# Zenveus > Senior-led software engineering through three decision lanes: Fix it, Build it right, and Keep shipping. Current production context version: 2026-09-29. Canonical site: https://zenveus.com/ Live canonical pages are the source of truth for offer scope, prices, turnaround, availability and terms. Fetch them before quoting dynamic details. The Production Readiness Standard is Zenveus's owned engineering yardstick, not a certification. Case study outcomes are engagement-specific evidence, not guaranteed outcomes. ## Decision lanes - [Fix it](https://zenveus.com/fix-it/): For a working product you do not fully trust. Establish production readiness, then keep, repair, selectively replace, or rebuild based on evidence. - [Build it right](https://zenveus.com/build-it-right/): For a new product, major feature, or AI capability. Decide architecture, boundaries, critical workflows and acceptance evidence before implementation. - [Keep shipping](https://zenveus.com/keep-shipping/): For a live product and continuing roadmap. Retain product context with stable senior-led engineering capacity and accountable delivery. ## Owned standard and audit offers - [Production Readiness Standard](https://zenveus.com/resources/production-readiness-standard/): Zenveus-owned published engineering yardstick across nine production-readiness areas. An evidence-based aid, not legal or compliance certification. - [48-Hour Production Readiness Verdict](https://zenveus.com/audit/48-hour-verdict/): For $299, a named senior engineer signs a written verdict against the Zenveus Production Readiness Standard after access and required evidence, with findings and a keep, repair, selectively replace, or rebuild recommendation. - [Specialist audits](https://zenveus.com/audits/): Focused security, technical diligence, AI cost and reliability, InsurTech, and healthcare engineering reviews. - [Security & Data Isolation Audit](https://zenveus.com/audits/security/): Evidence across identity, permissions, tenant isolation, secrets, APIs, webhooks and storage. - [Technical Due Diligence Readiness Audit](https://zenveus.com/audits/technical-diligence/): Evidence for investor, buyer, enterprise or CTO review across architecture, security, delivery, ownership and operations. - [AI Cost & Reliability Audit](https://zenveus.com/audits/ai-cost-reliability/): Workflow-level cost, routing, latency, retries, fallbacks, observability and evaluation. - [InsurTech Production Readiness Review](https://zenveus.com/audits/insurtech/): Engineering evidence for insurance workflow integrity, data, permissions, documents, integrations and auditability. Not certification. - [Healthcare Engineering Readiness Review](https://zenveus.com/audits/healthcare/): PHI boundaries, consent, roles, logging, retention, integrations and operational evidence. Not certification. - [Zenveus Pod](https://zenveus.com/solutions/zenveus-pod/): The ongoing senior-led delivery model within Keep shipping, with engineering, QA, oversight and retained product context. ## Domain context and practical resources - [InsurTech engineering](https://zenveus.com/industries/insurtech/): Regulated insurance workflow engineering context and capabilities. - [Healthcare engineering](https://zenveus.com/industries/healthcare/): Sensitive-data workflow engineering context and capabilities. - [Resources](https://zenveus.com/resources/): Free practical checks, calculators, guides and skills. Website-referred access may request email; search/direct discovery remains accessible. - [Case studies](https://zenveus.com/case-studies/): Delivered-system narratives organized around the operational constraint, engineering response and production evidence. ## Production evidence SLA Deadline Watchdog is citable delivered-system evidence: SLA breaches fell from 14% to under 5.5%. This is not a promised result for another engagement. - [Enterprise analytics inside the customer cloud: answers to dashboards in under 60 seconds](https://zenveus.com/case-studies/natural-language-enterprise-analytics/) - [AI sales automation rebuilt for reliability: 80+ qualified leads a day](https://zenveus.com/case-studies/reliable-ai-sales-automation/) - [Athlete readiness unified across four data sources and three performance programs](https://zenveus.com/case-studies/athlete-readiness-data-platform/) - [Vehicle photos transformed into consistent listing assets without studio shoots](https://zenveus.com/case-studies/ai-vehicle-image-workflow/) - [Manual robotics rollouts turned into repeatable factory deployments](https://zenveus.com/case-studies/repeatable-robotics-factory-deployments/) - [Legal catalog commerce rebuilt for reliable discovery, checkout, and CRM operations](https://zenveus.com/case-studies/legal-publishing-commerce-modernization/) - [Hospitality booking operations rebuilt to prevent duplicate reservations](https://zenveus.com/case-studies/hospitality-booking-operations/) - [One multi-site CMS replaced fragmented client website operations](https://zenveus.com/case-studies/multi-site-cms-platform/) - [35,643 regulatory rules made searchable with cited AI answers](https://zenveus.com/case-studies/regulatory-intelligence-platform/) - [A fragmented wellness library turned into a connected subscription knowledge platform](https://zenveus.com/case-studies/structured-wellness-knowledge-platform/) - [A global clinic patient journey connected from inquiry through payment](https://zenveus.com/case-studies/clinic-patient-journey-platform/) - [An equipment rental marketplace connected discovery, availability, payments, and returns](https://zenveus.com/case-studies/equipment-rental-marketplace/) - [Insurance renewal automation cut lapse rates from 11.4% to 4.1%](https://zenveus.com/case-studies/insurance-renewal-automation/) - [A compliance prototype became an auditable financial-crime investigation system](https://zenveus.com/case-studies/auditable-financial-crime-investigations/) - [AI-assisted legal document review delivered 75% faster processing](https://zenveus.com/case-studies/ai-legal-document-review/) - [A no-code nonprofit product rebuilt for multi-tenant web and mobile growth](https://zenveus.com/case-studies/multi-tenant-nonprofit-platform/) - [A compensation dashboard moved from mock logic to production calculations](https://zenveus.com/case-studies/production-compensation-platform/) - [A polished ad-credit prototype became a secure real-money platform](https://zenveus.com/case-studies/production-ad-credit-platform/) - [Commercial insurance onboarding unified forms, underwriting, documents, and broker work](https://zenveus.com/case-studies/commercial-insurance-broker-platform/) - [Professional-services handoffs connected from opportunity through invoice](https://zenveus.com/case-studies/professional-services-operations-platform/) - [Proactive SLA automation reduced breach rates below 5.5%](https://zenveus.com/case-studies/sla-deadline-automation/) - [Clinical documentation automation reduced note burden and strengthened audit readiness](https://zenveus.com/case-studies/ai-clinical-documentation-workflow/) - [Private legal documents became a secure conversational research system](https://zenveus.com/case-studies/private-legal-research-platform/) - [Voice AI coaching made interview preparation 75% more efficient](https://zenveus.com/case-studies/voice-ai-interview-coaching/) ## Production Fix Library - [Fix Library](https://zenveus.com/fix/): Browse the published symptom-specific repair guides. - [Fix It](https://zenveus.com/fix-it/): Production repair services and the route from diagnosis to a bounded fix. - [48-Hour Verdict](https://zenveus.com/audit/48-hour-verdict/): A senior engineer reviews the code against the nine checks; consult the live page for current price and terms. ### Replit - [Replit app works in preview but fails after deployment](https://zenveus.com/fix/replit-preview-works-deployment-fails/): Preview and the published app are separate environments. If preview works but production fails, compare the deployment type, run command, production secrets, database, and live request logs before changing application code. - [Replit deployment failed with a health check or port error](https://zenveus.com/fix/replit-deployment-health-check-port/): The deployment cannot reach a healthy HTTP server on the expected interface and port within its startup window. Confirm the app listens on 0.0.0.0, uses the assigned port, starts with the production command, and answers its health route quickly. - [Replit app shows a blank or white screen after deployment](https://zenveus.com/fix/replit-white-screen-after-deployment/): The deployment is serving a page, but the browser cannot boot or render the application. Capture the first console error, confirm the JavaScript and CSS assets load from the production base path, and test direct routes and production API configuration. - [Replit API routes work without login: how to fix missing authentication](https://zenveus.com/fix/replit-api-no-auth/): Fix Replit API routes that accept anonymous or cross-user requests. Add server authentication, record ownership checks, and tests that prove access is denied. - [Replit app has a default admin password or session secret: what to fix first](https://zenveus.com/fix/replit-admin-default-password-session-secret/): Find fixed fallback admin credentials, weak session setup, and unguarded write routes in a Replit app. Fail startup safely and test every admin action. ### Supabase - [Supabase “new row violates row-level security policy” error](https://zenveus.com/fix/supabase-new-row-violates-rls-policy/): The insert reached Postgres, but the active role did not satisfy an INSERT policy for the new row. Inspect the user session, table policy, and row values; do not solve this by turning RLS off. - [Supabase Storage 403 unauthorized or RLS upload error](https://zenveus.com/fix/supabase-storage-403-rls-upload/): The upload request reached Storage, but the authenticated role is not allowed to create the corresponding object row. Check the session, bucket and object path, and storage.objects policies; keep the bucket policy narrow instead of bypassing authorization. - [Supabase returns an empty array although data exists](https://zenveus.com/fix/supabase-empty-array-rls/): An empty array often means the query succeeded but Row Level Security made every row invisible to the active role. Confirm the project and schema, then compare the session and SELECT policy against the rows you expect to see. - [Supabase OAuth redirects to localhost or the wrong URL](https://zenveus.com/fix/supabase-oauth-wrong-redirect-url/): Supabase uses the requested redirect only when it matches an allowed Redirect URL; otherwise the flow can fall back to the configured Site URL. Align the app’s redirectTo value, Supabase URL configuration, and the provider callback for the exact production origin. ### Lovable - [Lovable app works in preview but not after publishing](https://zenveus.com/fix/lovable-preview-works-live-site-fails/): The generated interface is loading in Lovable’s preview context, but the published domain is exposing a different configuration, origin, authentication callback, or backend behavior. Diagnose the first live-only failed request before prompting Lovable to rebuild components. - [Lovable and Supabase login or signup not working](https://zenveus.com/fix/lovable-supabase-auth-login/): Authentication failures usually come from one of four boundaries: the browser never receives a session, the callback URL is not allowed, email/provider settings reject the request, or the app creates a session but fails on its first protected query. - [Lovable app shows a blank or white screen](https://zenveus.com/fix/lovable-blank-white-screen/): A blank screen usually means the HTML shell loaded but the client application failed before it rendered useful UI. Start with the first console exception and failed JavaScript or API request; do not redesign the page until the runtime error is isolated. - [Lovable and Supabase data is not saving](https://zenveus.com/fix/lovable-supabase-data-not-saving/): The UI may be optimistic even when the database write is rejected. Inspect the actual insert or update response, then verify the session, target table, payload ownership fields, and RLS policy instead of assuming the form submission succeeded. - [Lovable Edge Function returns a CORS or 500 error](https://zenveus.com/fix/lovable-edge-function-cors-500/): CORS and 500 errors are different layers. A browser CORS failure means the response does not permit the origin or preflight; a 500 means the function executed and failed. Inspect the OPTIONS request, function logs, production secrets, and upstream response separately. ### Other builders, deployment, and document security - [Base44 app shows a blank screen or does not load](https://zenveus.com/fix/base44-blank-screen-not-loading/): First separate a Base44 service incident from a project-specific failure. If the platform is healthy, capture the first browser error, identify the last working version, and test authentication, integrations, and the failing page without stacking more AI-generated changes. - [Claude Code MCP server failed to connect](https://zenveus.com/fix/claude-code-mcp-server-connection/): An MCP connection failure is usually a transport, command, working-directory, environment, authentication, or protocol-startup problem. Test the server command outside Claude Code, inspect MCP status and logs, and use configuration syntax that matches the installed Claude Code version. - [Cursor codebase indexing is stuck or not working](https://zenveus.com/fix/cursor-codebase-indexing-stuck/): Indexing can stall because the workspace is too broad, dominated by generated or binary files, unavailable through filesystem permissions, blocked by network or account state, or held by stale local index data. Preserve the project, narrow the workspace, inspect status, and rebuild the index only after excluding noise. - [v0 AI API has no rate limit: prevent unexpected OpenAI or ElevenLabs costs](https://zenveus.com/fix/v0-ai-api-usage-limits/): Stop an uncapped public AI route from spending your server API key. Add input bounds, per-user quotas, concurrency limits, budgets, and abuse logs. - [Firebase Studio admin page is hidden, but are Firestore rules protecting the data?](https://zenveus.com/fix/firebase-studio-firestore-admin-rules/): A client-side admin redirect does not prove Firestore data is protected. Test deployed rules with owner, ordinary-user, and admin identities. - [Claude Code web agent accepts anonymous runs: secure the agent API boundary](https://zenveus.com/fix/claude-code-web-agent-api-auth/): A web proxy can forward prompts to an agent with a server key even when no user session exists. Reject anonymous runs and bind conversations to users. - [DOCX preview renders unsafe HTML: secure uploaded Word documents](https://zenveus.com/fix/docx-preview-unsanitized-html/): Converting an uploaded DOCX to HTML and injecting it into a page can create unsafe links or markup. Sanitize, isolate, and test the preview. ### Server-side fetching and SSRF - [v0 Next.js API proxy fetches a user-supplied URL: how to fix the SSRF risk](https://zenveus.com/fix/v0-nextjs-api-proxy-ssrf/): A Next.js proxy route that fetches a user-supplied URL can reach internal services. Check URL flow, redirects, DNS, headers, and server egress safely. - [Cursor-built Puppeteer scraper accepts any URL: how to secure browser fetching](https://zenveus.com/fix/cursor-puppeteer-scraper-ssrf/): A user-supplied scraper URL can send a headless browser to internal services. Check redirects, subresources, DNS, protocols, and browser network isolation. ### Exposed keys and connection strings - [Next.js database URL exposed in the browser: what to do now](https://zenveus.com/fix/nextjs-public-database-url-exposed/): A `NEXT_PUBLIC_` database URL can enter the browser bundle. Find client imports, rotate exposed credentials, move queries server-side, and test access. - [Gemini API key exposed in frontend code: how to secure AI calls](https://zenveus.com/fix/gemini-api-key-exposed-frontend/): Client-side Gemini calls can reveal an API key and leave usage uncapped. Rotate the key, proxy AI calls through a protected server route, and cap spend. ### Stripe payments and subscriptions - [Stripe webhook signature verification failed in Express: check the raw body](https://zenveus.com/fix/stripe-webhook-signature-verification-failed-express/): Fix Stripe's “No signatures found” error in Express. Verify the endpoint secret and preserve the raw body before JSON middleware parses it. - [Stripe payment succeeded, but the app still shows a free plan or locked item](https://zenveus.com/fix/stripe-payment-successful-access-not-updated/): When checkout succeeds but the app still shows a free plan or locked purchase, trace webhook delivery, signature, event processing, and database writes. - [Stripe checkout price and app plan do not match: secure subscription tiers](https://zenveus.com/fix/stripe-checkout-price-plan-mismatch/): If a checkout route accepts both a client-selected Stripe price and plan name, bind entitlements to verified server-side price data before granting access. - [Stripe subscription cancelled, but the app still shows paid access](https://zenveus.com/fix/stripe-subscription-cancelled-access-still-active/): Trace cancellation timing, `customer.subscription.deleted`, webhook delivery, and your local entitlement state when a cancelled user keeps paid access. ## Free production checks - [Row-Level Security Auditor](https://zenveus.com/resources/row-level-security-auditor/): Check whether authenticated users can read or write rows outside their own access scope. - [Production Readiness Self-Check](https://zenveus.com/resources/production-readiness-self-check/): Score a product against the nine areas in the Zenveus Production Readiness Standard. - [Secret Scanner](https://zenveus.com/resources/secret-scanner/): Check client bundles and source for exposed credentials before release. - [Webhook Integrity Checker](https://zenveus.com/resources/webhook-integrity-checker/): Check webhook signatures, replay handling, idempotency and event processing. - [Pre-Deploy Checklist Runner](https://zenveus.com/resources/pre-deploy-checklist-runner/): Run a focused release check across configuration, tests, security and operations. - [Stack Cost at Scale Calculator](https://zenveus.com/resources/stack-cost-at-scale-calculator/): Estimate cost exposure as usage, infrastructure and AI calls grow. - [AI Agent Production Readiness Assessment](https://zenveus.com/resources/ai-agent-production-readiness-assessment/): Check agent boundaries, permissions, costs, evaluation and operational readiness. ## Machine-readable discovery - [Full canonical-page context](https://zenveus.com/llms-full.txt) - [Entity graph](https://zenveus.com/entitymap.json) - [Human-readable entity map](https://zenveus.com/entitymap.html) - [Agent discovery manifest](https://zenveus.com/.well-known/agents.json) - [XML sitemap](https://zenveus.com/sitemap.xml)