{"slug":1086,"term":1087,"definition":1088,"category":868,"aliases":1089,"links":1092,"related":1095,"readMore":-1,"target":1096,"hasArticle":613},"saas","SaaS","Software sold as an ongoing subscription to a hosted product rather than as a one-off license the customer installs and runs. The vendor operates the servers, ships updates continuously, and bills per seat or per usage.",[1090,1091],"Software as a Service","software-as-a-service",[1093],{"kind":636,"url":1094},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FSoftware_as_a_service",[765,764],"\u002Fglossary#saas",{"slug":749,"term":1098,"definition":1099,"category":891,"aliases":1100,"links":1102,"related":1105,"readMore":-1,"target":1106,"hasArticle":613},"Server-Sent Events","A one-way stream from server to client over an ordinary HTTP connection. Simpler than a WebSocket and enough wherever only the server has something to say — a progress feed, an AI response arriving token by token.",[1101],"SSE",[1103],{"kind":636,"url":1104},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FServer-sent_events",[747,667],"\u002Fglossary#server-sent-events",{"slug":839,"term":1108,"definition":1109,"category":660,"aliases":1110,"links":1113,"related":1116,"readMore":-1,"target":1117,"hasArticle":613},"Server-side rendering","Building a page as finished HTML on the server, so the first response already carries the content, headings, meta tags and structured data. Crawlers, link previews and slow devices read it without running JavaScript.",[1111,1112],"SSR","server-rendered",[1114],{"kind":636,"url":1115},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FServer-side_scripting",[829],"\u002Fglossary#server-side-rendering",{"slug":862,"term":1119,"definition":1120,"category":603,"aliases":1121,"links":1124,"related":1129,"readMore":-1,"target":1130,"hasArticle":613},"Skia","The open-source 2D graphics library from Google that draws Chrome, Android and — until Impeller — every Flutter frame. It renders to PDF as well as to a screen, which is what print-to-PDF in Chrome is doing.",[1122,1123],"Skia Graphics Engine","skia-safe",[1125,1127],{"kind":608,"url":1126},"https:\u002F\u002Fskia.org\u002F",{"kind":636,"url":1128},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FSkia_Graphics_Engine",[854],"\u002Fglossary#skia",{"slug":1132,"term":1133,"definition":1134,"category":868,"aliases":1135,"links":1138,"related":1139,"readMore":-1,"target":1141,"hasArticle":613},"staff-augmentation","Staff augmentation","A hiring model where engineers from an outside partner join your team and work under your management — in your repository, your sprints, your process — instead of delivering a project of their own. You buy capacity; the code and the context stay with you.",[489,1136,1137],"dedicated developers","outstaffing",[],[1140,1029],"total-cost-of-ownership","\u002Fglossary#staff-augmentation",{"slug":763,"term":1143,"definition":1144,"category":646,"aliases":1145,"links":1148,"related":1149,"readMore":-1,"target":1150,"hasArticle":613},"Staged rollout","Releasing a build to a small percentage of users first and widening only once the crash-free rate holds. A bad build caught at ten percent is a bad afternoon; the same build at a hundred percent is a bad week.",[1146,1147],"phased release","canary release",[],[752,643],"\u002Fglossary#staged-rollout",{"slug":1152,"term":1153,"definition":1154,"category":660,"aliases":1155,"links":1159,"related":1162,"readMore":-1,"target":1163,"hasArticle":613},"state-management","State management","How an app decides where a value lives, who is allowed to change it, and which parts of the screen redraw when it does. In Flutter the choice between Riverpod, BLoC and Provider is among the first architectural decisions and the hardest to revisit.",[1156,1157,1158],"state management","BLoC","Riverpod",[1160],{"kind":621,"url":1161},"https:\u002F\u002Fdocs.flutter.dev\u002Fdata-and-backend\u002Fstate-mgmt\u002Foptions",[795],"\u002Fglossary#state-management",{"slug":735,"term":1165,"definition":1166,"category":891,"aliases":1167,"links":1171,"related":1174,"readMore":-1,"target":1175,"hasArticle":613},"TLS","The encryption layer underneath HTTPS. It proves the server is who its certificate says, agrees a fresh key for the session, and encrypts everything after that — so the network in between sees ciphertext it cannot quietly alter.",[1168,1169,1170],"SSL","HTTPS","Transport Layer Security",[1172],{"kind":636,"url":1173},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FTransport_Layer_Security",[725,736],"\u002Fglossary#tls",{"slug":1029,"term":1177,"definition":1178,"category":868,"aliases":1179,"links":1181,"related":1184,"readMore":-1,"target":1185,"hasArticle":613},"Time to market","How long it takes to get a product from decision to real users. Most stack and scope arguments are really arguments about this number, because every week saved is a week of revenue, feedback and competitive position.",[1180,1029],"TTM",[1182],{"kind":636,"url":1183},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FTime_to_market",[922,1140],"\u002Fglossary#time-to-market",{"slug":1140,"term":1187,"definition":1188,"category":868,"aliases":1189,"links":1192,"related":1195,"readMore":-1,"target":1196,"hasArticle":613},"Total cost of ownership","What a product costs across its whole life rather than to build once: maintenance, upgrades, annual OS and store migrations, and the second team you staff to keep two codebases in step. Usually larger than the build quote, and almost never inside it.",[1190,1191],"TCO","cost of ownership",[1193],{"kind":636,"url":1194},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FTotal_cost_of_ownership",[1029],"\u002Fglossary#total-cost-of-ownership",{"slug":1198,"term":1199,"definition":1200,"category":891,"aliases":1201,"links":1203,"related":1208,"readMore":-1,"target":1210,"hasArticle":613},"webrtc","WebRTC","The browser and mobile standard for sending audio, video and data directly between two devices, with servers involved only in introducing them to each other. It is what an in-app video call is built on when it is not a rented SDK.",[1202],"Web Real-Time Communication",[1204,1206],{"kind":608,"url":1205},"https:\u002F\u002Fwebrtc.org\u002F",{"kind":636,"url":1207},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FWebRTC",[1209,747],"xmpp","\u002Fglossary#webrtc",{"slug":747,"term":1212,"definition":1213,"category":891,"aliases":1214,"links":1215,"related":1218,"readMore":-1,"target":1219,"hasArticle":613},"WebSocket","A protocol that holds one connection open between client and server so either side can send at any moment, instead of the client asking over and over. What live prices, chat and presence indicators run on.",[],[1216],{"kind":636,"url":1217},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FWebSocket",[749,667],"\u002Fglossary#websocket",{"slug":764,"term":1221,"definition":1222,"category":868,"aliases":1223,"links":1226,"related":1229,"readMore":1230,"target":1230,"hasArticle":588},"White-label","One product shipped under many brands. A white-label mobile platform builds each client a store-ready app with its own name, design and content from a single shared codebase, instead of forking the project per customer.",[1224,1225],"white label","multi-tenant app",[1227],{"kind":636,"url":1228},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FWhite-label_product",[922],"\u002Fglossary\u002Fwhite-label",{"slug":1209,"term":1232,"definition":1233,"category":891,"aliases":1234,"links":1237,"related":1242,"readMore":-1,"target":1243,"hasArticle":613},"XMPP","An open, federated messaging protocol, and the long-standing alternative to writing a chat backend or renting one. It extends to presence, typing indicators and file transfer, and it is old enough that every platform has a mature client library.",[1235,1236],"Jabber","Extensible Messaging and Presence Protocol",[1238,1240],{"kind":608,"url":1239},"https:\u002F\u002Fxmpp.org\u002F",{"kind":636,"url":1241},"https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FXMPP",[1198,747],"\u002Fglossary#xmpp"]