Launch Blocker Check
Built an app with Lovable, Bolt, Replit, Cursor or Claude Code, and about to put real users or real money on it? Send me the repo. In 1 business day, I'll name up to 3 things that would stop a safe launch, where each one is and the first step to fix it, and walk you through them on a 20-minute call. It's $149, and it counts in full toward any fix you buy from me within 14 days.
I'm Bryce Watson. I spent more than a decade as a software engineer at eBay, and before that I worked on payments at hyperWALLET.
The short version
You send a repo link and a few lines about the app. I confirm it fits within 1 business day, and you pay $149. Once I have the code, I run the tools below, read the risky parts myself, and send you up to 3 launch blockers, most urgent first. Then we talk for 20 minutes. I don't touch your live app, I never need your keys, and I delete my copy of your code when the job ends.
Last updated October 9, 2026
1 What I run, with your OK
- Gitleaks or TruffleHog, over your whole git history. They find keys and passwords in the code, including ones you deleted that still sit in an older commit. TruffleHog can try each key it finds against the service to see if it works. I turn that off: I never use a key I find.
- Semgrep, with its free rules. It flags common code mistakes, like text from a web address landing in the page unescaped, or a query built from user input.
- Supabase Security Advisor. It lives in your Supabase dashboard, so you run it, not me. I'll tell you where to click. If you paste me the results, I'll tell you which ones matter for your app.
- My own reading, where launch blockers usually sit. The tools miss the problems I see most often in these apps: database rules that let one user read another's data, server functions that don't check who's calling, keys sent to the browser, prices or credits the browser gets to decide, and payments the app treats as confirmed before Stripe says so.
The tools run on my own computer. I also use AI coding tools (Claude Code and OpenAI Codex) to read code faster, the same as for a review, and they send the parts of your code they read to Anthropic and OpenAI to process it. Before I use them on your code, I check that their model-training controls are switched off. If you'd rather I didn't use them on your code, say so on the form and I'll do the check without them. Nothing else leaves my computer.
2 What you get back
- Up to 3 launch blockers, most urgent first. Each says where it is (file and line), what it means in plain words, and the first thing to do about it.
- A 20-minute call to walk through them, at a time we agree.
- If I find fewer than 3, or none, I say so, along with what I didn't check. The check reads your code for the problems most likely to stop a launch. It isn't the full Launch Review, and a clean result doesn't mean the app is secure.
- If a key looks exposed, I'll tell you to replace it. I can't tell you whether it still works, because I don't try it.
- If you want them fixed, I quote each fix at a fixed price, and the $149 comes off any fix you buy within 14 days (one credit per order; with Review + Fix, it comes off the part above the $400 review). If you don't, that's the end of it. I won't follow up with a sales pitch.
3 What I need from you
- The repo. Public on GitHub: just the link. Private: add me (BryceEWatson) to the repository. On a personal repository, GitHub gives every collaborator write access, not just read, so remove me when the job ends. In an organization, you can give me the Read role instead. Rather not add me? Email me a zip of the project, or a share link if it's over 25 MB. GitHub's Download ZIP leaves out the history, so I can't check it for deleted keys. If you zip the folder yourself, include the hidden
.gitfolder. - A few lines about the app: what it does, which tool you built it with, when you plan to launch, and anything you're worried about.
- Your OK: that it's your app, or you have the owner's permission, and I can run the tools above on it.
A test login helps but isn't required. Please don't send keys, passwords, .env files, database exports or customer data. I don't need any of them, and I won't ask.
4 What I never do
- I don't sign in to, probe or scan your live app. The check reads the code you sent, nothing else.
- I don't use, test or keep any key or password I find.
- I don't share what I find with anyone, and I don't publish anything that identifies you or your app without your written OK.
- Within 7 days of the job ending (14 days after I deliver, when the credit window closes), I delete my copy of your code. If I used Codex on it, Codex's shared history on my computer can keep parts of what it read.
It's the same standard I follow when I report a problem in someone else's public code: how I report security issues.
5 The check and the $400 review
The check is a focused first look. The $400 Launch Review is the full look, and Launch Review + Fix adds the top 3 fixes and a retest (all three on the main page).
| Compare | $149 check | $400 review |
|---|---|---|
| What I read | Your repo, with the tools above and my own reading of where launch blockers usually sit | All your code and settings, tested with logins you set up, across eight areas, from security to code health |
| You get | Up to 3 launch blockers, most urgent first, a first step for each, and a 20-minute call | A written report ranked Critical to Low, a clear answer on whether to launch, a fixed price for each fix, and a 30-minute call |
| When | 1 business day, once I have the code | 2 business days from our agreed start date, once I have the code and a test login |
| Cost | $149, which comes off any fix you buy within 14 days | $400, refunded in full if you tell me within 7 days of delivery that it wasn't worth it. The guarantee sets out the limits. |
You don't need the check before booking a review. See a sample review report →
6 Send your repo
- Send the form below. I reply within 1 business day from bryce@watsonstandardco.com to confirm it fits and when I can start.
- Pay $149 with the button below, by card or from a US bank account, through Stripe. It's a payment to bwatsnet LLC, my company.
- Add me to the repo, or send the zip. The business day starts once I have the code; if it arrives after noon US Pacific, it starts the next business day.
Thanks, it's on its way to me. I'll reply within 1 business day from bryce@watsonstandardco.com to confirm it fits. If your repo is private, you can add me as a collaborator now or wait for my reply.
Don't paste keys, passwords or customer data into this form. It goes to my inbox through the Web3Forms relay, I use it only to reply, and I don't share it.
Already confirmed? Pay the $149 here. If you pay before I've confirmed and your app isn't a fit, I refund it in full.
Pay $149