We're three people building a web app that agencies will run their entire operation on: their projects, their team, their clients' data, their financials. We love building it and we're not giving that up. What we need is someone senior standing next to us, telling us the truth.
The app looks great and works well. Anyone can do that now. The part that actually matters, and that most teams shipping this way skip, is security, reliability, and compliance. Companies are going to trust us with everything they have. We're going to do this right or not at all.
We also don't know what we don't know. Our production readiness checklist isn't perfect, and we've already done things in development that we shouldn't have. We'd rather hear that from you than from a customer.
WHAT YOU'D ACTUALLY DO
WHAT'S IN FRONT OF US (or so we think)
Tenant isolation, secrets handling, rate limiting, auth hardening, backups and a real restore drill, audit trails, error tracking, uptime monitoring, branch protection, and a sensible path to compliance later. Security and reliability are priority one. Compliance (GDPR, SOC 2) is a real priority, but third.
STACK
Next.js (App Router), TypeScript, PostgreSQL on Supabase, Prisma, Auth.js, Vercel.
YOU
US
3 misfits with five years building operating systems for agencies on other people's platforms (Airtable and SmartSuite), now building our own. We've won together, and walked through fire together. We don't expect you to be here forever, but we'd love to grow with you while you are. You get what you give here!
DETAILS
TO APPLY
Skip the template. Tell us two things: (1) the first three things you'd check before letting a Next.js + Postgres app hold customers' financial data, and (2) the scariest thing you've ever found in production and what you did about it.
Thank you!