The situation
A ride-hailing platform was getting ready to go live. Ride-hailing handles exactly the kind of data you least want to leak: who people are, how to reach them, and where they go.
This was a separate engagement from my seven years or so in cybersecurity SaaS, and the client stays anonymous. The job was simple to say and hard to do: find out whether it was safe to launch, before any real user trusted it with their data.
What I did
A security and launch-readiness audit before go-live. I went through the platform looking for anything that could hurt its users or the business on day one.
Every finding was ranked by severity. The ones that had to be fixed before launch, whatever else happened, were called out as launch blockers, so it was clear where to start.
The result
- findings: 2 critical and 30 high
- 152findings: 2 critical and 30 high
- launch blockers resolved before any real user data was exposed
- 8 of 8launch blockers resolved before any real user data was exposed
A long list is not a verdict on the team that built the product. What matters is knowing which items can wait and which cannot, and fixing the second kind before launch day rather than after the first incident.
What it means for you
If you built quickly, with an agency, freelancers or AI tools, that was a sensible way to get here. Speed is how you find out whether an idea has legs. The next step is finding out what needs fixing before real users find it for you.
That is what a fixed-price Product Review before launch is for: findings ranked by severity, launch blockers called out, and a costed plan for what to fix first.