Often, yes. First answer five questions: what data the tool holds, who can log in, where it is hosted, who owns the code and accounts, and who maintains it. A team-only tool with no personal data can usually carry on with light checks. If it holds customer or financial data, can be reached from the internet or sits on a personal account, have an engineer review it first.
Many of the enquiries we receive about AI-built software begin with some version of this post's title. Someone in operations or finance used Claude, Claude Code, Lovable or Cursor to build the tool the team had wanted for years. It works and people rely on it. Now the managing director wants to know what the business has actually got.
The UK's National Cyber Security Centre takes a sensible line. Its June 2026 post on the "vibe coding spectrum" says that building this way for proofs of concept and low-risk internal tools "can often be perfectly fine", and that authentication, sensitive customer data and anything handling secret tokens or credentials need more rigour. This post helps you work out which side of that line your colleague's tool sits on, and what to do about it. Where the answers point to real risk, a vibe code audit is the next step.
What are the five questions to answer first?
Ask the colleague who built it to answer these with you. They know the tool better than anyone, and most of the answers take minutes.
| Question | What you are trying to find out | Bring in an engineer when |
|---|---|---|
| 1. What data does it hold? | Whether it stores or reads personal data about customers or staff, financial records, or anything covered by a client contract. | It holds personal or financial data, or connects to a system that does, such as your CRM, finance system or shared drive. |
| 2. Who can log in? | Whether it is used by the builder alone, the team, or people outside the company, and how people sign in. | Anyone outside the company can reach it, or it has its own login screen that the AI tool wrote. |
| 3. Where is it hosted? | Whether it runs on the builder's laptop, on a platform such as Lovable or Replit, or on a hosting account. | It is on the public internet, particularly on a free or personal plan. |
| 4. Who owns the code and accounts? | Whose name is on the code repository, the hosting, the database, the domain and the AI tool subscription, and whose card pays for them. | Any of them belong to the colleague personally. This usually calls for a move into company accounts (below) before it calls for a review. |
| 5. Who maintains it? | Who fixes it when it breaks, and whether anyone else could. | Part of the business would stop if it broke and only one person understands it. |
A workable threshold: if question one or two triggers, have an engineer review the tool before more people depend on it. If only questions four and five trigger, the priority is moving it into company accounts and writing down how it works. Our risk guide for apps built with AI sets out the levels of risk in more detail.
Personal data deserves the most attention because the duty sits with the business. If the tool leaks customer records and that is likely to put people at risk, the ICO's guidance is that you must report it "without undue delay, but not later than 72 hours after becoming aware of it". The ICO also expects you to record every breach, whether or not you report it. Who built the tool, and what wrote the code, does not change that.
How do you move it from a personal account into the company?
This step is easy to skip, and it matters at every level of risk. A tool built on a colleague's own accounts belongs, in practice, to whoever holds the passwords. If they leave, fall ill or let a card expire, the business can lose access to something it now runs on. Work through it in this order.
- Move the code into a company GitHub organisation. Create an organisation in the company's name with at least two owners, then transfer the repository into it. GitHub's documentation says issues, pull requests and commit history move with the repository, and links to the old location redirect automatically. The person transferring needs administrator access to the repository and permission to create repositories in the organisation. If the tool was built in Lovable with GitHub sync switched on, connect Lovable to the new organisation before you transfer: Lovable's documentation says that without a connection for the new owner, it disconnects the project.
- Put hosting, database and domain accounts in the company's name. Pay for them on a company card and give at least two people administrator access. If the tool lives on Lovable or Replit, our post on taking a Lovable or Replit app to production covers what has to change on those platforms.
- Rotate every key and password the tool uses. Treat any credential that sat in a personal account, on a personal laptop, in the code history or pasted into an AI chat as exposed. GitHub's guidance on sensitive data says the first step for a leaked secret is to revoke or rotate it, and that rewriting the repository's history on its own can leave the old commits accessible elsewhere. Keep the new values in a secrets manager, out of the code.
- Write it down. One page is enough to start: what the tool does, where it runs, which accounts it depends on, how to release a change and how to restore it from a backup. If nobody can write the restore step, you have found your first problem.
- Move the AI tool onto business terms. The next section explains why this matters.
Consumer and business terms for the AI tool
The AI subscription matters because the code, and anything your colleague pasted into the chat, went through it. A paid personal plan is still a personal plan. Here is what Anthropic and OpenAI say on their own pages, checked on 8 Oct 2026.
| Vendor | Personal plans | Business plans |
|---|---|---|
| Anthropic (Claude, Claude Code) | Free, Pro and Max are consumer plans. Anthropic trains new models on the data when the user's model-improvement setting is on. Claude Code data is kept for five years with that setting on and 30 days with it off. | Team, Enterprise and the API are under commercial terms. Anthropic does not train models on code or prompts sent to Claude Code unless the customer chooses to share them. Standard retention for Claude Code data is 30 days. |
| OpenAI (ChatGPT, Codex) | For services for individuals, such as ChatGPT and Codex, OpenAI may use content to train its models. The user can opt out in Data controls or the Privacy Portal. | Inputs and outputs from ChatGPT Business, ChatGPT Enterprise, ChatGPT Edu and the API are not used to train models by default. |
Two details are easy to miss. OpenAI says Codex has a separate setting for allowing training on full environments, and changing the ChatGPT setting does not change it. And moving to a business plan governs what happens from now on, so ask your colleague which settings were on while they built the tool. Whether Claude itself is suitable for your company's data is a separate question, covered in our guide to Claude, GDPR and business use.
This move is most of what our Claude Code, Codex and Cursor setup for business teams covers, along with a safe way for your colleague to keep building in company accounts.
Should you keep it, fix it or rebuild it?
Once the five questions are answered, the decision usually falls into one of three places.
| Decision | Usually right when | What it involves |
|---|---|---|
| Keep it as it is | Only the team uses it, it holds no personal or financial data, it sits in company accounts and someone besides the builder knows how it works. | The move into company accounts, a short write-up and a named owner. |
| Fix it | It holds personal data or can be reached from the internet, but it does its job and the overall design is sound. | An engineer's review, then targeted fixes, typically to database access rules, login, keys and hosting. |
| Rebuild it | The design itself is the problem, or fixing it would cost more than starting again. | A planned rebuild that keeps what the first version taught you about the job. |
Most apps can be made safe where they are, so a rebuild should need a reason you can see written down. Built-in security scanners help, but they do not settle the question. Lovable's own security documentation says its tools "cannot guarantee complete security" and suggests an additional professional security review for apps handling sensitive data or critical functionality.
That written evidence is what a review of an AI-built app should give you: what was found, how serious each item is and what fixing it would cost, so you can decide between fixing and rebuilding with the facts in front of you.
How do you raise it with the colleague without discouraging them?
The colleague who built the tool has usually done the business a favour. They spotted a problem, solved it without a budget and saved people time. Say that first, and mean it, because the way this conversation goes decides whether the next tool is built in the open or in private.
Explain the review as the company's job. Customer data, accounts and contracts are the business's responsibility, so checking them is something the company owes its customers. It says nothing about the colleague's competence, and a good engineer will check the work of experienced developers in exactly the same way.
Ask them to lead the walkthrough using the five questions above. People who build tools tend to know where the weak spots are, and they will often raise the gaps before you do. Agree who owns what afterwards: they stay the person who knows what the tool should do, and the company holds the accounts.
Avoid switching the tool off unless something is exposed right now, such as customer data readable without a login or a live key in a public repository. In that case, contain it first by locking down access and rotating keys, then talk.
Finally, give them an approved way to build the next one. That means company accounts from day one, a business plan for the AI tool and a written rule everyone can follow. Our AI policy template for UK businesses is a starting point for the rule, and our guide on setting up Claude Code safely for a business team covers the tooling. If one person has built a tool this way, others probably have too, and a shadow AI review will show you where.
How SpotDev can help
SpotDev Safe to Ship is a fixed-price vibe code audit for tools built with Claude Code, Cursor, Codex, Lovable or Replit: our engineers review the app, fix what is not safe at a fixed price quoted from the findings, and our CTO signs off the reviewed version. The sign-off covers that version on that date and is not a guarantee against every attack. Audits start from £1,500, priced by what the app holds and who uses it, and prices exclude VAT. If the bigger job is the move into company accounts and a safe way for your colleague to keep building, SpotDev Ready to Build sets that up from £4,000.
Frequently asked questions
Is a tool built with Claude, Lovable or Cursor unsafe by default?
No. The NCSC says building this way for proofs of concept and low-risk internal tools can often be fine. The risk depends on what the tool does: whether it holds personal or financial data, who can reach it, and how it handles logins and keys. A team-only tool with no personal data needs light checks. Anything customer-facing or holding sensitive data needs an engineer's review before the business relies on it.
Who is responsible if a colleague's AI-built tool leaks customer data?
Where the tool processes personal data for the business, the business normally carries the UK GDPR duties for it, whoever built it and whatever wrote the code. A breach that is likely to put people at risk must be reported to the ICO without undue delay and within 72 hours of becoming aware of it, and every breach should be recorded. Take legal advice on the specifics of your situation.
How do we move an app built on a personal account into the company?
Create a GitHub organisation in the company's name and transfer the repository into it. Move the hosting, database and domain accounts into company ownership with at least two administrators. Rotate every key and password the app uses and keep the new ones in a secrets manager. Write a one-page description of how it runs and how to restore it. Then move the AI tool onto a business plan.
Is a paid Claude Pro or ChatGPT Plus plan a business plan?
No. Anthropic treats Free, Pro and Max as consumer plans, where training on your data depends on the user's model-improvement setting. OpenAI treats ChatGPT and Codex for individuals as personal services that may train on content unless the user opts out. Under Claude Team, Enterprise and the API, Anthropic does not train on Claude Code prompts or code unless the customer opts in, and OpenAI does not use ChatGPT Business, Enterprise or API inputs and outputs for training by default.
Should we tell our colleague to stop using the tool?
Usually not. Unless something is exposed right now, such as customer data readable without a login or a live key in a public repository, keep it running while you answer the five questions and move it into company accounts. If something is exposed, contain it first by locking down access and rotating the keys, then review it. Afterwards, give your colleague an approved way to keep building.
How much does a review of an AI-built app cost?
SpotDev Safe to Ship starts from £1,500 for the vibe code audit, priced by risk tier, from an internal tool with no personal data up to software you sell to others. Fixes start from £1,500 at a fixed price based on the findings. If you commit to fixes within 30 days of the audit, 20% of the audit fee is credited against them. Prices exclude VAT.
Sources
- NCSC, The 'vibe coding spectrum' approach to AI-assisted software development, 18 Jun 2026
- ICO, Personal data breaches: a guide, accessed 8 Oct 2026
- GitHub Docs, Transferring a repository, accessed 8 Oct 2026
- GitHub Docs, Removing sensitive data from a repository, accessed 8 Oct 2026
- Lovable Docs, Sync your Lovable project with GitHub, accessed 8 Oct 2026
- Lovable Docs, Security overview, accessed 8 Oct 2026
- Anthropic, Claude Code Docs: Data usage, accessed 8 Oct 2026
- OpenAI Help Center, How your data is used to improve model performance, accessed 8 Oct 2026
- OpenAI, Enterprise privacy at OpenAI, updated 8 Jan 2026
Get new articles by email
Practical guides from the SpotDev team, when we publish them.
By submitting this form, you consent to us sending you emails with our latest content. Privacy Policy



