Fix a system that already exists

Your team takes over a system audited, stabilized and documented, without depending on a single person.

Do any of these situations sound familiar?

  • An AI-built repo works, but nobody wants to modify it.
  • A developer takes several days to understand the codebase before contributing.
  • Production incidents keep coming back with no clear cause.
  • A team uses AI tools daily with no shared convention.
  • A deadline (fundraise, audit, production release) forces you to secure the code quickly.

The offers on this path

Repo Rescue: Sanity Check

AI-generated code audit and hardening

A prioritized risk report on your repo. You know what breaks, what's urgent and what's left to do before deciding.

Duration
1 to 2 days

Triggers

  • A new developer takes several days to understand the code.
  • Incidents keep coming back and nobody knows why.
  • Dependencies haven't been updated in a long time.
  • A fundraise or an external audit is coming up.

Deliverables

  • Map of risk areas (security, dependencies, structure, tests).
  • Fix list ranked P0, P1, P2.
  • Architecture recommendation and technical debt note.
  • Duration estimate if a Rescue Sprint is needed.
  • Written report and a 30-minute debrief call.

What you provide

  • Read access to the repository.
  • A 30-minute scoping call.
  • The list of friction points already identified internally.

Eligibility

  • Project written in Node.js, TypeScript, React, Next.js, Vue.js, FastAPI or Python.
  • Code that already runs, not an empty project.

Out of scope

  • Any fix beyond a few one-off urgent items.
  • Full refactoring or new feature development.

Repo Rescue: Rescue Sprint

targeted codebase rescue with a locked scope

A stabilized, tested and documented codebase, ready for your team. No surprises: the scope is locked after diagnosis.

Duration
5 to 10 days

Triggers

  • A critical security flaw is still open.
  • The same regressions come back with every update.
  • No automated tests exist.
  • Onboarding a new developer takes more than 3 days.

Deliverables

  • Refactored structure with separated responsibilities.
  • Security fixes (dependency audit, secret scanning, OWASP best practices).
  • Automated tests and a CI/CD baseline.
  • Architecture documentation (CLAUDE.md or AGENTS.md style).
  • Local setup guide.
  • 60-minute knowledge transfer call.

What you provide

  • Write access to the repository.
  • Deployment rights on staging or production.
  • A product contact available during the engagement.
  • A kickoff meeting with the team.

Eligibility

  • A Sanity Check or an equivalent diagnosis already happened.
  • The rescue scope can be locked before the work starts.

Out of scope

  • New feature development beyond a small one-off item.
  • 24/7 on-call coverage or maintenance spanning several months.

AI-Driven Dev Workflow Setup

setting up AI-assisted development practices

Your team adopts clear conventions for coding with AI tools: documented context files and integrations that hold up. Generated code stays consistent from one developer to the next.

Duration
3 to 5 days

Triggers

  • Productivity stalls despite using AI tools.
  • AI-generated code quality varies too much between developers.
  • Onboarding onto AI tools takes time with no clear method.
  • No shared convention exists (no CLAUDE.md, no AGENTS.md).

Deliverables

  • Audit of current AI-assisted development practices.
  • CLAUDE.md / AGENTS.md templates adapted to your stack.
  • Tool configuration (Claude Code or equivalent).
  • Integration of relevant MCP tools for the team.
  • Documentation of the agentic workflow (review, roles, sprint process).
  • 2-hour training session and a follow-up check-in 2 weeks later.

What you provide

  • Access to the team's repository.
  • Access to the development environment.
  • List of current friction points.
  • Team availability for the training session.

Eligibility

  • A team of 2 to 10 developers already using AI tools day to day.

Out of scope

  • Building a custom AI agent (see AI Agent Deployment).
  • Ongoing support beyond the included follow-up check-in.

Method

The rescue follows a fixed order, to avoid surprises on either side.

  1. Scoping

    A call to understand the context, the constraints and what's already been tried.

  2. Diagnosis

    Audit of the existing code, returned as a prioritized risk report.

  3. Work within a locked scope

    The scope of the rescue is fixed after diagnosis, not before.

  4. Handoff

    Documentation, tests and knowledge transfer to your team.

Responsibilities

  • Antoine Delamare leads the engagement technically from start to finish.
  • The scope locked after diagnosis is binding for both parties.
  • Any scope extension is discussed and approved before it starts.

A concrete proof

Industrial ERP, back in production

Industrial technical textile SME, internal ERP built with AI tools.

Problem

The ERP worked, but nobody wanted to touch it anymore. 2 known security flaws were still open, and the application depended on libraries loaded from external CDNs.

Intervention

Audit, then a rescue within a locked scope. Fixed both CVEs and vendored the CDN-loaded libraries locally. Added a test suite and architecture documentation to hand the codebase to the team.

Results

2 CVEs fixed (CVE-2023-30533, CVE-2024-29041)
Prototype pollution in a file-generation library and path traversal in the web server, both publicly listed.
46 tests (Mocha + supertest)
Automated test suite added with the stabilization release.
0 remaining external CDN dependencies
The affected libraries are vendored locally; the application keeps working offline.

Limits

This proof documents an audit and a stabilization of existing code. It does not demonstrate a full architecture overhaul or a multi-environment deployment.

Tech stack

  • Node.js
  • Express
  • Mocha
  • supertest

Who this is for, and who it is not

Who this is for

  • Existing code already runs, even imperfectly.
  • A sponsor can approve the scope.
  • The stack is Node.js, TypeScript, React, Next.js, Vue.js, FastAPI or Python.

Who this is not for

  • A project still at the idea stage, with no code to audit.
  • A request for official certification or regulatory compliance.

After the rescue

Once the system is stabilized, a monthly Retainer takes over: fixes, new bounded workflows and security updates, without a dedicated hire.

AI Agent Retainer

Your AI agent stays stable and up to date, and gains new workflows every month, without a full-time hire.

Included deliverables

  • Fixes and regression resolution.
  • 1 to 3 new bounded workflows per month.
  • Security review and dependency updates.
  • Monthly performance report and recommendations.
  • Asynchronous support within 24 business hours.

Frequently asked questions about this path

Should I start with the Sanity Check before the Rescue Sprint?

Recommended. The Sanity Check sets a clear scope before any work starts; the report stays useful even if you don't continue.

Will the code be completely rewritten?

No. The rescue targets the risk areas identified during diagnosis, not a full rewrite.

Can my team carry on alone after the engagement?

That's the goal of the handoff: documentation, tests and a handover call included in every offer on this path.

Do you work with a stack you don't already know?

The Sanity Check quickly confirms compatibility before any longer commitment.

A system to fix?

Describe your repo and your friction points on a call. You leave with a clear recommendation, no commitment.