Menu
Back to Case Studies

B2B SaaS ·Confidential, anonymized work sample

An AI-generated product that passed every demo, and would not have survived its first real users.

A founder built a full B2B SaaS application end to end with Claude Code and was about to launch it. It ran, it demoed well, and nobody on the team could say what would happen once live data, live payments and live users hit it.

Where this fits

Best for founders and product owners who shipped an AI-generated MVP that passes a demo and now need to know what happens when real users, real data and real payments hit it.

98 findings in 11,580 lines. Not one rated low.

  • 35 critical
  • 82 of 98 high or critical
  • 7 business days

What we did

  • Reviewed both the deployed build and the source at a fixed commit
  • Ranked all 98 findings by severity, each written as a business consequence
  • Traced every finding to a specific file and line, so it is a fix list
  • Delivered it navigable, so any engineer can work through it item by item

Result

The launch was postponed. The client kept us on to do the beta-readiness work, and the product went to beta after the critical findings were closed.

Severity summary from the delivered report. Client identity removed, findings unaltered.

The hard part

The difficulty is not finding bugs. AI-generated code compiles, passes its demo and reads like a finished product, so nothing looks wrong. The risk lives in what was never written: the authorization check that was skipped, the row-level policy that exists but permits everything, the migration with no way back. Reading a codebase for what is absent is a senior skill, and it is the one thing code generation cannot do for you.

Stack
Next.jsSupabasePostgreSQLTypeScript
Focus
AI-Generated CodeCode AuditSecurity ReviewProduction Readiness

Facing a similar problem?

Tell us where it stalls today, and we'll tell you how we would approach it.