ZenveusOrganization
Senior-led software engineering organized around three decision lanes: Fix it, Build it right, and Keep shipping.
Senior-led software engineering organized around three decision lanes: Fix it, Build it right, and Keep shipping.
Zenveus — published by Zenveus
- OFFERS Fix it
- OFFERS Build it right
- OFFERS Keep shipping
- OFFERS Production Readiness Standard
- OFFERS 48-Hour Production Readiness Verdict
- OFFERS Specialist audits
- OFFERS Security & Data Isolation Audit
- OFFERS Technical Due Diligence Readiness Audit
- OFFERS AI Cost & Reliability Audit
- OFFERS InsurTech Production Readiness Review
- OFFERS Healthcare Engineering Readiness Review
- OFFERS Zenveus Pod
- OFFERS InsurTech engineering
- OFFERS Healthcare engineering
- OFFERS Resources
- OFFERS Case studies
- DESCRIBED_BY Fix Library
Fix itService
For a working product you do not fully trust. Establish production readiness, then keep, repair, selectively replace, or rebuild based on evidence.
For a working product you do not fully trust. Establish production readiness, then keep, repair, selectively replace, or rebuild based on evidence.
Fix it — published by Zenveus
- DESCRIBED_BY Fix Library
Build it rightService
For a new product, major feature, or AI capability. Decide architecture, boundaries, critical workflows and acceptance evidence before implementation.
For a new product, major feature, or AI capability. Decide architecture, boundaries, critical workflows and acceptance evidence before implementation.
Build it right — published by Zenveus
Keep shippingService
For a live product and continuing roadmap. Retain product context with stable senior-led engineering capacity and accountable delivery.
For a live product and continuing roadmap. Retain product context with stable senior-led engineering capacity and accountable delivery.
Keep shipping — published by Zenveus
Production Readiness StandardMethodology
Zenveus-owned published engineering yardstick across nine production-readiness areas. An evidence-based aid, not legal or compliance certification.
Zenveus-owned published engineering yardstick across nine production-readiness areas. An evidence-based aid, not legal or compliance certification.
Production Readiness Standard — published by Zenveus
48-Hour Production Readiness VerdictService
For $299, a named senior engineer signs a written verdict against the Zenveus Production Readiness Standard after access and required evidence, with findings and a keep, repair, selectively replace, or rebuild recommendation.
For $299, a named senior engineer signs a written verdict against the Zenveus Production Readiness Standard after access and required evidence, with findings and a keep, repair, selectively replace, or rebuild recommendation.
48-Hour Production Readiness Verdict — published by Zenveus
Specialist auditsService
Focused security, technical diligence, AI cost and reliability, InsurTech, and healthcare engineering reviews.
Focused security, technical diligence, AI cost and reliability, InsurTech, and healthcare engineering reviews.
Specialist audits — published by Zenveus
Security & Data Isolation AuditService
Evidence across identity, permissions, tenant isolation, secrets, APIs, webhooks and storage.
Evidence across identity, permissions, tenant isolation, secrets, APIs, webhooks and storage.
Security & Data Isolation Audit — published by Zenveus
Technical Due Diligence Readiness AuditService
Evidence for investor, buyer, enterprise or CTO review across architecture, security, delivery, ownership and operations.
Evidence for investor, buyer, enterprise or CTO review across architecture, security, delivery, ownership and operations.
Technical Due Diligence Readiness Audit — published by Zenveus
AI Cost & Reliability AuditService
Workflow-level cost, routing, latency, retries, fallbacks, observability and evaluation.
Workflow-level cost, routing, latency, retries, fallbacks, observability and evaluation.
AI Cost & Reliability Audit — published by Zenveus
InsurTech Production Readiness ReviewService
Engineering evidence for insurance workflow integrity, data, permissions, documents, integrations and auditability. Not certification.
Engineering evidence for insurance workflow integrity, data, permissions, documents, integrations and auditability. Not certification.
InsurTech Production Readiness Review — published by Zenveus
Healthcare Engineering Readiness ReviewService
PHI boundaries, consent, roles, logging, retention, integrations and operational evidence. Not certification.
PHI boundaries, consent, roles, logging, retention, integrations and operational evidence. Not certification.
Healthcare Engineering Readiness Review — published by Zenveus
Zenveus PodService
The ongoing senior-led delivery model within Keep shipping, with engineering, QA, oversight and retained product context.
The ongoing senior-led delivery model within Keep shipping, with engineering, QA, oversight and retained product context.
Zenveus Pod — published by Zenveus
InsurTech engineeringService
Regulated insurance workflow engineering context and capabilities.
Regulated insurance workflow engineering context and capabilities.
InsurTech engineering — published by Zenveus
Healthcare engineeringService
Sensitive-data workflow engineering context and capabilities.
Sensitive-data workflow engineering context and capabilities.
Healthcare engineering — published by Zenveus
ResourcesTaxonomy
Free practical checks, calculators, guides and skills. Website-referred access may request email; search/direct discovery remains accessible.
Free practical checks, calculators, guides and skills. Website-referred access may request email; search/direct discovery remains accessible.
Resources — published by Zenveus
Case studiesTaxonomy
Delivered-system narratives organized around the operational constraint, engineering response and production evidence.
Delivered-system narratives organized around the operational constraint, engineering response and production evidence.
Case studies — published by Zenveus
Replit app works in preview but fails after deploymentConcept
Preview and the published app are separate environments. If preview works but production fails, compare the deployment type, run command, production secrets, database, and live request logs before changing application code.
Preview and the published app are separate environments. If preview works but production fails, compare the deployment type, run command, production secrets, database, and live request logs before changing application code.
Replit app works in preview but fails after deployment — published by Zenveus
- PART_OF Fix Library
Supabase “new row violates row-level security policy” errorConcept
The insert reached Postgres, but the active role did not satisfy an INSERT policy for the new row. Inspect the user session, table policy, and row values; do not solve this by turning RLS off.
The insert reached Postgres, but the active role did not satisfy an INSERT policy for the new row. Inspect the user session, table policy, and row values; do not solve this by turning RLS off.
Supabase “new row violates row-level security policy” error — published by Zenveus
- PART_OF Fix Library
Lovable app works in preview but not after publishingConcept
The generated interface is loading in Lovable’s preview context, but the published domain is exposing a different configuration, origin, authentication callback, or backend behavior. Diagnose the first live-only failed request before prompting Lovable to rebuild components.
The generated interface is loading in Lovable’s preview context, but the published domain is exposing a different configuration, origin, authentication callback, or backend behavior. Diagnose the first live-only failed request before prompting Lovable to rebuild components.
Lovable app works in preview but not after publishing — published by Zenveus
- PART_OF Fix Library
Lovable and Supabase login or signup not workingConcept
Authentication failures usually come from one of four boundaries: the browser never receives a session, the callback URL is not allowed, email/provider settings reject the request, or the app creates a session but fails on its first protected query.
Authentication failures usually come from one of four boundaries: the browser never receives a session, the callback URL is not allowed, email/provider settings reject the request, or the app creates a session but fails on its first protected query.
Lovable and Supabase login or signup not working — published by Zenveus
- PART_OF Fix Library
Replit deployment failed with a health check or port errorConcept
The deployment cannot reach a healthy HTTP server on the expected interface and port within its startup window. Confirm the app listens on 0.0.0.0, uses the assigned port, starts with the production command, and answers its health route quickly.
The deployment cannot reach a healthy HTTP server on the expected interface and port within its startup window. Confirm the app listens on 0.0.0.0, uses the assigned port, starts with the production command, and answers its health route quickly.
Replit deployment failed with a health check or port error — published by Zenveus
- PART_OF Fix Library
Supabase Storage 403 unauthorized or RLS upload errorConcept
The upload request reached Storage, but the authenticated role is not allowed to create the corresponding object row. Check the session, bucket and object path, and storage.objects policies; keep the bucket policy narrow instead of bypassing authorization.
The upload request reached Storage, but the authenticated role is not allowed to create the corresponding object row. Check the session, bucket and object path, and storage.objects policies; keep the bucket policy narrow instead of bypassing authorization.
Supabase Storage 403 unauthorized or RLS upload error — published by Zenveus
- PART_OF Fix Library
Lovable app shows a blank or white screenConcept
A blank screen usually means the HTML shell loaded but the client application failed before it rendered useful UI. Start with the first console exception and failed JavaScript or API request; do not redesign the page until the runtime error is isolated.
A blank screen usually means the HTML shell loaded but the client application failed before it rendered useful UI. Start with the first console exception and failed JavaScript or API request; do not redesign the page until the runtime error is isolated.
Lovable app shows a blank or white screen — published by Zenveus
- PART_OF Fix Library
Supabase returns an empty array although data existsConcept
An empty array often means the query succeeded but Row Level Security made every row invisible to the active role. Confirm the project and schema, then compare the session and SELECT policy against the rows you expect to see.
An empty array often means the query succeeded but Row Level Security made every row invisible to the active role. Confirm the project and schema, then compare the session and SELECT policy against the rows you expect to see.
Supabase returns an empty array although data exists — published by Zenveus
- PART_OF Fix Library
Replit app shows a blank or white screen after deploymentConcept
The deployment is serving a page, but the browser cannot boot or render the application. Capture the first console error, confirm the JavaScript and CSS assets load from the production base path, and test direct routes and production API configuration.
The deployment is serving a page, but the browser cannot boot or render the application. Capture the first console error, confirm the JavaScript and CSS assets load from the production base path, and test direct routes and production API configuration.
Replit app shows a blank or white screen after deployment — published by Zenveus
- PART_OF Fix Library
Lovable and Supabase data is not savingConcept
The UI may be optimistic even when the database write is rejected. Inspect the actual insert or update response, then verify the session, target table, payload ownership fields, and RLS policy instead of assuming the form submission succeeded.
The UI may be optimistic even when the database write is rejected. Inspect the actual insert or update response, then verify the session, target table, payload ownership fields, and RLS policy instead of assuming the form submission succeeded.
Lovable and Supabase data is not saving — published by Zenveus
- PART_OF Fix Library
Supabase OAuth redirects to localhost or the wrong URLConcept
Supabase uses the requested redirect only when it matches an allowed Redirect URL; otherwise the flow can fall back to the configured Site URL. Align the app’s redirectTo value, Supabase URL configuration, and the provider callback for the exact production origin.
Supabase uses the requested redirect only when it matches an allowed Redirect URL; otherwise the flow can fall back to the configured Site URL. Align the app’s redirectTo value, Supabase URL configuration, and the provider callback for the exact production origin.
Supabase OAuth redirects to localhost or the wrong URL — published by Zenveus
- PART_OF Fix Library
Lovable Edge Function returns a CORS or 500 errorConcept
CORS and 500 errors are different layers. A browser CORS failure means the response does not permit the origin or preflight; a 500 means the function executed and failed. Inspect the OPTIONS request, function logs, production secrets, and upstream response separately.
CORS and 500 errors are different layers. A browser CORS failure means the response does not permit the origin or preflight; a 500 means the function executed and failed. Inspect the OPTIONS request, function logs, production secrets, and upstream response separately.
Lovable Edge Function returns a CORS or 500 error — published by Zenveus
- PART_OF Fix Library
Base44 app shows a blank screen or does not loadConcept
First separate a Base44 service incident from a project-specific failure. If the platform is healthy, capture the first browser error, identify the last working version, and test authentication, integrations, and the failing page without stacking more AI-generated changes.
First separate a Base44 service incident from a project-specific failure. If the platform is healthy, capture the first browser error, identify the last working version, and test authentication, integrations, and the failing page without stacking more AI-generated changes.
Base44 app shows a blank screen or does not load — published by Zenveus
- PART_OF Fix Library
Claude Code MCP server failed to connectConcept
An MCP connection failure is usually a transport, command, working-directory, environment, authentication, or protocol-startup problem. Test the server command outside Claude Code, inspect MCP status and logs, and use configuration syntax that matches the installed Claude Code version.
An MCP connection failure is usually a transport, command, working-directory, environment, authentication, or protocol-startup problem. Test the server command outside Claude Code, inspect MCP status and logs, and use configuration syntax that matches the installed Claude Code version.
Claude Code MCP server failed to connect — published by Zenveus
- PART_OF Fix Library
Cursor codebase indexing is stuck or not workingConcept
Indexing can stall because the workspace is too broad, dominated by generated or binary files, unavailable through filesystem permissions, blocked by network or account state, or held by stale local index data. Preserve the project, narrow the workspace, inspect status, and rebuild the index only after excluding noise.
Indexing can stall because the workspace is too broad, dominated by generated or binary files, unavailable through filesystem permissions, blocked by network or account state, or held by stale local index data. Preserve the project, narrow the workspace, inspect status, and rebuild the index only after excluding noise.
Cursor codebase indexing is stuck or not working — published by Zenveus
- PART_OF Fix Library
Replit API routes work without login: how to fix missing authenticationConcept
Fix Replit API routes that accept anonymous or cross-user requests. Add server authentication, record ownership checks, and tests that prove access is denied.
If your Replit API returns private data or accepts a write without login, check the server route before changing the UI. Require a verified session before sensitive work, then constrain each record operation to the caller’s allowed role, owner, or tenant. Test anonymous and cross-user requests directly; hiding a button does not protect the API.
Replit API routes work without login: how to fix missing authentication — published by Zenveus
- PART_OF Fix Library
v0 Next.js API proxy fetches a user-supplied URL: how to fix the SSRF riskConcept
A Next.js proxy route that fetches a user-supplied URL can reach internal services. Check URL flow, redirects, DNS, headers, and server egress safely.
When a Next.js API route passes a caller-supplied URL straight to server-side `fetch`, the caller may be able to make the server contact destinations that their own browser cannot reach. Replace the arbitrary URL with a named, configured upstream action. Allow only required methods and headers, and enforce destination and egress checks before every outbound request.
v0 Next.js API proxy fetches a user-supplied URL: how to fix the SSRF risk — published by Zenveus
- PART_OF Fix Library
v0 AI API has no rate limit: prevent unexpected OpenAI or ElevenLabs costsConcept
Stop an uncapped public AI route from spending your server API key. Add input bounds, per-user quotas, concurrency limits, budgets, and abuse logs.
A server-held AI key can be charged every time a public chat or text-to-speech route calls the provider. Bound request size and model output, set per-user or session quotas, limit concurrency, enforce a budget before each provider call, and log usage without recording private prompt text. Authentication is appropriate when the feature is for account holders; a deliberately public demo still needs abuse controls.
v0 AI API has no rate limit: prevent unexpected OpenAI or ElevenLabs costs — published by Zenveus
- PART_OF Fix Library
Firebase Studio admin page is hidden, but are Firestore rules protecting the data?Concept
A client-side admin redirect does not prove Firestore data is protected. Test deployed rules with owner, ordinary-user, and admin identities.
An admin page that redirects non-admin users in React or Next.js only controls navigation. Firestore and Storage rules decide whether a direct client SDK request can read or change data. Retrieve the rules actually deployed, then test ordinary users, owners, and admins against the sensitive collections in the Firebase Emulator before declaring the data protected or exposed.
Firebase Studio admin page is hidden, but are Firestore rules protecting the data? — published by Zenveus
- PART_OF Fix Library
Replit app has a default admin password or session secret: what to fix firstConcept
Find fixed fallback admin credentials, weak session setup, and unguarded write routes in a Replit app. Fail startup safely and test every admin action.
A production app should fail startup when its required admin password or session secret is missing, instead of using a hard-coded fallback. Remove fixed defaults, rotate affected secrets, protect each admin read and write on the server, and regenerate the session after successful login. Test direct API requests because an admin login screen does not protect routes that never check the session.
Replit app has a default admin password or session secret: what to fix first — published by Zenveus
- PART_OF Fix Library
Claude Code web agent accepts anonymous runs: secure the agent API boundaryConcept
A web proxy can forward prompts to an agent with a server key even when no user session exists. Reject anonymous runs and bind conversations to users.
A server-held agent API key authenticates the web server to the agent service; it does not authorize the browser user. Reject a missing web session before saving messages or starting an agent run. Bind each conversation ID to the authenticated owner, limit which tools that user may invoke, and apply quotas and timeouts.
Claude Code web agent accepts anonymous runs: secure the agent API boundary — published by Zenveus
- PART_OF Fix Library
Cursor-built Puppeteer scraper accepts any URL: how to secure browser fetchingConcept
A user-supplied scraper URL can send a headless browser to internal services. Check redirects, subresources, DNS, protocols, and browser network isolation.
Parsing a URL only proves that it has valid syntax. A server-side Puppeteer browser may visit internal addresses, follow redirects, and load images, scripts, frames, or other subresources from additional hosts. Restrict destinations and protocols before navigation, inspect each browser request, and run the browser in a network-isolated environment with resource limits.
Cursor-built Puppeteer scraper accepts any URL: how to secure browser fetching — published by Zenveus
- PART_OF Fix Library
Next.js database URL exposed in the browser: what to do nowConcept
A `NEXT_PUBLIC_` database URL can enter the browser bundle. Find client imports, rotate exposed credentials, move queries server-side, and test access.
Treat a database connection string used through a `NEXT_PUBLIC_` variable in a Client Component as browser-visible. Stop direct browser database calls, move queries to a server route or server-only module, rotate the connection credential, and check what that credential could access. Changing the variable name alone does not remove a value from an already published JavaScript bundle.
Next.js database URL exposed in the browser: what to do now — published by Zenveus
- PART_OF Fix Library
Gemini API key exposed in frontend code: how to secure AI callsConcept
Client-side Gemini calls can reveal an API key and leave usage uncapped. Rotate the key, proxy AI calls through a protected server route, and cap spend.
If a client-side page constructs a Gemini provider client with a `NEXT_PUBLIC_` key, assume the key can be recovered from the browser build when configured. Move provider calls to a server route, rotate the exposed key, authorize the requesting user, and put request, concurrency, and spend limits before each provider call.
Gemini API key exposed in frontend code: how to secure AI calls — published by Zenveus
- PART_OF Fix Library
Stripe webhook signature verification failed in Express: check the raw bodyConcept
Fix Stripe's “No signatures found” error in Express. Verify the endpoint secret and preserve the raw body before JSON middleware parses it.
Stripe verifies the exact request bytes it sent. If `express.json()` parses the request before `stripe.webhooks.constructEvent()`, the handler no longer receives that raw payload and signature verification can fail. Mount the webhook with `express.raw({ type: 'application/json' })` before the general JSON parser, and use the endpoint's correct signing secret.
Stripe webhook signature verification failed in Express: check the raw body — published by Zenveus
- PART_OF Fix Library
Stripe payment succeeded, but the app still shows a free plan or locked itemConcept
When checkout succeeds but the app still shows a free plan or locked purchase, trace webhook delivery, signature, event processing, and database writes.
A checkout success page confirms a browser redirect, not that the app granted access. Trace the Stripe event through delivery, signature verification, event type, user mapping, database write, and the user's next read. Fix the first failing step; do not mark a purchase paid from a query string alone.
Stripe payment succeeded, but the app still shows a free plan or locked item — published by Zenveus
- PART_OF Fix Library
Stripe checkout price and app plan do not match: secure subscription tiersConcept
If a checkout route accepts both a client-selected Stripe price and plan name, bind entitlements to verified server-side price data before granting access.
Never grant a subscription tier merely because the browser supplied a plan name alongside a Stripe Price ID. Resolve the allowed price on the server, map it to one product tier, and verify the paid subscription or invoice before writing entitlements. Reject a price/plan combination the server did not define.
Stripe checkout price and app plan do not match: secure subscription tiers — published by Zenveus
- PART_OF Fix Library
Stripe subscription cancelled, but the app still shows paid accessConcept
Trace cancellation timing, `customer.subscription.deleted`, webhook delivery, and your local entitlement state when a cancelled user keeps paid access.
First distinguish a scheduled cancellation from an ended subscription. A cancellation set for period end may retain access until that date. When Stripe marks the subscription ended, your app must process the lifecycle event and update its own subscription and entitlement records. Verify both the Stripe state and the local state before revoking access.
Stripe subscription cancelled, but the app still shows paid access — published by Zenveus
- PART_OF Fix Library
DOCX preview renders unsafe HTML: secure uploaded Word documentsConcept
Converting an uploaded DOCX to HTML and injecting it into a page can create unsafe links or markup. Sanitize, isolate, and test the preview.
Treat HTML produced from an uploaded DOCX as untrusted content. A DOCX-to-HTML converter does not establish that links and markup are safe to inject into your application page. Sanitize the HTML with a narrow allowlist, restrict link protocols, and consider an isolated preview frame for documents from other users.
DOCX preview renders unsafe HTML: secure uploaded Word documents — published by Zenveus
- PART_OF Fix Library
Fix LibraryTaxonomy
Zenveus diagnostic guides for production failures in AI-built applications, including Lovable, Supabase, Replit, Base44, Next.js, Stripe, Firebase, APIs, keys, webhooks and deployment.
Find the production symptom, run the checks, apply a scoped repair, and verify the live path.
Fix Library — published by Zenveus
- COVERS Replit app works in preview but fails after deployment
- COVERS Supabase “new row violates row-level security policy” error
- COVERS Lovable app works in preview but not after publishing
- COVERS Lovable and Supabase login or signup not working
- COVERS Replit deployment failed with a health check or port error
- COVERS Supabase Storage 403 unauthorized or RLS upload error
- COVERS Lovable app shows a blank or white screen
- COVERS Supabase returns an empty array although data exists
- COVERS Replit app shows a blank or white screen after deployment
- COVERS Lovable and Supabase data is not saving
- COVERS Supabase OAuth redirects to localhost or the wrong URL
- COVERS Lovable Edge Function returns a CORS or 500 error
- COVERS Base44 app shows a blank screen or does not load
- COVERS Claude Code MCP server failed to connect
- COVERS Cursor codebase indexing is stuck or not working
- COVERS Replit API routes work without login: how to fix missing authentication
- COVERS v0 Next.js API proxy fetches a user-supplied URL: how to fix the SSRF risk
- COVERS v0 AI API has no rate limit: prevent unexpected OpenAI or ElevenLabs costs
- COVERS Firebase Studio admin page is hidden, but are Firestore rules protecting the data?
- COVERS Replit app has a default admin password or session secret: what to fix first
- COVERS Claude Code web agent accepts anonymous runs: secure the agent API boundary
- COVERS Cursor-built Puppeteer scraper accepts any URL: how to secure browser fetching
- COVERS Next.js database URL exposed in the browser: what to do now
- COVERS Gemini API key exposed in frontend code: how to secure AI calls
- COVERS Stripe webhook signature verification failed in Express: check the raw body
- COVERS Stripe payment succeeded, but the app still shows a free plan or locked item
- COVERS Stripe checkout price and app plan do not match: secure subscription tiers
- COVERS Stripe subscription cancelled, but the app still shows paid access
- COVERS DOCX preview renders unsafe HTML: secure uploaded Word documents
Row-Level Security AuditorSoftwareProduct
Check whether authenticated users can read or write rows outside their own access scope.
Check whether authenticated users can read or write rows outside their own access scope.
Row-Level Security Auditor — published by Zenveus
Production Readiness Self-CheckSoftwareProduct
Score a product against the nine areas in the Zenveus Production Readiness Standard.
Score a product against the nine areas in the Zenveus Production Readiness Standard.
Production Readiness Self-Check — published by Zenveus
Secret ScannerSoftwareProduct
Check client bundles and source for exposed credentials before release.
Check client bundles and source for exposed credentials before release.
Secret Scanner — published by Zenveus
Webhook Integrity CheckerSoftwareProduct
Check webhook signatures, replay handling, idempotency and event processing.
Check webhook signatures, replay handling, idempotency and event processing.
Webhook Integrity Checker — published by Zenveus
Pre-Deploy Checklist RunnerSoftwareProduct
Run a focused release check across configuration, tests, security and operations.
Run a focused release check across configuration, tests, security and operations.
Pre-Deploy Checklist Runner — published by Zenveus
Stack Cost at Scale CalculatorSoftwareProduct
Estimate cost exposure as usage, infrastructure and AI calls grow.
Estimate cost exposure as usage, infrastructure and AI calls grow.
Stack Cost at Scale Calculator — published by Zenveus
AI Agent Production Readiness AssessmentSoftwareProduct
Check agent boundaries, permissions, costs, evaluation and operational readiness.
Check agent boundaries, permissions, costs, evaluation and operational readiness.
AI Agent Production Readiness Assessment — published by Zenveus