Skip to content
CUYCO

Snagg

Snagg's team had built a React Native wishlist app and wanted to know it was safe to put real people on. We audited it end to end, wrote the findings up twice (once for engineers, once for the founders), and shipped the most urgent fixes with automated tests behind them.

Client
Snagg
Year
2026
Built with
React NativeExpoFirebaseFirestore rulesGitHub Actions
Snagg — A production-readiness audit of a social wishlist app before launch, with the security fixes shipped and a test suite to keep them fixed.

The brief

Snagg is a social wishlist app: build wishlists, follow friends, and share what you actually want. The team had the app built and designed, and it looked ready. Before inviting real users, they wanted an outside view on whether it was actually ready, especially around privacy, which is the whole point of a feature like private accounts.

The hard part

An app can look finished while the rules underneath it are not. Privacy settings that only exist in the interface, a production build still pointed at a test database, and a server function that could be misused to send email are exactly the kind of issues that stay invisible until a real user trips over them. The job was to find them before that happened, rank them honestly, and explain them in a way the founders could act on without reading code.

What we built

  • A production-readiness audit ranking every finding as critical, high or medium, with the evidence and the fix for each
  • A founder's guide: the same findings in plain English, with how changes should move from a test environment to real users
  • Privacy enforced at the data layer: private accounts, and personal details such as contact and billing data, now readable only by the people who should see them
  • Write ownership enforced: users can only change their own wishlists, products and profile
  • Abuse protection on the email verification function
  • A stronger, single password policy, and share links that open the app
  • Automated security-rule tests that run on every change, so the fixes cannot quietly regress

What happened

The critical privacy gaps were closed before launch rather than after, and every fix is covered by tests that run automatically. The founders came away with a clear list of what was fixed, what remained, and why each item mattered.

Tell us what you are trying to solve.

Thirty minutes on a call is usually enough to work out whether this is a two-week job, a two-month job, or something you should not build at all. You get a written scope and a fixed price before anything starts.

Taking on new work now · Replies in one business day