HoldClearRequest scope

Next.js 15 · Prisma · PostgreSQL · audit-led repair

Secure the money path before extending it.

An existing audit is evidence, not a fixed scope. This sprint converts the highest-risk findings into named code changes, targeted tests, a client-owned staging release, and a defensible decision on the remaining platform.

Audit supplied by clientSandbox firstNo private-key custodyEscrow-compatible
REPRODUCEBOUNDREMEDIATEPROVE

CONTROLLED REMEDIATION

Four gates between an audit PDF and live money.

01

Reproduce before repair

Confirm the repository, lockfile, environment contract, database schema, audit version, and a clean local or staging build before changing financial behavior.

02

Name the exact findings

Convert the existing audit into three agreed critical fixes with affected routes, abuse case, expected behavior, and observable acceptance criteria.

03

Prove the money path

Test authentication, authorization, webhook replay, idempotency, balance mutation, scheduled jobs, and audit logging in sandbox or test data.

04

Release without custody

Deploy to a client-owned staging environment, document changed files and limitations, and keep live withdrawals disabled until acceptance evidence is signed off.

THE $800 BOUNDARY

Small enough to accept. Useful enough to reduce risk.

Deposits, withdrawals, balances, admin controls, bots, migrations, and production deployment cannot responsibly be treated as one unknown fixed-price task. The first milestone proves the codebase and removes a defined critical slice.

INCLUDED01
  • Repository and audit intake with a reproducible build
  • A severity-to-code map for the supplied critical findings
  • Implementation of up to three agreed critical remediations
  • Targeted regression tests and a written evidence summary
  • Client-owned Vercel staging deployment and continuation estimate
SEPARATE SCOPE02
  • Rebuilding every deposit, withdrawal, balance, and admin flow
  • Live exchange custody, private-key handling, or seed phrases
  • Trading strategy, profitability, or regulatory advice
  • Bot completion, historical migration, and production launch unless separately scoped

ACCEPTANCE EVIDENCE

No “done” without a traceable result.

BUILD

Reproducible commands, environment requirements, and known setup exceptions.

CHANGE

Finding-to-file map, abuse case, changed behavior, and explicit remaining risk.

TEST

Targeted automated checks plus manual evidence for the agreed financial and admin paths.

DEPLOY

Client-owned staging URL, configuration checklist, rollback note, and fixed continuation quote.

READY INPUTS

Audit. Repository. Three critical findings.

Share them inside the hiring platform after the $800 milestone boundary is accepted.
Request the written scope →