Auth and secrets
Keys in the frontend, committed .env files, default admin, and session handling that lets anyone become someone else.
Vibe coding audit
You shipped an AI-generated app with Cursor, Lovable, Bolt, v0, Replit, or Copilot. Looks done is not live. We audit the repo, security, privacy, and debt for $200 + GST, then quote the rescue. Melbourne-based. Australia-wide and international.
This is not theoretical
Mathspace is an education product, not a weekend demo. Attackers used administrator access on unpatched internal reporting software. Vibe-coded apps fail the same way: open admin, skipped patches, and no one owning the stack.

A weekend demo is not a product. Real users, real cards, real privacy law.
Demo versus live
The interface can look finished in a weekend. Production-ready means strangers can use it without leaking keys, data, or card details.
What the prompt shipped
What production needs
The standard
Same seven surfaces every time. Ranked written report. Rescue is quoted after. If eligibility fails, Discovery produces a separate quote.
Standard Vibe Coding Audit
$200 + GST
One AI-generated app. Ranked written report.
Typical window: one to two weeks after access
Request a Discovery SessionPrice applies when
Included at $200 + GST
Keys in the frontend, committed .env files, default admin, and session handling that lets anyone become someone else.
Who can read or write whose data. Open storage buckets, and OWASP-class injection or XSS paths that AI scaffolding often skips.
What personal information you collect, where it is stored, and whether GDPR, UK GDPR, or Australian APPs are on the radar. We flag a Privacy Impact Assessment if the project needs one. We do not write the PIA.
Stripe or similar wired through client-side secrets, webhooks that trust any payload, or receipts that leak other customers. Card data must never touch your server. Reviewed when payments exist or are about to.
Generated files nobody owns, duplicated logic, no tests, and a stack that cannot be changed without asking the model again. We map what is salvageable versus what should be rebuilt.
Race conditions, broken error paths, missing rate limits, and crashes that only appear with real traffic. Production-ready means it survives more than a demo.
Who owns the Vercel, Firebase, or Supabase project. Whether backups restore. Whether you would even know if the app went down or leaked data.
Not included at $200 + GST
Follow-on work, quoted from the report. You approve each item before we change production.
A full PIA is a separate scoped engagement. The audit flags when that is the honest next step.
This is a production-readiness audit of configuration, code, privacy flows, and debt. A pentest is a different engagement, useful only once the basics are in place.
We do not certify the app, stamp compliance, or give legal advice.
Email, domain DNS, and devices sit on the Cyber Security Audit Melbourne page, from $1,300 + GST.
We audit what is running. We do not vibe-code a product from a one-line idea.
The standard price is one app. Extra apps are quoted separately.
The seven surfaces
The $200 standard audit inspects every surface below. Ranked findings, plain English, and a quote to harden or rewrite what is not safe to run with real users.
Keys in the frontend, committed .env, sessions anyone can steal.
One user reading another user's records or files.
What you collect, where it lives, which privacy regime applies.
Client-side Stripe secrets, webhooks that trust any payload.
Unowned generated files, no tests, salvage versus rebuild.
Race conditions, missing rate limits, crashes under real traffic.
Who owns hosting, whether backups restore, whether you would know.
Fit
You built with Cursor, Lovable, Bolt, v0, Replit, Copilot, or ChatGPT and people are signing up. You cannot answer where data lives, who can see it, or what happens if the next prompt breaks production.
Stripe is wired, or about to be. Customer emails, files, or health-adjacent records sit in a database you did not design. Privacy rules follow your users, not your postcode.
A founder shipped it. You now own hosting, backups, and the next patch advisory. We audit the repo so your preventative programme covers the product, not only the mailbox. We train. We do not run live incident response.
If you will not share the repo, hosting, and admin accounts, we cannot audit what is running. Discovery is free. The $200 audit needs the eligibility above. We do not vibe-code a new product from a one-line pitch.
How it works
Four stages. The $200 fee covers discovery through the ranked report. Harden or rewrite is approved item by item.
A free Discovery Session to confirm eligibility, the stack, who uses it, and what production-ready means for you. If the $200 standard applies, that is the quote.
Read-only access to source, hosting, identity, and data stores. We inspect all seven surfaces in the contract.
Plain-English findings ordered by risk, with recommended fixes and an itemised quote to harden, patch, or rewrite.
Optional follow-on, paid separately. You approve each item: security fixes, privacy controls, tests, observability, and the rebuilds that make the product actually production-ready.
Outcomes
Every issue is explained in plain English, ordered by real risk, with a recommended fix you can approve item by item.
Most clients ask us to harden or rewrite the priority items as fixed-price follow-on work. You approve each item before we start.
Secrets in repos, open admin, missing access control, and personal-information flows are reviewed together so you do not pay twice for the same surface.
Request a Discovery Session. The standard vibe coding audit is $200 + GST for one eligible app. Rescue work is quoted from the report, and you approve it before any code changes.
Request a Discovery SessionProof
Real builds, not stock screenshots. See how the craft lands for clients like you.

Case study
Case study: Luxora Hair, a custom Australian luxury hair ecommerce platform.
View project
Case study
Case study: One Line Loop, an email-first daily journaling app.
View project
Case study
Case study: AutoSizer, a browser-first image resizer for marketplaces.
View projectQuestions
A production-readiness review of an AI-generated or vibe-coded app. We inspect the repo, hosting, security, privacy, technical debt, and bugs, then rank what must change before real users, payments, or regulators become a problem. It is not a certificate and it is not legal advice. The standard audit is $200 + GST for one eligible app.
The Standard Vibe Coding Audit is $200 + GST for one eligible AI-generated app when you provide read-only repo and hosting access. That fee is the ranked written report and an itemised rescue quote. Harden, rewrite, a Privacy Impact Assessment, and extra apps are quoted separately. If eligibility fails, Discovery produces a separate quote. We do not shrink the seven-surface list to hit the price.
Inspection of all seven surfaces: auth and secrets; access control and injection; privacy, cookies, and residency; payments and billing; technical debt and tests; bugs and reliability; hosting, backups, and observability. You get a ranked plain-English report, a salvage versus rewrite call, and an itemised quote to fix priority items. Discovery is free. Typical window is one to two weeks after access.
Usually not on day one. Tools like Lovable, Bolt, v0, Replit, Copilot, and Cursor are strong at shipping a demo. Production-ready means auth, access control, secrets, privacy, backups, and a codebase a human can maintain. That is the gap we audit.
Privacy law follows the people whose data you collect, not where you wrote the prompts. EU users can trigger GDPR. Australian users can trigger the Privacy Act and APPs. UK users can trigger UK GDPR. We map what you collect and flag when a Privacy Impact Assessment is the next step. We do not certify you as compliant.
Whichever is cheaper and safer. Salvageable code gets hardened. Generated spaghetti that cannot be tested or secured gets a scoped rewrite. You see the recommendation and the quote before we change anything. That rescue work is not included in the $200 audit.
Most focused reviews of a single web or mobile app complete within one to two weeks after Discovery, depending on repo access and how quickly you answer questions about users and data.
If the app collects personal information, uses AI on customer data, or has EU, UK, or Australian users, a threshold PIA is often the honest next step. The vibe coding audit flags that. A full PIA is a separate scoped engagement on our Privacy Impact Assessment Australia page.
No. It is a practical production-readiness audit: configuration, code, privacy flows, and debt. Full penetration testing is a different engagement and only useful once the basics are in place.
We can still review the live app, hosting, and accounts, but that is outside the $200 standard. A repo makes the audit faster and the rescue cheaper. If the source only lives in a chat history, we will say so in Discovery and quote accordingly.
No. We are Melbourne-based and deliver Australia-wide and internationally. Same process, same packages, remote by default. We meet in person across Melbourne when it helps.
Official guidance
Next step
Request a Discovery Session. The standard vibe coding audit is $200 + GST for one eligible app. Rescue work is quoted from the report, and you approve it before any code changes.