Auth and secrets
Keys in the frontend, committed .env files, default admin, and session handling that lets anyone become someone else.
Vibe coding audit
Built a website or app with Codex, Cursor, Lovable, Bolt or another AI tool? We inspect all seven production-readiness surfaces for $200 + GST, explain what to keep and quote the fixes separately. Melbourne-based, reviewing apps remotely for Sydney, Australia and international clients.
This is not theoretical
Mathspace is an education product, not a weekend demo. Attackers used administrator access on unpatched internal reporting software. Vibe-coded apps fail the same way: open admin, skipped patches, and no one owning the stack.

A weekend demo is not a product. Real users, real cards, real privacy law.
Demo versus live
The interface can look finished in a weekend. Production-ready means strangers can use it without leaking keys, data, or card details.
What the prompt shipped
What production needs
The standard
Same seven surfaces every time. Ranked written report. Rescue is quoted after. If eligibility fails, Discovery produces a separate quote.
Standard Vibe Coding Audit
$200 + GST
One AI-generated app. Ranked written report.
Typical window: one to two weeks after access
Request a Discovery SessionPrice applies when
Included at $200 + GST
Keys in the frontend, committed .env files, default admin, and session handling that lets anyone become someone else.
Who can read or write whose data. Open storage buckets, and OWASP-class injection or XSS paths that AI scaffolding often skips.
What personal information you collect, where it is stored, and whether GDPR, UK GDPR, or Australian APPs are on the radar. We flag a Privacy Impact Assessment if the project needs one. We do not write the PIA.
Stripe or similar wired through client-side secrets, webhooks that trust any payload, or receipts that leak other customers. Card data must never touch your server. Reviewed when payments exist or are about to.
Generated files nobody owns, duplicated logic, no tests, and a stack that cannot be changed without asking the model again. We map what is salvageable versus what should be rebuilt.
Race conditions, broken error paths, missing rate limits, and crashes that only appear with real traffic. Production-ready means it survives more than a demo.
Who owns the Vercel, Firebase, or Supabase project. Whether backups restore. Whether you would even know if the app went down or leaked data.
Not included at $200 + GST
Follow-on work, quoted from the report. You approve each item before we change production.
A full PIA is a separate scoped engagement. The audit flags when that is the honest next step.
This is a production-readiness audit of configuration, code, privacy flows, and debt. A pentest is a different engagement, useful only once the basics are in place.
We do not certify the app, stamp compliance, or give legal advice.
Email, domain DNS, and devices sit on the Cyber Security Audit Melbourne page, from $1,300 + GST.
We audit what is running. We do not vibe-code a product from a one-line idea.
The standard price is one app. Extra apps are quoted separately.
The seven surfaces
The $200 standard audit inspects every surface below. Ranked findings, plain English, and a quote to harden or rewrite what is not safe to run with real users.
Keys in the frontend, committed .env, sessions anyone can steal.
One user reading another user's records or files.
What you collect, where it lives, which privacy regime applies.
Client-side Stripe secrets, webhooks that trust any payload.
Unowned generated files, no tests, salvage versus rebuild.
Race conditions, missing rate limits, crashes under real traffic.
Who owns hosting, whether backups restore, whether you would know.
Fit
You built with Codex, Cursor, Lovable, Bolt, v0, Replit, Copilot or ChatGPT and people are signing up. You need a review of the existing work and a clear path to fix the unfinished or unsafe parts.
Stripe is wired, or about to be. Customer emails, files, or health-adjacent records sit in a database you did not design. Privacy rules follow your users, not your postcode.
A founder shipped it. You now own hosting, backups, and the next patch advisory. We audit the repo so your preventative programme covers the product, not only the mailbox. We train. We do not run live incident response.
If you will not share the repo, hosting, and admin accounts, we cannot audit what is running. Discovery is free. The $200 audit needs the eligibility above. We do not vibe-code a new product from a one-line pitch.
How it works
Four stages. The $200 fee covers discovery through the ranked report. Harden or rewrite is approved item by item.
A free Discovery Session to confirm eligibility, the stack, who uses it, and what production-ready means for you. If the $200 standard applies, that is the quote.
Read-only access to source, hosting, identity, and data stores. We inspect all seven surfaces in the contract.
Plain-English findings ordered by risk, with recommended fixes and an itemised quote to harden, patch, or rewrite.
Optional follow-on, paid separately. You approve each item: security fixes, privacy controls, tests, observability, and the rebuilds that make the product actually production-ready.
Outcomes
Every issue is explained in plain English, ordered by real risk, with a recommended fix you can approve item by item.
You can use the report with your own developer or ask us to implement the priority repairs. Follow-on work is scoped and priced separately; you approve it before we start.
Secrets in repos, open admin, missing access control, and personal-information flows are reviewed together so you do not pay twice for the same surface.
Request a Discovery Session. The standard vibe coding audit is $200 + GST for one eligible app. Rescue work is quoted from the report, and you approve it before any code changes.
Request a Discovery SessionProof
Real builds, not stock screenshots. See how the craft lands for clients like you.

Case study
Case study: Luxora Hair, a custom Australian luxury hair ecommerce platform.
View project
Case study
Case study: One Line Loop, an email-first daily journaling app.
View project
Case study
Case study: AutoSizer, a browser-first image resizer for marketplaces.
View projectQuestions
A production-readiness review of an AI-generated or vibe-coded app. We inspect the repo, hosting, security, privacy, technical debt, and bugs, then rank what must change before real users, payments, or regulators become a problem. It is not a certificate and it is not legal advice. The standard audit is $200 + GST for one eligible app.
The Standard Vibe Coding Audit is $200 + GST for one eligible AI-generated app when you provide read-only repo and hosting access. That fee is the ranked written report and an itemised rescue quote. Harden, rewrite, a Privacy Impact Assessment, and extra apps are quoted separately. If eligibility fails, Discovery produces a separate quote. We do not shrink the seven-surface list to hit the price.
Inspection of all seven surfaces: auth and secrets; access control and injection; privacy, cookies, and residency; payments and billing; technical debt and tests; bugs and reliability; hosting, backups, and observability. You get a ranked plain-English report, a salvage versus rewrite call, and an itemised quote to fix priority items. Discovery is free. Typical window is one to two weeks after access.
The tool name cannot answer that. We need to inspect the source, configuration and customer journeys. The review checks auth, access control, secrets, privacy, payments, reliability and maintainability so the recommendation follows evidence rather than assumptions about AI-generated code.
Yes, as separately scoped implementation work. Common briefs include booking rules, verified payment handling, customer and staff roles, quoting, CRM connections and deployment. The report identifies risks; a follow-on quote defines the feature, acceptance checks and handover. These changes are not included in the $200 audit.
Privacy law follows the people whose data you collect, not where you wrote the prompts. EU users can trigger GDPR. Australian users can trigger the Privacy Act and APPs. UK users can trigger UK GDPR. We map what you collect and flag when a Privacy Impact Assessment is the next step. We do not certify you as compliant.
We assess the interface, business logic, data and infrastructure separately. Useful code can be retained while weak parts are repaired or replaced. If a rewrite is recommended, the report explains the evidence and scope before you decide. Implementation is quoted separately and is not included in the $200 audit.
Most focused reviews of a single web or mobile app complete within one to two weeks after Discovery, depending on repo access and how quickly you answer questions about users and data.
If the app collects personal information, uses AI on customer data, or has EU, UK, or Australian users, a threshold PIA is often the honest next step. The vibe coding audit flags that. A full PIA is a separate scoped engagement on our Privacy Impact Assessment Australia page.
No. It is a practical production-readiness audit: configuration, code, privacy flows, and debt. Full penetration testing is a different engagement and only useful once the basics are in place.
We can still review the live app, hosting, and accounts, but that is outside the $200 standard. A repo makes the audit faster and the rescue cheaper. If the source only lives in a chat history, we will say so in Discovery and quote accordingly.
No. We are Melbourne-based and deliver Australia-wide and internationally. Same process, same packages, remote by default. We meet in person across Melbourne when it helps.
Official guidance
Go deeper
Next step
Request a Discovery Session. The standard vibe coding audit is $200 + GST for one eligible app. Rescue work is quoted from the report, and you approve it before any code changes.