# Thorfyn — English (en)

Canonical URL: https://thorfyn.com/en

> Any software, from a first version or an AI-built prototype to a product at scale, with a panel that shows every step. A software house in Brazil, async.

## Your software, built in the open and run from your own panel.

Software house · Brazil. Any software, from the first thousand users to the first million. The reply comes from someone who would build it.

Built with: Next.js, React, TypeScript, Node.js, PostgreSQL, Supabase, Docker, Vercel, Stripe.

### Where is your software today?

- **Build (Project)** — A new product or module, from first version to launch, every step on your panel.
- **Follow and run (Monthly operation)** — Your product is live. It has to scale, stay up and cost less per user.
- **From an AI-built prototype to production** — Real users arrived and the builder stopped helping. We take it to production, in your accounts. Built in: Lovable, Bolt, v0, Bubble. Diagnosis: One week on the code you have. A written report, one recommendation.

## One request, end to end

The latest request on this site, from the message in the panel to the version users are on. Times come from GitHub, in São Paulo time.

- Request
- Pull request
- Preview
- Production

## One panel, two modes

Follow the build and the production from one place.

- Project — What is being built right now, who is waiting on what, and what shipped this week. (Real data: GitHub: pull requests and deploys, by webhook, reconciled daily; Cycle, milestones and requests written by the owner.)
- Operations — What the site is doing in production, measured by the site itself: availability, traffic served and every incident. (Real data: Measured by the Worker, every 60 s; Cross-checked from outside Cloudflare, every 10 min.)

## From a thousand users to a million

Pick a product and move up a stage. Each step shows what enters the architecture and what it asks of the team.

- **Launch** — One app and one database, shipped fast, with previews from day one.
- **Grow** — A CDN and a queue take load off the app; the team gets a design and QA rhythm.
- **Scale** — Cache and read replicas, a DevOps owner, and cost per user on the panel.
- **Operate at scale** — Several regions, observability and an SRE on call: the product stays up while it grows.

Moving up a stage is a scope change: it only enters with your approval.

A starting shape; discovery confirms it.

## What arrives, week by week

An example with an invented product: one discovery week and a stage of 4 weeks. The real schedule comes from the plan, which closes in the first week.

- Week 1 — The plan, closed. Each item is checkable, and the price is one value. Scope, Architecture, Schedule, Fixed price, Risks, What stays out.
- Weeks 2 to 4 — A preview for each delivery. Each delivery gets an address of its own, so you can click through it before anything goes live. Sign-in by link: ready; Calendar and bookings: ready; Payment: waits for you. What depends on you is shown with the week.
- Week 5 — You approve, we publish. Delivery ready for production: List of the day and release. Tests and build passed. Approve and publish. You confirm on your own device. Fetching the code, Installing, Running the tests, Building the version, Publishing to your accounts. Published to your accounts. Demonstration, nothing is published.

## From an AI-built prototype to production

Real users arrived and the builder stopped helping. We take it to production, in your accounts.

Built in: Lovable, Bolt, v0, Bubble.

- **Diagnosis** — One week on the code you have. A written report, one recommendation.
- **You choose** — Harden or rebuild. The decision is yours.
- **Harden** — Keep the stack, close the holes.
- **Rebuild** — Standard stack, built to reach a million users.
- **The work** — Each delivery has a preview; publishing waits for your approval.
- **In your accounts** — Repository and cloud in your name. You leave whenever you want.

Why the diagnosis starts with access rules: CVE-2025-48757 records apps generated by an AI builder whose database tables could be read and written without signing in. The record at NVD: https://nvd.nist.gov/vuln/detail/CVE-2025-48757

## How we work

Your code, your accounts, our hours, and what happens before every release.

- **Yours from day one** — Code, repositories and cloud accounts are created in your name. We get access, not ownership.
- **You leave whenever you want** — An exit package kept current with every delivery: architecture, how to operate it and the handover of access.
- **Nothing that locks you in** — Standard, open tools only. Your product keeps running without us.

### Your hours, ours, and what that leaves

Our workday runs 09:00 to 18:00 in Brazil. Pick where you are and see how much of it lands inside your day.

### Before every release

- Every change is tested
- You see it before it is published
- You know whether it is up
- Screens that match each other

## What if something drifts from the agreement?

Five rules that hold at every stage.

- **Half only when it runs in production** — Half when the stage is signed, half when it runs live.
- **A scope change only with your approval** — A new deadline and a new price enter when you approve, never before.
- **Nothing goes live without your approval** — Every delivery has a preview, and publishing waits for your approval.
- **Everything stays on record** — The activity only adds lines; what was approved is not rewritten.
- **You leave whenever you want** — The exit package goes with the project from day one.

## What it costs, and how you pay

Five steps, from a one-day triage to a monthly operation, each with its price here. The rest of the page says how the payment is split.

### Project (Build)

A new product or module, from the first sketch to launch.

- A paid discovery week, then one signed stage at a time
- 50% when signed, 50% when it runs in production
- Stop after discovery and the plan is still yours

### Monthly operation (Follow and run)

Your product is live and has to evolve, stay up and cost less per user.

- One engineer who owns a product area, month after month
- Starts with an audit of what runs today
- Thirty days notice, the paid cycle delivered in full

- **Prototype triage** — 390 USD, fixed price, One day. An app generated in Lovable, Bolt or v0 that is about to get real users or take real payments. One day reading sign-in, exposed data, secrets and payment, ending in a written verdict: launch, fix first or rebuild. Take the audit or the discovery week within 14 days and the triage fee is credited in full.
- **Audit** — 1,200 USD, fixed price, Two to three days. A product already running that is slow, costs too much per user or is hard to change. A written report: what is slow or costly, what it takes to fix, and in what order. Fix what the report names, or take the discovery week for a bigger change.
- **Discovery week** — 2,400 USD, one week paid, One week. A new product, or a rebuild, that needs a plan before it needs code. Five days that end in the written stage plan: what ships, by when, for how much. If you stop there, the plan is yours and nothing else is owed. Sign the first stage, and the discovery week is credited in full against its price.
- **Stage project** — from 6,000 USD per stage, Two to eight weeks per stage. The product the plan describes, built one signed stage at a time. A working stage in production, in your repository and your accounts. Sign the next stage, or move to monthly operation once it is live.
- **Monthly operation** — from 1,500 USD per month, Month to month. A live product that has to evolve, stay up and cost less per user. One engineer who owns a product area: releases, incidents, cost and load. Thirty days notice ends it, and the repository is already yours.

Pay with: Wise, Pix, PayPal, Tether, Wire. Invoices come from a Brazilian company, in USD, EUR or BRL, with the tax documents your accounting will ask for.

## Questions before you hire us

**How much does it cost to start?** The discovery week costs 2,400 USD and ends in the written stage plan: what ships, by when, for how much. If you stop there, the plan is yours.

**How long does a first stage take?** Most ship in two to eight weeks. The discovery week puts a number on yours before you commit to it.

**What happens if I stop?** You keep everything, because none of it was held anywhere else. A monthly operation ends on thirty days notice; a project ends at the close of the stage that was signed.

**Who writes the code?** The person who answers your email. The work is not handed to a bench you never meet, which is also why one operation slot is open at a time.

**What happens to the infrastructure?** It runs in your cloud accounts from the first week, on standard, open tools. We hold access, not ownership, and revoking it takes one afternoon.

**Can you take over an app built with Lovable, Bolt or Bubble?** Yes. It starts with the same discovery week, applied to what already exists: we read the code and the data, and the plan says whether to harden it or rebuild it. Either way it ends up in your repository and your accounts.

**Do you work with teams in the US and Europe?** Yes, async. Our workday runs 09:00 to 18:00 in Brazil, and the hours section shows how much of it lands inside yours. Invoices go out in USD, EUR or BRL.

## Tell us where you are.

One email is enough. Say what exists today, what should exist, and when.

### What happens after you write

- 1 business day — A written reply
- within 3 days — A 30-minute call
- 5 business days — The written stage plan

- Email: hello@thorfyn.com
- Prefer to talk? Book 30 minutes: https://cal.com/matheuspavaneli/call-thorfyn
- Founded by Matheus Pavaneli
- One operation slot open for the next cycle
- Brazil · working async
- The reply comes within one business day.
