Skip to content
Thorfyn

Software house · Brazil

Your software, built in the open and run from your own panel.

Any software, from the first thousand users to the first million.

Start a project

hello@thorfyn.com · The reply comes from someone who would build it.

Built with

  • Next.js
  • React
  • TypeScript
  • Node.js
  • PostgreSQL
  • Supabase
  • Docker
  • Vercel
  • Stripe

One panel, two modes

Follow the build and the production from one place.

Panel
Example · Norte Store

You are looking at Norte Store, a fictional store. This site's own numbers come in here, tile by tile, from the first measurement.

Cycle 3

6/ 10

day 6 of 10

Milestones3

  • DonePix checkout
  • In progressMerchant dashboard
  • NextDelivery app

Shipped14 days

15merges that reached production

Sep 28Oct 11

Requests5

  • To do1
    • Export orders as CSVNS-152
  • Doing1
    • Date filter on the dashboardNS-149
  • In review1
    • Coupons with an expiry dateNS-150
  • Done2
    • Partial refundNS-148
    • Receipt by emailNS-147

Deliveries3

  • NS-148-partial-refundPublished#212 · 09:56 · by @marina · commits @rafa
  • NS-150-coupon-expiryIn preview#214 · 11:56 · by @rafa
  • NS-149-date-filterBuilding#215 · 13:56 · by @marina

Authorship read from GitHub: 3 deliveries by @marina, @rafa.

Latest requestNS-148

Partial refund

1 d 1 hfrom request to production

  • Fictional product · illustrative numbers

From a thousand users to a million

Pick a product and move up a stage. Each step shows what enters the architecture and what it asks of the team.

  1. Launch

    One app and one database, shipped fast, with previews from day one.

  2. Grow

    A CDN and a queue take load off the app; the team gets a design and QA rhythm.

  3. Scale

    Cache and read replicas, a DevOps owner, and cost per user on the panel.

  4. Operate at scale

    Several regions, observability and an SRE on call: the product stays up while it grows.

A starting shape; discovery confirms it.

Architecture

RegionsUsersCDNAppCacheQueueDatabaseRead replicasObservability

What arrives, week by week

Example

An example with an invented product: one discovery week and a stage of 4 weeks. The real schedule comes from the plan, which closes in the first week.

  1. Week 1The plan, closed
  2. Week 2Sign-in by link
  3. Week 3Calendar and bookings
  4. Week 4Paymentdepends on you
  5. Week 5List of the day and release
Week 1

The plan, closed

Each item is checkable, and the price is one value.

  • Scope
  • Architecture
  • Schedule
  • Fixed price
  • Risks
  • What stays out

Build stage, from6,000USD

Weeks 2 to 4

A preview for each delivery

Each delivery gets an address of its own, so you can click through it before anything goes live.

preview.your-product.app

  • Sign-in by linkready
  • Calendar and bookingsready
  • Paymentwaits for you

What depends on you is shown with the week.

Week 5Waiting for you

You approve, we publish

Delivery ready for production

List of the day and release. Tests and build passed.

You confirm on your own device.

Demonstration, nothing is published.

From an AI-built prototype to production

Real users arrived and the builder stopped helping. We take it to production, in your accounts.

Built inLovableBoltv0Bubble

  1. Diagnosis

    2,400USD, one week paid

    One week on the code you have. A written report, one recommendation.

  2. You choose

    Harden or rebuild. The decision is yours.

  3. The work

    Each delivery has a preview; publishing waits for your approval.

  4. In your accounts

    Repository and cloud in your name. You leave whenever you want.

Why the diagnosis starts with access rules: CVE-2025-48757 records apps generated by an AI builder whose database tables could be read and written without signing in. The record at NVD

Send us your app

A link to the app is enough to start. Read access to the repository helps, if there is one.

The full path, step by step
diagnosis · your-appDemo data

A one-week report

What the diagnosis hands you

findings
6
days of work, in the example
8.5
recommended path
Harden
  • What we saw.
    The public API returns the customer list with no credential.
    Effect.
    Anyone downloads the personal data of every customer.
    Fix.
    Turn on row-level access rules and test with and without signing in.
  • What we saw.
    The key appears in the bundle the browser downloads.
    Effect.
    Anyone who opens the inspector can use the payments account.
    Fix.
    Replace the key and move the call to the server.
  • What we saw.
    Every change from the generator goes live at once.
    Effect.
    A generator mistake takes the app down for every customer.
    Fix.
    A test environment, minimal tests and an approval before production.
Recommended path. The choice is yours.

In the diagnosis we only read the code. Nothing changes in your app.

Read the full sample reportSix findings, one recommendation

How we work

Your code, your accounts, our hours, and what happens before every release.

Your hours, ours, and what that leaves

Our workday runs 09:00 to 18:00 in Brazil. Pick where you are and see how much of it lands inside your day.

Hours we share
8 hours
Hours we cover alone
1 hour

Before every release

  • Every change is tested
  • You see it before it is published
  • You know whether it is up
  • Screens that match each other
deploy · your-product
git push origin checkout-redesignlint ............ oktypecheck ....... oktests ........... okbuild ........... okpreview ......... pr-148.preview.appproduction ...... waiting for your approval

What if something drifts from the agreement?

Five rules that hold at every stage.

  • Half only when it runs in production

    Half when the stage is signed, half when it runs live.

  • A scope change only with your approval

    A new deadline and a new price enter when you approve, never before.

  • Nothing goes live without your approval

    Every delivery has a preview, and publishing waits for your approval.

  • Everything stays on record

    The activity only adds lines; what was approved is not rewritten.

    How security works
  • You leave whenever you want

    The exit package goes with the project from day one.

    Read about the exit package

What it costs, and how you pay

Five steps, from a one-day triage to a monthly operation, each with its price here. The rest of the page says how the payment is split.

Price ladder

  • Prototype triage

    An app generated in Lovable, Bolt or v0 that is about to get real users or take real payments.

    One day reading sign-in, exposed data, secrets and payment, ending in a written verdict: launch, fix first or rebuild.

    One day

    Take the audit or the discovery week within 14 days and the triage fee is credited in full.

    390USD, fixed price
  • Audit

    A product already running that is slow, costs too much per user or is hard to change.

    A written report: what is slow or costly, what it takes to fix, and in what order.

    Two to three days

    Fix what the report names, or take the discovery week for a bigger change.

    1,200USD, fixed price
  • Discovery week

    A new product, or a rebuild, that needs a plan before it needs code.

    See a sample plan

    Five days that end in the written stage plan: what ships, by when, for how much. If you stop there, the plan is yours and nothing else is owed.

    One week

    Sign the first stage, and the discovery week is credited in full against its price.

    2,400USD, one week paid
  • Stage project

    The product the plan describes, built one signed stage at a time.

    A working stage in production, in your repository and your accounts.

    Two to eight weeks per stage

    Sign the next stage, or move to monthly operation once it is live.

    from6,000USD per stage
  • Monthly operation

    A live product that has to evolve, stay up and cost less per user.

    One engineer who owns a product area: releases, incidents, cost and load.

    Month to month

    Thirty days notice ends it, and the repository is already yours.

    from1,500USD per month

Pay withWisePixPayPalTetherWire

Invoices come from a Brazilian company, in USD, EUR or BRL, with the tax documents your accounting will ask for.

Questions before you hire us

Seven questions that arrive by email every time.

How much does it cost to start?

The discovery week costs 2,400 USD and ends in the written stage plan: what ships, by when, for how much. If you stop there, the plan is yours.

How long does a first stage take?

Most ship in two to eight weeks. The discovery week puts a number on yours before you commit to it.

What happens if I stop?

You keep everything, because none of it was held anywhere else. A monthly operation ends on thirty days notice; a project ends at the close of the stage that was signed.

Who writes the code?

The person who answers your email. The work is not handed to a bench you never meet, which is also why one operation slot is open at a time.

What happens to the infrastructure?

It runs in your cloud accounts from the first week, on standard, open tools. We hold access, not ownership, and revoking it takes one afternoon.

Can you take over an app built with Lovable, Bolt or Bubble?

Yes. It starts with the same discovery week, applied to what already exists: we read the code and the data, and the plan says whether to harden it or rebuild it. Either way it ends up in your repository and your accounts.

Do you work with teams in the US and Europe?

Yes, async. Our workday runs 09:00 to 18:00 in Brazil, and the hours section shows how much of it lands inside yours. Invoices go out in USD, EUR or BRL.

Tell us where you are.

One email is enough. Say what exists today, what should exist, and when.

One operation slot open for the next cycle

What happens after you write

  1. 1 business dayA written reply
  2. within 3 daysA 30-minute call
  3. 5 business daysThe written stage plan
Prefer to talk? Book 30 minutes

No account. The time shows in your browser's time zone.

Two or three lines are enough. Links help.

We use your email and message only to reply and, if you ask, to propose. We send a confirmation and, if there is no answer, two reminders, each with a link to stop. Messages are deleted after twelve months. Privacy