I review one app, repository, and deployment environment across:
• Authentication, authorization, and tenant isolation
• Payments, webhook verification, and sensitive actions
• API routes, secrets, validation, and rate limits
• Data safety, migrations, backups, and recovery
• Deployment, monitoring, error handling, and rollback
• LLM prompt injection and PII risks where relevant