The three unauthenticated endpoints from the code review, then the reason they existed. Your middleware guards pages, not the API, so every route decides for itself who is allowed in. We work that down route by route.
The collectible layer, the shared Supabase instance, the schema split between events and mvp_events. These are one-way doors. The hour exists so you walk through them on purpose.
When a venue or sponsor asks for a security review, you want the answer ready, not researched. We keep a running scope of what the enterprise build actually requires, so the number is never a surprise.
| Line | Standard Rate | Retainer Rate | Monthly |
|---|---|---|---|
| Advisory, 4 hoursSolutions architect, weekly working session | $250/hr | $175/hr | $700 |
| Engineering, ~3 hoursProduct engineering against the repo | $175/hr | $95/hr | $300 |
| Monthly retainer$1,525 of time at standard rates. You pay 34 percent less. | $1,525 | $1,000 |
Month to month. Thirty days written notice either direction. Invoiced the first of the month for the month ahead. Net 14. ACH or check.
$95/hr, up to 20 hours a month. Additional engineering runs at the same retainer rate against a written estimate you approve first. Nothing gets billed you did not agree to.
The retainer rates apply to retainer work. Defined builds are quoted separately at standard rates: the full authorization layer, the schema consolidation, the collectible layer, and the enterprise platform. This arrangement is how you get to those scopes with your eyes open, not a discount on them.
Hours do not roll forward. A missed week is a missed week. Reschedule inside the month and it counts.
What we need to start. Repo access already granted under the signed NDA, a standing calendar hold, and one named person on your side who owns merges. Start date is the Monday after signature.