Auth and secrets
API keys in the frontend, .env files committed, default admin passwords, and session handling that lets anyone become someone else.
Vibe coding audit
You shipped an AI-generated app with Cursor, Lovable, Bolt, v0, Replit, or Copilot. We audit the repo, security, privacy, and technical debt, then quote the work that makes it production-ready. Melbourne-based. Australia-wide and international.
Production readiness
A vibe coding audit is a production-readiness review of the app you already shipped. Ranked findings, plain English, and a fixed quote to harden or rewrite what is not safe to run with real users.
API keys in the frontend, .env files committed, default admin passwords, and session handling that lets anyone become someone else.
Who can read or write whose data. Missing row-level checks, open storage buckets, and OWASP-class injection or XSS paths that AI scaffolding often skips.
What personal information you collect, where it is stored, and whether GDPR, UK GDPR, or Australian APPs are even on the radar. Threshold for a Privacy Impact Assessment if the project needs one.
Stripe or similar wired through client-side secrets, webhooks that trust any payload, or receipts that leak other customers. Card data must never touch your server.
Generated files nobody owns, duplicated logic, no tests, and a stack that cannot be changed without asking the model again. We map what is salvageable versus what should be rebuilt.
Race conditions, broken error paths, missing rate limits, and crashes that only appear with real traffic. Production-ready means it survives more than a demo.
Who owns the Vercel, Firebase, or Supabase project. Whether backups restore. Whether you would even know if the app went down or leaked data.
Fit
You built with Cursor, Lovable, Bolt, v0, Replit, Copilot, or ChatGPT and people are signing up. You cannot answer where data lives, who can see it, or what happens if the next prompt breaks production.
Stripe is wired, or about to be. Customer emails, files, or health-adjacent records sit in a database you did not design. Privacy rules follow your users, not your postcode.
If you will not share the repo, hosting, and admin accounts, we cannot audit what is running. Discovery is free. The audit is scoped. We do not vibe-code a new product from a one-line pitch.
Industries
Sign-up, messaging, bookings, or listings generated in a weekend. Auth, file uploads, and public APIs are where vibe-coded products leak first.
A Cursor-built admin that now runs quoting, roster, or customer files for a real team. One shared login and no backups is not a production system.
GDPR, UK GDPR, and the Australian Privacy Act apply based on who you collect from. A Melbourne ABN does not exempt EU residents. We map the gap; we do not sell a compliance certificate.
Outcomes
Every issue is explained in plain English, ordered by real risk, with a recommended fix you can approve item by item.
Most clients ask us to harden or rewrite the priority items as fixed-price follow-on work. You approve each item before we start.
Secrets in repos, open admin, missing access control, and personal-information flows are reviewed together so you do not pay twice for the same surface.
How it works
A Discovery Session to map the stack, how it was generated, who uses it, and what production-ready means for you. Fixed quote before any audit starts.
Read-only access to source, hosting, identity, and data stores. We inspect auth, secrets, privacy flows, debt, and the surfaces attackers or regulators would hit first.
Plain-English findings ordered by risk, with recommended fixes and a scoped quote to harden, patch, or rewrite.
Optional follow-on work you approve item by item: security fixes, privacy controls, tests, observability, and the rebuilds that make the product actually production-ready.
Request a Discovery Session. We will look at how the app was built, what is exposed, and send a fixed quote before any audit or rescue work starts.
Request a Discovery SessionProof
Real builds, not stock screenshots. See how the craft lands for clients like you.

Case study
Case study: Luxora Hair, a custom Australian luxury hair ecommerce platform.
View project
Case study
Case study: One Line Loop, an email-first daily journaling app.
View project
Case study
Case study: AutoSizer, a browser-first image resizer for marketplaces.
View projectQuestions
A production-readiness review of an AI-generated or vibe-coded app. We inspect the repo, hosting, security, privacy, technical debt, and bugs, then rank what must change before real users, payments, or regulators become a problem. It is not a certificate and it is not legal advice.
Usually not on day one. Tools like Lovable, Bolt, v0, Replit, Copilot, and Cursor are strong at shipping a demo. Production-ready means auth, access control, secrets, privacy, backups, and a codebase a human can maintain. That is the gap we audit.
Privacy law follows the people whose data you collect, not where you wrote the prompts. EU users can trigger GDPR. Australian users can trigger the Privacy Act and APPs. UK users can trigger UK GDPR. We map what you collect and flag when a Privacy Impact Assessment is the next step. We do not certify you as compliant.
Whichever is cheaper and safer. Salvageable code gets hardened. Generated spaghetti that cannot be tested or secured gets a scoped rewrite. You see the recommendation and the quote before we change anything.
Most focused reviews of a single web or mobile app complete within one to two weeks after Discovery, depending on repo access and how quickly you answer questions about users and data.
If the app collects personal information, uses AI on customer data, or has EU, UK, or Australian users, a threshold PIA is often the honest next step. The vibe coding audit flags that. A full PIA is a separate scoped engagement on our Privacy Impact Assessment Australia page.
No. It is a practical production-readiness audit: configuration, code, privacy flows, and debt. Full penetration testing is a different engagement and only useful once the basics are in place.
We can still review the live app, hosting, and accounts. A repo makes the audit faster and the rescue cheaper. If the source only lives in a chat history, we will say so in Discovery and quote accordingly.
No. We are Melbourne-based and deliver Australia-wide and internationally. Same process, same packages, remote by default. We meet in person across Melbourne when it helps.
Official guidance
Next step
Request a Discovery Session. We will look at how the app was built, what is exposed, and send a fixed quote before any audit or rescue work starts.