# Sample diagnosis report — Thorfyn

Canonical URL: https://thorfyn.com/en/sample-diagnosis

> An example diagnosis of a made-up AI-built app: findings from critical to low, before and after evidence, and one call, harden or rebuild. Fictional.

Example: Example · made-up app, not a real client

What the report says about your app.

A made-up AI-generated app, a services marketplace. The report shows what we found, in what order to fix it and one recommendation.

## Finding 1 · critical · what we saw in the example app

- Before: GET /api/customers (signed out) returned 200 OK
- After the fix: GET /api/customers (signed out) returned 401 Unauthorized

Made-up data. Anyone, without signing in, could download the customer list. After the access rule, the same request is refused.

## From most to least severe

6 findings, 8.5 days of work in the example. Open one to see what we saw, the effect and the fix.

1. **Tables readable without signing in** (Critical, 2 days). What we saw. The public API returns the customer list with no credential. Effect. Anyone downloads the personal data of every customer. Fix. Turn on row-level access rules and test with and without signing in.
2. **Secret payment key in the browser code** (High, 1 day). What we saw. The key appears in the bundle the browser downloads. Effect. Anyone who opens the inspector can use the payments account. Fix. Replace the key and move the call to the server.
3. **Release straight to production, no tests** (High, 3 days). What we saw. Every change from the generator goes live at once. Effect. A generator mistake takes the app down for every customer. Fix. A test environment, minimal tests and an approval before production.
4. **Payment notice accepted without checking the signature** (Medium, 1 day). What we saw. The address that receives the notice accepts any call. Effect. Someone can mark an order as paid without paying. Fix. Check the provider's signature on every notice.
5. **No database copy that can be restored** (Medium, 1 day). What we saw. There is no scheduled copy and no restore test. Effect. A data mistake cannot be undone. Fix. A daily copy and one tested restore.
6. **No alert if the app goes down** (Low, 0.5 days). What we saw. Nobody is told when the app stops. Effect. The customer finds out before you do. Fix. An external check and an email alert.

## Two paths, one choice

The decision is yours. The report recommends one, in writing.

- **Harden (Recommended)** — Keeps the stack and closes the holes. The structure holds today's product; The flaws are configuration, not design; 8.5 days of work, in the example.
- **Rebuild (If the product changes)** — Moves to a standard stack built to reach a million users. Makes sense if the next feature needs a different data model.

Why the diagnosis starts with access rules: CVE-2025-48757 records apps generated by an AI builder whose database tables could be read and written without signing in. The record at NVD: https://nvd.nist.gov/vuln/detail/CVE-2025-48757

## Your diagnosis, on your app.

One discovery week, one report, one recommendation.

- See the sample plan: https://thorfyn.com/en/sample-stage-plan
- Questions and requests: hello@thorfyn.com
- Back to the home page: https://thorfyn.com/en
