Vibe coding audit

Vibe-coded apps, made production ready

You shipped an AI-generated app with Cursor, Lovable, Bolt, v0, Replit, or Copilot. We audit the repo, security, privacy, and technical debt, then quote the work that makes it production-ready. Melbourne-based. Australia-wide and international.

Scoped quote before workMelbourne · Australia · WorldwideDiscovery Session
Vibe Coding Audit

Production readiness

What we actually inspect

A vibe coding audit is a production-readiness review of the app you already shipped. Ranked findings, plain English, and a fixed quote to harden or rewrite what is not safe to run with real users.

Auth and secrets

API keys in the frontend, .env files committed, default admin passwords, and session handling that lets anyone become someone else.

Access control and injection

Who can read or write whose data. Missing row-level checks, open storage buckets, and OWASP-class injection or XSS paths that AI scaffolding often skips.

Privacy, cookies, and residency

What personal information you collect, where it is stored, and whether GDPR, UK GDPR, or Australian APPs are even on the radar. Threshold for a Privacy Impact Assessment if the project needs one.

Payments and billing

Stripe or similar wired through client-side secrets, webhooks that trust any payload, or receipts that leak other customers. Card data must never touch your server.

Technical debt and tests

Generated files nobody owns, duplicated logic, no tests, and a stack that cannot be changed without asking the model again. We map what is salvageable versus what should be rebuilt.

Bugs and reliability

Race conditions, broken error paths, missing rate limits, and crashes that only appear with real traffic. Production-ready means it survives more than a demo.

Hosting, backups, and observability

Who owns the Vercel, Firebase, or Supabase project. Whether backups restore. Whether you would even know if the app went down or leaked data.

Fit

Who this is for

Founders who vibe-coded an app and now have users

You built with Cursor, Lovable, Bolt, v0, Replit, Copilot, or ChatGPT and people are signing up. You cannot answer where data lives, who can see it, or what happens if the next prompt breaks production.

Teams about to take payments or store personal data

Stripe is wired, or about to be. Customer emails, files, or health-adjacent records sit in a database you did not design. Privacy rules follow your users, not your postcode.

Not a fit for idea-only prompts with no access

If you will not share the repo, hosting, and admin accounts, we cannot audit what is running. Discovery is free. The audit is scoped. We do not vibe-code a new product from a one-line pitch.

Industries

Where we show up most

Consumer and marketplace apps

Sign-up, messaging, bookings, or listings generated in a weekend. Auth, file uploads, and public APIs are where vibe-coded products leak first.

Internal tools that escaped the founder laptop

A Cursor-built admin that now runs quoting, roster, or customer files for a real team. One shared login and no backups is not a production system.

SaaS experiments with EU, UK, or Australian users

GDPR, UK GDPR, and the Australian Privacy Act apply based on who you collect from. A Melbourne ABN does not exempt EU residents. We map the gap; we do not sell a compliance certificate.

Outcomes

What you walk away with

Ranked findings, not a scare PDF

Every issue is explained in plain English, ordered by real risk, with a recommended fix you can approve item by item.

Audit then rescue, same studio

Most clients ask us to harden or rewrite the priority items as fixed-price follow-on work. You approve each item before we start.

Privacy and security in one pass

Secrets in repos, open admin, missing access control, and personal-information flows are reviewed together so you do not pay twice for the same surface.

How it works

A process without black boxes

  1. Discovery

    A Discovery Session to map the stack, how it was generated, who uses it, and what production-ready means for you. Fixed quote before any audit starts.

  2. Repo and infra review

    Read-only access to source, hosting, identity, and data stores. We inspect auth, secrets, privacy flows, debt, and the surfaces attackers or regulators would hit first.

  3. Ranked report

    Plain-English findings ordered by risk, with recommended fixes and a scoped quote to harden, patch, or rewrite.

  4. Harden or rewrite

    Optional follow-on work you approve item by item: security fixes, privacy controls, tests, observability, and the rebuilds that make the product actually production-ready.

Get a scoped quote before any work starts

Request a Discovery Session. We will look at how the app was built, what is exposed, and send a fixed quote before any audit or rescue work starts.

Request a Discovery Session

Questions

Straight answers

What is a vibe coding audit?

A production-readiness review of an AI-generated or vibe-coded app. We inspect the repo, hosting, security, privacy, technical debt, and bugs, then rank what must change before real users, payments, or regulators become a problem. It is not a certificate and it is not legal advice.

Is my Lovable, Bolt, or Cursor app production-ready?

Usually not on day one. Tools like Lovable, Bolt, v0, Replit, Copilot, and Cursor are strong at shipping a demo. Production-ready means auth, access control, secrets, privacy, backups, and a codebase a human can maintain. That is the gap we audit.

Do GDPR or Australian privacy rules apply if I built this from my laptop?

Privacy law follows the people whose data you collect, not where you wrote the prompts. EU users can trigger GDPR. Australian users can trigger the Privacy Act and APPs. UK users can trigger UK GDPR. We map what you collect and flag when a Privacy Impact Assessment is the next step. We do not certify you as compliant.

Do you rewrite the app or patch what I have?

Whichever is cheaper and safer. Salvageable code gets hardened. Generated spaghetti that cannot be tested or secured gets a scoped rewrite. You see the recommendation and the quote before we change anything.

How long does a vibe coding audit take?

Most focused reviews of a single web or mobile app complete within one to two weeks after Discovery, depending on repo access and how quickly you answer questions about users and data.

Do I also need a Privacy Impact Assessment?

If the app collects personal information, uses AI on customer data, or has EU, UK, or Australian users, a threshold PIA is often the honest next step. The vibe coding audit flags that. A full PIA is a separate scoped engagement on our Privacy Impact Assessment Australia page.

Is this a penetration test?

No. It is a practical production-readiness audit: configuration, code, privacy flows, and debt. Full penetration testing is a different engagement and only useful once the basics are in place.

What if I only have a hosted preview and no Git repo?

We can still review the live app, hosting, and accounts. A repo makes the audit faster and the rescue cheaper. If the source only lives in a chat history, we will say so in Discovery and quote accordingly.

Do you only work with Melbourne clients?

No. We are Melbourne-based and deliver Australia-wide and internationally. Same process, same packages, remote by default. We meet in person across Melbourne when it helps.

Next step

Make the app you shipped actually production-ready.

Request a Discovery Session. We will look at how the app was built, what is exposed, and send a fixed quote before any audit or rescue work starts.