Zenveus EntityMap

Published by Zenveus · generated 2026-09-29T18:22:47+00:00 · 54 entities · JSON entity graph

Current services, the Production Readiness Standard, production fixes and free tools. Canonical pages are the source of truth for changing offer details.

ZenveusOrganization

Senior-led software engineering organized around three decision lanes: Fix it, Build it right, and Keep shipping.

Senior-led software engineering organized around three decision lanes: Fix it, Build it right, and Keep shipping.

Zenveus — published by Zenveus

Fix itService

For a working product you do not fully trust. Establish production readiness, then keep, repair, selectively replace, or rebuild based on evidence.

For a working product you do not fully trust. Establish production readiness, then keep, repair, selectively replace, or rebuild based on evidence.

Fix it — published by Zenveus

Build it rightService

For a new product, major feature, or AI capability. Decide architecture, boundaries, critical workflows and acceptance evidence before implementation.

For a new product, major feature, or AI capability. Decide architecture, boundaries, critical workflows and acceptance evidence before implementation.

Build it right — published by Zenveus

Keep shippingService

For a live product and continuing roadmap. Retain product context with stable senior-led engineering capacity and accountable delivery.

For a live product and continuing roadmap. Retain product context with stable senior-led engineering capacity and accountable delivery.

Keep shipping — published by Zenveus

Production Readiness StandardMethodology

Zenveus-owned published engineering yardstick across nine production-readiness areas. An evidence-based aid, not legal or compliance certification.

Zenveus-owned published engineering yardstick across nine production-readiness areas. An evidence-based aid, not legal or compliance certification.

Production Readiness Standard — published by Zenveus

48-Hour Production Readiness VerdictService

For $299, a named senior engineer signs a written verdict against the Zenveus Production Readiness Standard after access and required evidence, with findings and a keep, repair, selectively replace, or rebuild recommendation.

For $299, a named senior engineer signs a written verdict against the Zenveus Production Readiness Standard after access and required evidence, with findings and a keep, repair, selectively replace, or rebuild recommendation.

48-Hour Production Readiness Verdict — published by Zenveus

Specialist auditsService

Focused security, technical diligence, AI cost and reliability, InsurTech, and healthcare engineering reviews.

Focused security, technical diligence, AI cost and reliability, InsurTech, and healthcare engineering reviews.

Specialist audits — published by Zenveus

Security & Data Isolation AuditService

Evidence across identity, permissions, tenant isolation, secrets, APIs, webhooks and storage.

Evidence across identity, permissions, tenant isolation, secrets, APIs, webhooks and storage.

Security & Data Isolation Audit — published by Zenveus

Technical Due Diligence Readiness AuditService

Evidence for investor, buyer, enterprise or CTO review across architecture, security, delivery, ownership and operations.

Evidence for investor, buyer, enterprise or CTO review across architecture, security, delivery, ownership and operations.

Technical Due Diligence Readiness Audit — published by Zenveus

AI Cost & Reliability AuditService

Workflow-level cost, routing, latency, retries, fallbacks, observability and evaluation.

Workflow-level cost, routing, latency, retries, fallbacks, observability and evaluation.

AI Cost & Reliability Audit — published by Zenveus

InsurTech Production Readiness ReviewService

Engineering evidence for insurance workflow integrity, data, permissions, documents, integrations and auditability. Not certification.

Engineering evidence for insurance workflow integrity, data, permissions, documents, integrations and auditability. Not certification.

InsurTech Production Readiness Review — published by Zenveus

Healthcare Engineering Readiness ReviewService

PHI boundaries, consent, roles, logging, retention, integrations and operational evidence. Not certification.

PHI boundaries, consent, roles, logging, retention, integrations and operational evidence. Not certification.

Healthcare Engineering Readiness Review — published by Zenveus

Zenveus PodService

The ongoing senior-led delivery model within Keep shipping, with engineering, QA, oversight and retained product context.

The ongoing senior-led delivery model within Keep shipping, with engineering, QA, oversight and retained product context.

Zenveus Pod — published by Zenveus

InsurTech engineeringService

Regulated insurance workflow engineering context and capabilities.

Regulated insurance workflow engineering context and capabilities.

InsurTech engineering — published by Zenveus

Healthcare engineeringService

Sensitive-data workflow engineering context and capabilities.

Sensitive-data workflow engineering context and capabilities.

Healthcare engineering — published by Zenveus

ResourcesTaxonomy

Free practical checks, calculators, guides and skills. Website-referred access may request email; search/direct discovery remains accessible.

Free practical checks, calculators, guides and skills. Website-referred access may request email; search/direct discovery remains accessible.

Resources — published by Zenveus

Case studiesTaxonomy

Delivered-system narratives organized around the operational constraint, engineering response and production evidence.

Delivered-system narratives organized around the operational constraint, engineering response and production evidence.

Case studies — published by Zenveus

Replit app works in preview but fails after deploymentConcept

Preview and the published app are separate environments. If preview works but production fails, compare the deployment type, run command, production secrets, database, and live request logs before changing application code.

Preview and the published app are separate environments. If preview works but production fails, compare the deployment type, run command, production secrets, database, and live request logs before changing application code.

Replit app works in preview but fails after deployment — published by Zenveus

Supabase “new row violates row-level security policy” errorConcept

The insert reached Postgres, but the active role did not satisfy an INSERT policy for the new row. Inspect the user session, table policy, and row values; do not solve this by turning RLS off.

The insert reached Postgres, but the active role did not satisfy an INSERT policy for the new row. Inspect the user session, table policy, and row values; do not solve this by turning RLS off.

Supabase “new row violates row-level security policy” error — published by Zenveus

Lovable app works in preview but not after publishingConcept

The generated interface is loading in Lovable’s preview context, but the published domain is exposing a different configuration, origin, authentication callback, or backend behavior. Diagnose the first live-only failed request before prompting Lovable to rebuild components.

The generated interface is loading in Lovable’s preview context, but the published domain is exposing a different configuration, origin, authentication callback, or backend behavior. Diagnose the first live-only failed request before prompting Lovable to rebuild components.

Lovable app works in preview but not after publishing — published by Zenveus

Lovable and Supabase login or signup not workingConcept

Authentication failures usually come from one of four boundaries: the browser never receives a session, the callback URL is not allowed, email/provider settings reject the request, or the app creates a session but fails on its first protected query.

Authentication failures usually come from one of four boundaries: the browser never receives a session, the callback URL is not allowed, email/provider settings reject the request, or the app creates a session but fails on its first protected query.

Lovable and Supabase login or signup not working — published by Zenveus

Replit deployment failed with a health check or port errorConcept

The deployment cannot reach a healthy HTTP server on the expected interface and port within its startup window. Confirm the app listens on 0.0.0.0, uses the assigned port, starts with the production command, and answers its health route quickly.

The deployment cannot reach a healthy HTTP server on the expected interface and port within its startup window. Confirm the app listens on 0.0.0.0, uses the assigned port, starts with the production command, and answers its health route quickly.

Replit deployment failed with a health check or port error — published by Zenveus

Supabase Storage 403 unauthorized or RLS upload errorConcept

The upload request reached Storage, but the authenticated role is not allowed to create the corresponding object row. Check the session, bucket and object path, and storage.objects policies; keep the bucket policy narrow instead of bypassing authorization.

The upload request reached Storage, but the authenticated role is not allowed to create the corresponding object row. Check the session, bucket and object path, and storage.objects policies; keep the bucket policy narrow instead of bypassing authorization.

Supabase Storage 403 unauthorized or RLS upload error — published by Zenveus

Lovable app shows a blank or white screenConcept

A blank screen usually means the HTML shell loaded but the client application failed before it rendered useful UI. Start with the first console exception and failed JavaScript or API request; do not redesign the page until the runtime error is isolated.

A blank screen usually means the HTML shell loaded but the client application failed before it rendered useful UI. Start with the first console exception and failed JavaScript or API request; do not redesign the page until the runtime error is isolated.

Lovable app shows a blank or white screen — published by Zenveus

Supabase returns an empty array although data existsConcept

An empty array often means the query succeeded but Row Level Security made every row invisible to the active role. Confirm the project and schema, then compare the session and SELECT policy against the rows you expect to see.

An empty array often means the query succeeded but Row Level Security made every row invisible to the active role. Confirm the project and schema, then compare the session and SELECT policy against the rows you expect to see.

Supabase returns an empty array although data exists — published by Zenveus

Replit app shows a blank or white screen after deploymentConcept

The deployment is serving a page, but the browser cannot boot or render the application. Capture the first console error, confirm the JavaScript and CSS assets load from the production base path, and test direct routes and production API configuration.

The deployment is serving a page, but the browser cannot boot or render the application. Capture the first console error, confirm the JavaScript and CSS assets load from the production base path, and test direct routes and production API configuration.

Replit app shows a blank or white screen after deployment — published by Zenveus

Lovable and Supabase data is not savingConcept

The UI may be optimistic even when the database write is rejected. Inspect the actual insert or update response, then verify the session, target table, payload ownership fields, and RLS policy instead of assuming the form submission succeeded.

The UI may be optimistic even when the database write is rejected. Inspect the actual insert or update response, then verify the session, target table, payload ownership fields, and RLS policy instead of assuming the form submission succeeded.

Lovable and Supabase data is not saving — published by Zenveus

Supabase OAuth redirects to localhost or the wrong URLConcept

Supabase uses the requested redirect only when it matches an allowed Redirect URL; otherwise the flow can fall back to the configured Site URL. Align the app’s redirectTo value, Supabase URL configuration, and the provider callback for the exact production origin.

Supabase uses the requested redirect only when it matches an allowed Redirect URL; otherwise the flow can fall back to the configured Site URL. Align the app’s redirectTo value, Supabase URL configuration, and the provider callback for the exact production origin.

Supabase OAuth redirects to localhost or the wrong URL — published by Zenveus

Lovable Edge Function returns a CORS or 500 errorConcept

CORS and 500 errors are different layers. A browser CORS failure means the response does not permit the origin or preflight; a 500 means the function executed and failed. Inspect the OPTIONS request, function logs, production secrets, and upstream response separately.

CORS and 500 errors are different layers. A browser CORS failure means the response does not permit the origin or preflight; a 500 means the function executed and failed. Inspect the OPTIONS request, function logs, production secrets, and upstream response separately.

Lovable Edge Function returns a CORS or 500 error — published by Zenveus

Base44 app shows a blank screen or does not loadConcept

First separate a Base44 service incident from a project-specific failure. If the platform is healthy, capture the first browser error, identify the last working version, and test authentication, integrations, and the failing page without stacking more AI-generated changes.

First separate a Base44 service incident from a project-specific failure. If the platform is healthy, capture the first browser error, identify the last working version, and test authentication, integrations, and the failing page without stacking more AI-generated changes.

Base44 app shows a blank screen or does not load — published by Zenveus

Claude Code MCP server failed to connectConcept

An MCP connection failure is usually a transport, command, working-directory, environment, authentication, or protocol-startup problem. Test the server command outside Claude Code, inspect MCP status and logs, and use configuration syntax that matches the installed Claude Code version.

An MCP connection failure is usually a transport, command, working-directory, environment, authentication, or protocol-startup problem. Test the server command outside Claude Code, inspect MCP status and logs, and use configuration syntax that matches the installed Claude Code version.

Claude Code MCP server failed to connect — published by Zenveus

Cursor codebase indexing is stuck or not workingConcept

Indexing can stall because the workspace is too broad, dominated by generated or binary files, unavailable through filesystem permissions, blocked by network or account state, or held by stale local index data. Preserve the project, narrow the workspace, inspect status, and rebuild the index only after excluding noise.

Indexing can stall because the workspace is too broad, dominated by generated or binary files, unavailable through filesystem permissions, blocked by network or account state, or held by stale local index data. Preserve the project, narrow the workspace, inspect status, and rebuild the index only after excluding noise.

Cursor codebase indexing is stuck or not working — published by Zenveus

Replit API routes work without login: how to fix missing authenticationConcept

Fix Replit API routes that accept anonymous or cross-user requests. Add server authentication, record ownership checks, and tests that prove access is denied.

If your Replit API returns private data or accepts a write without login, check the server route before changing the UI. Require a verified session before sensitive work, then constrain each record operation to the caller’s allowed role, owner, or tenant. Test anonymous and cross-user requests directly; hiding a button does not protect the API.

Replit API routes work without login: how to fix missing authentication — published by Zenveus

v0 Next.js API proxy fetches a user-supplied URL: how to fix the SSRF riskConcept

A Next.js proxy route that fetches a user-supplied URL can reach internal services. Check URL flow, redirects, DNS, headers, and server egress safely.

When a Next.js API route passes a caller-supplied URL straight to server-side `fetch`, the caller may be able to make the server contact destinations that their own browser cannot reach. Replace the arbitrary URL with a named, configured upstream action. Allow only required methods and headers, and enforce destination and egress checks before every outbound request.

v0 Next.js API proxy fetches a user-supplied URL: how to fix the SSRF risk — published by Zenveus

v0 AI API has no rate limit: prevent unexpected OpenAI or ElevenLabs costsConcept

Stop an uncapped public AI route from spending your server API key. Add input bounds, per-user quotas, concurrency limits, budgets, and abuse logs.

A server-held AI key can be charged every time a public chat or text-to-speech route calls the provider. Bound request size and model output, set per-user or session quotas, limit concurrency, enforce a budget before each provider call, and log usage without recording private prompt text. Authentication is appropriate when the feature is for account holders; a deliberately public demo still needs abuse controls.

v0 AI API has no rate limit: prevent unexpected OpenAI or ElevenLabs costs — published by Zenveus

Firebase Studio admin page is hidden, but are Firestore rules protecting the data?Concept

A client-side admin redirect does not prove Firestore data is protected. Test deployed rules with owner, ordinary-user, and admin identities.

An admin page that redirects non-admin users in React or Next.js only controls navigation. Firestore and Storage rules decide whether a direct client SDK request can read or change data. Retrieve the rules actually deployed, then test ordinary users, owners, and admins against the sensitive collections in the Firebase Emulator before declaring the data protected or exposed.

Firebase Studio admin page is hidden, but are Firestore rules protecting the data? — published by Zenveus

Replit app has a default admin password or session secret: what to fix firstConcept

Find fixed fallback admin credentials, weak session setup, and unguarded write routes in a Replit app. Fail startup safely and test every admin action.

A production app should fail startup when its required admin password or session secret is missing, instead of using a hard-coded fallback. Remove fixed defaults, rotate affected secrets, protect each admin read and write on the server, and regenerate the session after successful login. Test direct API requests because an admin login screen does not protect routes that never check the session.

Replit app has a default admin password or session secret: what to fix first — published by Zenveus

Claude Code web agent accepts anonymous runs: secure the agent API boundaryConcept

A web proxy can forward prompts to an agent with a server key even when no user session exists. Reject anonymous runs and bind conversations to users.

A server-held agent API key authenticates the web server to the agent service; it does not authorize the browser user. Reject a missing web session before saving messages or starting an agent run. Bind each conversation ID to the authenticated owner, limit which tools that user may invoke, and apply quotas and timeouts.

Claude Code web agent accepts anonymous runs: secure the agent API boundary — published by Zenveus

Cursor-built Puppeteer scraper accepts any URL: how to secure browser fetchingConcept

A user-supplied scraper URL can send a headless browser to internal services. Check redirects, subresources, DNS, protocols, and browser network isolation.

Parsing a URL only proves that it has valid syntax. A server-side Puppeteer browser may visit internal addresses, follow redirects, and load images, scripts, frames, or other subresources from additional hosts. Restrict destinations and protocols before navigation, inspect each browser request, and run the browser in a network-isolated environment with resource limits.

Cursor-built Puppeteer scraper accepts any URL: how to secure browser fetching — published by Zenveus

Next.js database URL exposed in the browser: what to do nowConcept

A `NEXT_PUBLIC_` database URL can enter the browser bundle. Find client imports, rotate exposed credentials, move queries server-side, and test access.

Treat a database connection string used through a `NEXT_PUBLIC_` variable in a Client Component as browser-visible. Stop direct browser database calls, move queries to a server route or server-only module, rotate the connection credential, and check what that credential could access. Changing the variable name alone does not remove a value from an already published JavaScript bundle.

Next.js database URL exposed in the browser: what to do now — published by Zenveus

Gemini API key exposed in frontend code: how to secure AI callsConcept

Client-side Gemini calls can reveal an API key and leave usage uncapped. Rotate the key, proxy AI calls through a protected server route, and cap spend.

If a client-side page constructs a Gemini provider client with a `NEXT_PUBLIC_` key, assume the key can be recovered from the browser build when configured. Move provider calls to a server route, rotate the exposed key, authorize the requesting user, and put request, concurrency, and spend limits before each provider call.

Gemini API key exposed in frontend code: how to secure AI calls — published by Zenveus

Stripe webhook signature verification failed in Express: check the raw bodyConcept

Fix Stripe's “No signatures found” error in Express. Verify the endpoint secret and preserve the raw body before JSON middleware parses it.

Stripe verifies the exact request bytes it sent. If `express.json()` parses the request before `stripe.webhooks.constructEvent()`, the handler no longer receives that raw payload and signature verification can fail. Mount the webhook with `express.raw({ type: 'application/json' })` before the general JSON parser, and use the endpoint's correct signing secret.

Stripe webhook signature verification failed in Express: check the raw body — published by Zenveus

Stripe payment succeeded, but the app still shows a free plan or locked itemConcept

When checkout succeeds but the app still shows a free plan or locked purchase, trace webhook delivery, signature, event processing, and database writes.

A checkout success page confirms a browser redirect, not that the app granted access. Trace the Stripe event through delivery, signature verification, event type, user mapping, database write, and the user's next read. Fix the first failing step; do not mark a purchase paid from a query string alone.

Stripe payment succeeded, but the app still shows a free plan or locked item — published by Zenveus

Stripe checkout price and app plan do not match: secure subscription tiersConcept

If a checkout route accepts both a client-selected Stripe price and plan name, bind entitlements to verified server-side price data before granting access.

Never grant a subscription tier merely because the browser supplied a plan name alongside a Stripe Price ID. Resolve the allowed price on the server, map it to one product tier, and verify the paid subscription or invoice before writing entitlements. Reject a price/plan combination the server did not define.

Stripe checkout price and app plan do not match: secure subscription tiers — published by Zenveus

Stripe subscription cancelled, but the app still shows paid accessConcept

Trace cancellation timing, `customer.subscription.deleted`, webhook delivery, and your local entitlement state when a cancelled user keeps paid access.

First distinguish a scheduled cancellation from an ended subscription. A cancellation set for period end may retain access until that date. When Stripe marks the subscription ended, your app must process the lifecycle event and update its own subscription and entitlement records. Verify both the Stripe state and the local state before revoking access.

Stripe subscription cancelled, but the app still shows paid access — published by Zenveus

DOCX preview renders unsafe HTML: secure uploaded Word documentsConcept

Converting an uploaded DOCX to HTML and injecting it into a page can create unsafe links or markup. Sanitize, isolate, and test the preview.

Treat HTML produced from an uploaded DOCX as untrusted content. A DOCX-to-HTML converter does not establish that links and markup are safe to inject into your application page. Sanitize the HTML with a narrow allowlist, restrict link protocols, and consider an isolated preview frame for documents from other users.

DOCX preview renders unsafe HTML: secure uploaded Word documents — published by Zenveus

Fix LibraryTaxonomy

Zenveus diagnostic guides for production failures in AI-built applications, including Lovable, Supabase, Replit, Base44, Next.js, Stripe, Firebase, APIs, keys, webhooks and deployment.

Find the production symptom, run the checks, apply a scoped repair, and verify the live path.

Fix Library — published by Zenveus

Row-Level Security AuditorSoftwareProduct

Check whether authenticated users can read or write rows outside their own access scope.

Check whether authenticated users can read or write rows outside their own access scope.

Row-Level Security Auditor — published by Zenveus

Production Readiness Self-CheckSoftwareProduct

Score a product against the nine areas in the Zenveus Production Readiness Standard.

Score a product against the nine areas in the Zenveus Production Readiness Standard.

Production Readiness Self-Check — published by Zenveus

Secret ScannerSoftwareProduct

Check client bundles and source for exposed credentials before release.

Check client bundles and source for exposed credentials before release.

Secret Scanner — published by Zenveus

Webhook Integrity CheckerSoftwareProduct

Check webhook signatures, replay handling, idempotency and event processing.

Check webhook signatures, replay handling, idempotency and event processing.

Webhook Integrity Checker — published by Zenveus

Pre-Deploy Checklist RunnerSoftwareProduct

Run a focused release check across configuration, tests, security and operations.

Run a focused release check across configuration, tests, security and operations.

Pre-Deploy Checklist Runner — published by Zenveus

Stack Cost at Scale CalculatorSoftwareProduct

Estimate cost exposure as usage, infrastructure and AI calls grow.

Estimate cost exposure as usage, infrastructure and AI calls grow.

Stack Cost at Scale Calculator — published by Zenveus

AI Agent Production Readiness AssessmentSoftwareProduct

Check agent boundaries, permissions, costs, evaluation and operational readiness.

Check agent boundaries, permissions, costs, evaluation and operational readiness.

AI Agent Production Readiness Assessment — published by Zenveus