Senior Full-Stack Developer / Independent Code & Security Auditor — SaaS Platform
Budget: $500.0
FIXED /
⭐ 5.00 (4)
USA
postgresql
Gewenste kwalificaties
- Ervaring: Gevorderd
We are seeking an experienced senior full-stack developer to perform an independent technical audit of an existing production SaaS/event engagement platform.
Initial engagement: $500 fixed-price technical audit and evaluation.
This phase is focused on reviewing and documenting the existing system. Major remediation, redevelopment, migrations, or new feature development are not included. Any corrective development identified during the audit will be discussed and scoped separately.
The platform is already developed and operational. This is NOT an initial build-from-scratch project.
Our immediate objective is to have an experienced developer independently review the existing application, architecture, security, database, build/deployment process, and documentation before becoming involved in additional development.
We are also interested in establishing a relationship with a qualified developer who could potentially serve as an additional/backup developer for the platform after the audit.
INITIAL SCOPE — TECHNICAL AUDIT
The selected developer will review:
Application Architecture
- Overall system architecture
- Frontend/backend framework
- Repository and folder structure
- API architecture
- Database architecture
- Application dependencies
- Code maintainability
- Scalability
- Technical debt
- Dead, duplicate, or unnecessary code
Security
- Authentication
- Authorization
- User roles and permissions
- Database security and RLS policies
- Password handling
- Session/token security
- API security
- Environment variables
- Secrets/API-key management
- Client-side exposure of sensitive information
- Input validation
- Rate limiting
- Dependency vulnerabilities
- Logging and audit capabilities
We specifically want confirmation that passwords, API keys, tokens, database credentials, service-role credentials, and other sensitive information are being handled according to accepted security practices and are not improperly exposed in the repository or client application.
Database
- Schema design
- Relationships
- Indexing
- Query efficiency
- RLS/security policies
- Backup strategy
- Data integrity
- Scalability considerations
Build & Deployment
Review the complete process from source code to production, including:
- Production build process
- Environment configuration
- Development/production separation
- Deployment procedures
- DNS/SSL
- Hosting configuration
- Database configuration
- Rollback procedures
- Backup and disaster recovery
We want to determine whether another qualified developer could successfully maintain, deploy, troubleshoot, and rebuild the application without dependency on the original developer.
Infrastructure Ownership
Verify that critical infrastructure and production services are controlled by the company rather than being dependent upon individual developer accounts.
This includes source repositories, hosting, database, DNS/CDN, production environments, administrative systems, and other critical services.
Code Quality
Evaluate:
- Coding practices
- Maintainability
- Error handling
- Performance
- Security practices
- Dependency management
- Documentation
- Testing
- Potential regression risks
- Areas requiring refactoring
IMPORTANT
The initial assignment is primarily READ-ONLY.
Do not make major production changes, migrations, architectural changes, or refactoring during the audit without authorization.
The existing production application must remain operational.
We want the reviewer to understand the existing system before recommending changes.
REQUIRED DELIVERABLE
Provide a written Technical Audit Report.
Findings should be classified:
CRITICAL — immediate security, ownership, production, or data risk
HIGH — should be corrected before significant scaling
MEDIUM — important technical improvement
LOW — optimization or cleanup
For each finding provide:
Problem
Risk
Recommended Fix
Estimated Effort
The report should also provide an overall assessment of:
1. Codebase health
2. Security posture
3. Architecture
4. Database design
5. Deployment/build quality
6. Documentation
7. Scalability
8. Maintainability
9. Infrastructure ownership/transferability
10. Recommended priorities
TECHNOLOGY EXPERIENCE
Applicants should have strong experience with modern SaaS/web application architecture and production systems.
Experience with technologies such as:
- Supabase/PostgreSQL
- Row Level Security
- Cloudflare
- Railway
- Git/GitHub
- REST/API integrations
- Authentication systems
- Modern JavaScript/TypeScript frameworks
- Production deployment and DevOps
- Web application security
is strongly preferred.
SECURITY & CONFIDENTIALITY
Because the review may involve access to proprietary source code and production infrastructure, confidentiality is required.
Credentials should never be requested through ordinary Upwork messages or email.
Temporary/role-based access should be used whenever possible.
The developer should never copy production credentials, databases, source code, or proprietary materials outside authorized environments.
POTENTIAL ONGOING ROLE
A successful audit may lead to ongoing development work.
We are intentionally adding technical redundancy to the platform so that development, maintenance, security, and deployment knowledge are not concentrated with a single programmer.
Please include:
1. Examples of SaaS applications you have audited or inherited from another developer.
2. Your experience with Supabase/PostgreSQL and RLS.
3. Your experience reviewing application security.
4. Your experience with Cloudflare and production deployments.
5. How you approach auditing an unfamiliar codebase.
6. What you would review before making your first code change.
7. An example of a major issue you discovered while auditing another developer's application.
Please begin your proposal with the words “CODE AUDIT” so we know you read the complete posting.
Openen op Upwork
AI proposal draft
Generate a short cover letter for this job. Edit before sending.
Sign in to generate an AI proposal draft.
Inloggen