Safe to Ship: vibe code audit

Make your AI-coded app safe to publish

A colleague built a tool with Claude Code, Cursor or Codex. Now customers or company data depend on it, and nobody technical has checked it. SpotDev's software engineers audit it, fix what isn't safe, and our CTO signs off the version you use.

Request a Quote

We reply within an hour during UK business hours.

The security gaps AI tools leave, and how we close them

AI coding tools are very good at making software work and much less reliable at making it secure, because security is rarely in the prompt. SpotDev Safe to Ship is a fixed-price vibe code audit with fixes. These are the gaps we find most often in AI-built apps, and what we do about each one.

Without SpotDev

What we usually find

With SpotDev

How we fix it

Without SpotDev

Anyone can read the database

The login screen looks secure, but anyone who finds the database address can read every record.

With SpotDev

Locked down at the database

Access rules on every table, so each user reaches only the records they should.

Without SpotDev

Keys and passwords in the code

API keys sit in the code or the browser, where anyone who looks can copy them.

With SpotDev

Keys rotated and moved out

New keys, held in a secrets manager, never in the code.

Without SpotDev

Permissions on the screen only

Buttons are hidden from users who shouldn't press them, but the server still accepts the request.

With SpotDev

Permissions checked on the server

Every action is checked where it runs, not just where it is displayed.

Without SpotDev

No backups, no audit trail

If data is lost or changed, nobody can tell what happened or put it back.

With SpotDev

Backups and logging in place

Data can be restored, and every change can be traced.

Without SpotDev

Only the builder understands it

If they are away or leave, nobody can fix it.

With SpotDev

Documented for anyone to pick up

Another engineer can take it on from the repository and the documentation.

What a vibe code audit checks

The six places AI-built apps most often go wrong. We check every one, and fix what we find.

Who can see your data

We check that each user can reach only the records they should, in the database as well as on the screen, and close any gaps.

Exposed keys and passwords

We find API keys and passwords left in the code or the browser, then rotate them and move them into a secrets manager.

Vulnerable code and libraries

We check the code and the libraries it relies on for known vulnerabilities, unsafe patterns and errors that leak data.

Connections to your other systems

We check what each connection to your CRM, finance or other systems can reach, and narrow it to what the app needs.

Backups and recovery

We make sure your data is backed up, changes are logged, and the app can recover when something fails.

Who owns it

We check the code, hosting and accounts belong to the business, so nothing is lost if the builder leaves.

How the audit and fixes work

  1. 01

    Engineering review

    Our engineers work through all six areas, to the depth the tier requires.

  2. 02

    Report and walk-through

    A written report graded by severity, taken through with you on a call, with a clear keep, fix or rebuild recommendation.

  3. 03

    Fixes

    A fixed price for anything that needs fixing, either hardened where the app runs now or moved to infrastructure you own.

  4. 04

    CTO sign-off

    Our CTO reviews the fixed version and approves your application as 'Safe to Ship'.

Priced by what your app holds

A dashboard nobody outside the team sees needs a lighter review than software your customers log into. We agree the tier with you first, and it sets the fixed price, from £1,500.

Internal tool, no personal data

A dashboard, calculator or planner used only by your own team.

Internal tool with personal or financial data

A CRM add-on, an expenses tool, or anything holding customer or staff records.

Customer-facing tool

A portal, booking system or form that people outside your business use.

Software you sell to others

A product other businesses pay for, where their data and their contracts depend on it.

At the end

A signed-off app, and our access removed

You finish with written confirmation that an engineer has checked the version you use.

Signed off by our CTO

Our CTO signs off the version we reviewed and fixed: an experienced engineer would have been comfortable shipping it.

Covers the version you use

The sign-off applies to that version, on that date. It is not a guarantee against every attack, and no honest firm offers one.

NDA before we see the code

An NDA is in place first, and we ask for read-only access wherever the platform allows it.

Our access removed at the end

Where the app holds personal data we work under a data processing agreement, and we remove our access when the work ends.

Vibe code audit pricing, from £1,500

Every Safe to Ship engagement is a fixed price agreed before work starts and paid up front. The audit price depends on the app's risk tier. Prices exclude VAT.
  • Safe to Ship audit

    From £1,500

    A review of one app by our engineers, signed off by our CTO.

    • Priced by risk tier
    • Written report graded by severity
    • Walk-through with the engineers who did the review
    • A clear recommendation: keep, fix or rebuild
    • 20% of the fee credited against fixes committed within 30 days
  • Safe to Ship fixes

    From £1,500

    The fixes the audit identified, at a fixed price.

    • Hardened in place, or moved to infrastructure you own
    • Database access rules and authentication fixed
    • Keys rotated and moved into a secrets manager
    • Backups and logging in place
    • Re-review and CTO sign-off

Engineers who check what AI builds

SpotDev is an AI and digital transformation consultancy that builds real software, with an in-house, fully remote engineering team. We use AI coding tools in our own engineering every day, so we know where they cut corners.

5.0from 38 client reviews
  • Claude Developer certified

    All our developers hold the Claude Developer accreditation.

  • Codex Deployment certified

    Work with engineers that hold OpenAI's Codex Deployment certification

  • Cursor-experienced engineers

    SpotDev has been building on Cursor for years and it's our in-house IDE.

Security you can check

  • Cyber Essentials Plus
  • CTO sign-off on every audit
  • NDA before code access
  • In-house engineers

Common questions

What is a vibe code audit?

A review by experienced engineers of software built mainly with AI coding tools, looking for the security, reliability and ownership problems those tools tend to leave behind. SpotDev Safe to Ship is our fixed-price version: the audit, fixes where needed, and a sign-off from our CTO.

Is vibe-coded software secure?

It can be, but AI coding tools rarely make it secure by default. They build what they are asked for, and the prompt rarely mentions database access rules, secrets or backups. A published vulnerability record from 2025, CVE-2025-48757, described apps generated with Lovable whose database rules let unauthenticated visitors read or write data. Lovable disputes it, on the basis that each customer is responsible for protecting their own application's data. Either way, the accountability sits with the business running the app.

Can you review an app built with Claude Code, Cursor or Codex?

Yes. We review apps built with Claude Code, Codex, Cursor, Lovable, Replit and similar tools, and code written without AI. The problems we look for are the same whichever tool produced them.

How much does a vibe code audit cost?

Our audits start from £1,500 and depend on the app's risk tier. Fixes start from £1,500 and are quoted as a fixed price from the audit findings. If you commit to fixes within 30 days of the audit, 20% of the audit fee comes off the price. Prices exclude VAT.

Will you tell us to rebuild everything?

Only if that is genuinely the right answer. Most apps can be made safe where they are. If a rebuild is needed, the report explains why, so you can decide with the evidence in front of you.

Can the app stay on Lovable or Replit?

Often, yes. We can harden it where it runs by fixing database access rules, authentication and keys. Where moving it to infrastructure your business owns would be safer, we say so and quote both routes.

How long does an audit take?

It depends on the risk tier and the size of the app. We confirm a delivery date alongside the fixed price, before any work starts.

Does the sign-off mean the app cannot be hacked?

No, and no honest firm would promise that. It means an experienced engineer has reviewed that version and would have been comfortable shipping it, on the date we reviewed it.

What happens after the fixes?

If your team will keep building, Ready to Build sets up the tools and checks that stop the same problems coming back, and trains your builder to use them.

Tell us about the app

Describe what it does, who uses it and what data it holds. We reply within one business day with the risk tier and a fixed price for the audit.