Vibe coding audit

Keep the progress. Check what is ready

Built a website or app with Codex, Cursor, Lovable, Bolt or another AI tool? We inspect all seven production-readiness surfaces for $200 + GST, explain what to keep and quote the fixes separately. Melbourne-based, reviewing apps remotely for Sydney, Australia and international clients.

$200 + GSTMelbourne · Australia · WorldwideRanked written report
Vibe Coding Audit

This is not theoretical

Unpatched admin tools take real data

Mathspace is an education product, not a weekend demo. Attackers used administrator access on unpatched internal reporting software. Vibe-coded apps fail the same way: open admin, skipped patches, and no one owning the stack.

7NEWS photograph of the Mathspace cyber attack reported 8 September 2026. Personal data of more than one million students, parents, guardians and school staff in Australia and New Zealand was exposed.
Hackers obtained administrator access to Mathspace internal reporting software from 10 August 2026. Names and other customer data were downloaded on 27 August. More than one million students, parents, guardians and school staff in Australia and New Zealand were affected. Credit: 7NEWS · Mathspace notice · Australian cyber breaches roundup

A weekend demo is not a product. Real users, real cards, real privacy law.

Demo versus live

What the prompt shipped is not what go-live needs

The interface can look finished in a weekend. Production-ready means strangers can use it without leaking keys, data, or card details.

Cracked demo frame beside a blocked live gate

What the prompt shipped

  • A login screen that works on your laptop
  • Happy-path checkout or sign-up
  • A deploy to Vercel, Firebase, Lovable, or Bolt
  • Features the last prompt asked for

What production needs

  • Auth that actually authorises
  • Secrets out of the browser and the repo
  • Backups that restore, and logs you would see
  • A privacy map for the people who signed up

The standard

What $200 buys

Same seven surfaces every time. Ranked written report. Rescue is quoted after. If eligibility fails, Discovery produces a separate quote.

Standard Vibe Coding Audit

$200 + GST

One AI-generated app. Ranked written report.

Typical window: one to two weeks after access

Request a Discovery Session

Price applies when

  1. One AI-generated or vibe-coded web or mobile app (one Git repo, or one hosted app plus exportable source).
  2. Read-only access to source, hosting, identity, and data stores within five business days of booking.
  3. You can say who the users are and what personal information the app collects.
  4. Remote review. Melbourne studio, Australia-wide and international.

Included at $200 + GST

Auth and secrets

Keys in the frontend, committed .env files, default admin, and session handling that lets anyone become someone else.

Access control and injection

Who can read or write whose data. Open storage buckets, and OWASP-class injection or XSS paths that AI scaffolding often skips.

Privacy, cookies, and residency

What personal information you collect, where it is stored, and whether GDPR, UK GDPR, or Australian APPs are on the radar. We flag a Privacy Impact Assessment if the project needs one. We do not write the PIA.

Payments and billing

Stripe or similar wired through client-side secrets, webhooks that trust any payload, or receipts that leak other customers. Card data must never touch your server. Reviewed when payments exist or are about to.

Technical debt and tests

Generated files nobody owns, duplicated logic, no tests, and a stack that cannot be changed without asking the model again. We map what is salvageable versus what should be rebuilt.

Bugs and reliability

Race conditions, broken error paths, missing rate limits, and crashes that only appear with real traffic. Production-ready means it survives more than a demo.

Hosting, backups, and observability

Who owns the Vercel, Firebase, or Supabase project. Whether backups restore. Whether you would even know if the app went down or leaked data.

  • Ranked plain-English findings report, ordered by real risk, with a recommended fix for each item.
  • Salvage versus rewrite recommendation.
  • Itemised quote to harden or rewrite priority items. You approve before any code change.

Not included at $200 + GST

Harden, patch, or rewrite

Follow-on work, quoted from the report. You approve each item before we change production.

Privacy Impact Assessment

A full PIA is a separate scoped engagement. The audit flags when that is the honest next step.

Penetration test

This is a production-readiness audit of configuration, code, privacy flows, and debt. A pentest is a different engagement, useful only once the basics are in place.

Certificate or legal advice

We do not certify the app, stamp compliance, or give legal advice.

Org-wide cyber audit

Email, domain DNS, and devices sit on the Cyber Security Audit Melbourne page, from $1,300 + GST.

A new product from a pitch

We audit what is running. We do not vibe-code a product from a one-line idea.

Second and subsequent apps

The standard price is one app. Extra apps are quoted separately.

The seven surfaces

Do not go live until these are checked

The $200 standard audit inspects every surface below. Ranked findings, plain English, and a quote to harden or rewrite what is not safe to run with real users.

Seven production-readiness surfaces as a ranked risk map

Auth and secrets

Keys in the frontend, committed .env, sessions anyone can steal.

Access control and injection

One user reading another user's records or files.

Privacy, cookies, and residency

What you collect, where it lives, which privacy regime applies.

Payments and billing

Client-side Stripe secrets, webhooks that trust any payload.

Technical debt and tests

Unowned generated files, no tests, salvage versus rebuild.

Bugs and reliability

Race conditions, missing rate limits, crashes under real traffic.

Hosting, backups, and observability

Who owns hosting, whether backups restore, whether you would know.

Fit

Who this is for

Founders who vibe-coded an app and now have users

You built with Codex, Cursor, Lovable, Bolt, v0, Replit, Copilot or ChatGPT and people are signing up. You need a review of the existing work and a clear path to fix the unfinished or unsafe parts.

Teams about to take payments or store personal data

Stripe is wired, or about to be. Customer emails, files, or health-adjacent records sit in a database you did not design. Privacy rules follow your users, not your postcode.

IT teams inheriting a vibe-coded app

A founder shipped it. You now own hosting, backups, and the next patch advisory. We audit the repo so your preventative programme covers the product, not only the mailbox. We train. We do not run live incident response.

Not a fit for idea-only prompts with no access

If you will not share the repo, hosting, and admin accounts, we cannot audit what is running. Discovery is free. The $200 audit needs the eligibility above. We do not vibe-code a new product from a one-line pitch.

How it works

Audit, then quote, then optional rescue

Four stages. The $200 fee covers discovery through the ranked report. Harden or rewrite is approved item by item.

Four-stage path: discovery, review, ranked report, optional rescue
  1. Discovery

    A free Discovery Session to confirm eligibility, the stack, who uses it, and what production-ready means for you. If the $200 standard applies, that is the quote.

  2. Repo and infra review

    Read-only access to source, hosting, identity, and data stores. We inspect all seven surfaces in the contract.

  3. Ranked report

    Plain-English findings ordered by risk, with recommended fixes and an itemised quote to harden, patch, or rewrite.

  4. Harden or rewrite

    Optional follow-on, paid separately. You approve each item: security fixes, privacy controls, tests, observability, and the rebuilds that make the product actually production-ready.

Outcomes

What you walk away with

Ranked findings, not a scare PDF

Every issue is explained in plain English, ordered by real risk, with a recommended fix you can approve item by item.

Audit then rescue, same studio

You can use the report with your own developer or ask us to implement the priority repairs. Follow-on work is scoped and priced separately; you approve it before we start.

Privacy and security in one pass

Secrets in repos, open admin, missing access control, and personal-information flows are reviewed together so you do not pay twice for the same surface.

Book the $200 audit before you go live

Request a Discovery Session. The standard vibe coding audit is $200 + GST for one eligible app. Rescue work is quoted from the report, and you approve it before any code changes.

Request a Discovery Session

Questions

Straight answers

What is a vibe coding audit?

A production-readiness review of an AI-generated or vibe-coded app. We inspect the repo, hosting, security, privacy, technical debt, and bugs, then rank what must change before real users, payments, or regulators become a problem. It is not a certificate and it is not legal advice. The standard audit is $200 + GST for one eligible app.

How much does a vibe coding audit cost?

The Standard Vibe Coding Audit is $200 + GST for one eligible AI-generated app when you provide read-only repo and hosting access. That fee is the ranked written report and an itemised rescue quote. Harden, rewrite, a Privacy Impact Assessment, and extra apps are quoted separately. If eligibility fails, Discovery produces a separate quote. We do not shrink the seven-surface list to hit the price.

What is included in the $200 audit?

Inspection of all seven surfaces: auth and secrets; access control and injection; privacy, cookies, and residency; payments and billing; technical debt and tests; bugs and reliability; hosting, backups, and observability. You get a ranked plain-English report, a salvage versus rewrite call, and an itemised quote to fix priority items. Discovery is free. Typical window is one to two weeks after access.

Is my Lovable, Bolt, or Cursor app production-ready?

The tool name cannot answer that. We need to inspect the source, configuration and customer journeys. The review checks auth, access control, secrets, privacy, payments, reliability and maintainability so the recommendation follows evidence rather than assumptions about AI-generated code.

Can you finish the missing features after the audit?

Yes, as separately scoped implementation work. Common briefs include booking rules, verified payment handling, customer and staff roles, quoting, CRM connections and deployment. The report identifies risks; a follow-on quote defines the feature, acceptance checks and handover. These changes are not included in the $200 audit.

Do GDPR or Australian privacy rules apply if I built this from my laptop?

Privacy law follows the people whose data you collect, not where you wrote the prompts. EU users can trigger GDPR. Australian users can trigger the Privacy Act and APPs. UK users can trigger UK GDPR. We map what you collect and flag when a Privacy Impact Assessment is the next step. We do not certify you as compliant.

Do you rewrite the app or patch what I have?

We assess the interface, business logic, data and infrastructure separately. Useful code can be retained while weak parts are repaired or replaced. If a rewrite is recommended, the report explains the evidence and scope before you decide. Implementation is quoted separately and is not included in the $200 audit.

How long does a vibe coding audit take?

Most focused reviews of a single web or mobile app complete within one to two weeks after Discovery, depending on repo access and how quickly you answer questions about users and data.

Do I also need a Privacy Impact Assessment?

If the app collects personal information, uses AI on customer data, or has EU, UK, or Australian users, a threshold PIA is often the honest next step. The vibe coding audit flags that. A full PIA is a separate scoped engagement on our Privacy Impact Assessment Australia page.

Is this a penetration test?

No. It is a practical production-readiness audit: configuration, code, privacy flows, and debt. Full penetration testing is a different engagement and only useful once the basics are in place.

What if I only have a hosted preview and no Git repo?

We can still review the live app, hosting, and accounts, but that is outside the $200 standard. A repo makes the audit faster and the rescue cheaper. If the source only lives in a chat history, we will say so in Discovery and quote accordingly.

Do you only work with Melbourne clients?

No. We are Melbourne-based and deliver Australia-wide and internationally. Same process, same packages, remote by default. We meet in person across Melbourne when it helps.

Next step

Know what to keep. Know what to fix next.

Request a Discovery Session. The standard vibe coding audit is $200 + GST for one eligible app. Rescue work is quoted from the report, and you approve it before any code changes.