Skip to main content
Cardinal Stacks blog

Field notes from the team that shipsproduction software in two weeks.

Practical writing on AI-coded delivery, regulated builds, and the economics of flat-fee custom software. Written by the senior engineers who deliver every Cardinal engagement.

Lovable App Security: 7 Fixes Before Production

Seven Lovable app security gaps show up on almost every audit Cardinal Stacks runs: weak auth defaults, missing Supabase Row Level Security, API keys in git, no spend ceiling on LLM endpoints, console-only error handling, manual deploys with no rollback, and PII flowing to LLMs unredacted. This is the CTO's read on what to find and how to fix each one before you onboard paying users.

7 min read

How Long to Get a Bolt or v0 App Production Ready?

A Bolt or v0 app reaches production-ready in 14 calendar days for $4,800 flat. Lovable and Cursor projects of comparable scope run on the same timeline. Cardinal Stacks calls this Vibe Rescue, and what follows is the methodology underneath the number: what happens day by day, what slows the work down, and why parallel-agent orchestration is the only way the math works.

7 min read

HIPAA-Compliant App Development: What AI Tools Miss

Lovable, v0, and Bolt can scaffold a healthcare app in an afternoon. None of them can sign a Business Associate Agreement, redact patient data before it reaches an LLM, or stand up an audit posture that survives a real breach review. This is what HIPAA-compliant app development actually requires, where AI coding tools come up short, and what has to be in place before your first patient signs up.

8 min read

Flat-Fee vs Hourly Software Development: What You Pay

On a known deliverable, flat-fee software development is usually cheaper than hourly billing and ships faster against the same scope. The honest exception is genuine R&D, where scope is not yet knowable and hourly bills for the thinking. Here is what each model actually costs, where flat-fee fails, and how Cardinal Stacks prices the four engagements it sells, especially for regulated builds where compliance counsel needs a known scope to sign off.

8 min read

SEC EDGAR Software Development: What to Look For

Most vendors pitching SEC EDGAR custom software can describe the filing API. Fewer can describe what happens when a submission is rejected at 4:47pm on a deadline day, who signed off on the disclosure that went out, or how the audit chain holds up two years later. Evaluating a SEC EDGAR development partner means getting written answers on five things: production EDGAR systems shipped, audit-trail architecture, FINRA scoping by registration class, encryption surfaces, and data-handling contracts. This is what to ask, what audit-ready architecture actually looks like, and where Cardinal Stacks has shipped under SEC and FINRA-aware obligations.

9 min read

How to harden a Lovable, v0, or Bolt app for production in 14 days

Vibe-coded apps ship the demo, not the deploy. Here is the seven-surface checklist Cardinal Stacks uses to take a Lovable, v0, Bolt, or Cursor project from prototype to hardened production in two weeks, the failure modes that show up on each surface, and the diagnostic questions a founder can answer before sending the repo.

11 min read

Flat-fee SaaS development in 2026: what it actually costs and why

Custom software pricing finally caught up to AI-assisted delivery. Here is what a Cardinal Stacks build costs in 2026, why the timeline collapsed from twelve weeks to two, where the price actually goes inside the engagement, and how the gross-margin math lets a senior team ship at numbers a legacy agency cannot match.

13 min read

Skip the reading list

Send the repo, audit back in 48 hours.

Every post on this page is a long version of the same answer: send a project, get a written quote inside two business days. The fastest path is the form.