Who can see your data
We check that each user can reach only the records they should, in the database as well as on the screen, and close any gaps.
Safe to Ship: vibe code audit
A colleague built a tool with Claude Code, Cursor or Codex. Now customers or company data depend on it, and nobody technical has checked it. SpotDev's software engineers audit it, fix what isn't safe, and our CTO signs off the version you use.
We reply within an hour during UK business hours.
AI coding tools are very good at making software work and much less reliable at making it secure, because security is rarely in the prompt. SpotDev Safe to Ship is a fixed-price vibe code audit with fixes. These are the gaps we find most often in AI-built apps, and what we do about each one.
The login screen looks secure, but anyone who finds the database address can read every record.
Access rules on every table, so each user reaches only the records they should.
API keys sit in the code or the browser, where anyone who looks can copy them.
New keys, held in a secrets manager, never in the code.
Buttons are hidden from users who shouldn't press them, but the server still accepts the request.
Every action is checked where it runs, not just where it is displayed.
If data is lost or changed, nobody can tell what happened or put it back.
Data can be restored, and every change can be traced.
If they are away or leave, nobody can fix it.
Another engineer can take it on from the repository and the documentation.
The six places AI-built apps most often go wrong. We check every one, and fix what we find.
We check that each user can reach only the records they should, in the database as well as on the screen, and close any gaps.
We find API keys and passwords left in the code or the browser, then rotate them and move them into a secrets manager.
We check the code and the libraries it relies on for known vulnerabilities, unsafe patterns and errors that leak data.
We check what each connection to your CRM, finance or other systems can reach, and narrow it to what the app needs.
We make sure your data is backed up, changes are logged, and the app can recover when something fails.
We check the code, hosting and accounts belong to the business, so nothing is lost if the builder leaves.
Our engineers work through all six areas, to the depth the tier requires.
A written report graded by severity, taken through with you on a call, with a clear keep, fix or rebuild recommendation.
A fixed price for anything that needs fixing, either hardened where the app runs now or moved to infrastructure you own.
Our CTO reviews the fixed version and approves your application as 'Safe to Ship'.
A dashboard nobody outside the team sees needs a lighter review than software your customers log into. We agree the tier with you first, and it sets the fixed price, from £1,500.
A dashboard, calculator or planner used only by your own team.
A CRM add-on, an expenses tool, or anything holding customer or staff records.
A portal, booking system or form that people outside your business use.
A product other businesses pay for, where their data and their contracts depend on it.
You finish with written confirmation that an engineer has checked the version you use.
Our CTO signs off the version we reviewed and fixed: an experienced engineer would have been comfortable shipping it.
The sign-off applies to that version, on that date. It is not a guarantee against every attack, and no honest firm offers one.
An NDA is in place first, and we ask for read-only access wherever the platform allows it.
Where the app holds personal data we work under a data processing agreement, and we remove our access when the work ends.
From £1,500
A review of one app by our engineers, signed off by our CTO.
From £1,500
The fixes the audit identified, at a fixed price.
SpotDev is an AI and digital transformation consultancy that builds real software, with an in-house, fully remote engineering team. We use AI coding tools in our own engineering every day, so we know where they cut corners.
All our developers hold the Claude Developer accreditation.
Work with engineers that hold OpenAI's Codex Deployment certification
SpotDev has been building on Cursor for years and it's our in-house IDE.
A review by experienced engineers of software built mainly with AI coding tools, looking for the security, reliability and ownership problems those tools tend to leave behind. SpotDev Safe to Ship is our fixed-price version: the audit, fixes where needed, and a sign-off from our CTO.
It can be, but AI coding tools rarely make it secure by default. They build what they are asked for, and the prompt rarely mentions database access rules, secrets or backups. A published vulnerability record from 2025, CVE-2025-48757, described apps generated with Lovable whose database rules let unauthenticated visitors read or write data. Lovable disputes it, on the basis that each customer is responsible for protecting their own application's data. Either way, the accountability sits with the business running the app.
Yes. We review apps built with Claude Code, Codex, Cursor, Lovable, Replit and similar tools, and code written without AI. The problems we look for are the same whichever tool produced them.
Our audits start from £1,500 and depend on the app's risk tier. Fixes start from £1,500 and are quoted as a fixed price from the audit findings. If you commit to fixes within 30 days of the audit, 20% of the audit fee comes off the price. Prices exclude VAT.
Only if that is genuinely the right answer. Most apps can be made safe where they are. If a rebuild is needed, the report explains why, so you can decide with the evidence in front of you.
Often, yes. We can harden it where it runs by fixing database access rules, authentication and keys. Where moving it to infrastructure your business owns would be safer, we say so and quote both routes.
It depends on the risk tier and the size of the app. We confirm a delivery date alongside the fixed price, before any work starts.
No, and no honest firm would promise that. It means an experienced engineer has reviewed that version and would have been comfortable shipping it, on the date we reviewed it.
If your team will keep building, Ready to Build sets up the tools and checks that stop the same problems coming back, and trains your builder to use them.
SpotDev is an OpenAI Select Partner and a HubSpot Diamond Solutions Partner, and is Certified in the Claude Partner Network. SpotDev is a separate company from OpenAI, Anthropic and the makers of the other tools named on this page, and partner status does not constitute endorsement of SpotDev. OpenAI and ChatGPT are trademarks of OpenAI. Claude is a trademark of Anthropic, PBC. Other product names are trademarks of their owners.