Vibe-coded apps · production audit · Melbourne

You shipped an AI-built app. It is not production ready.
Melbourne help for vibe-coded and AI-built apps that are live but insecure, full of bugs, and not ready for Australian or EU privacy rules. I audit what you shipped with Cursor, Lovable, Bolt, v0 or ChatGPT, then fix the security, bugs and technical debt so it can actually run in production.
Quoted after a look at the live app or repo · Melbourne-based delivery · Remote-friendly
- Melbourne-based · AEST-friendly
- Reply within one business day
- Fixed-price options where scope allows
- You own the data, code and systems
Pain pointsWhat usually hurts
01
You cannot explain what you shipped
Cursor, Lovable, Bolt, v0 or ChatGPT wrote most of it. It runs in a demo. You do not know what happens if a real user, a payment, or a bad actor hits it.
02
Privacy rules were never designed in
Customer names, emails and maybe payment-adjacent data sit in a database you did not lock down. Australian Privacy Act, GDPR if you have EU users, and cookie or consent basics were not part of the prompt.
03
Security is an afterthought
API keys in the frontend, Firestore or Supabase rules that allow read-all, auth that looks like login but does not protect records, admin pages with no real access control.
04
Bugs and debt show up at first real traffic
Error states are missing, retries duplicate charges, the model left dead code and conflicting patterns, and nobody can safely change it without breaking the happy path.
StackTools you probably used
- Cursor
- Lovable
- Bolt
- v0
- ChatGPT
- Claude
- Replit
- Firebase
- Supabase
- Stripe
- Vercel
- Next.js
OutcomesWhat improves
- A ranked list of what is actually dangerous versus cosmetic
- Secrets, auth and data access tightened so the demo is not an open door
- Privacy and consent gaps called out in plain language, not a lawyer stamp
- Bugs and debt sequenced so you can keep running or launch with eyes open
- Optional hands-on fixes after the audit, using the services below
AuditWhat I actually check
This is a production-readiness pass, not a tutorial on vibe coding. The point is to rank what will hurt you first, then fix it.
- Secrets and environment leaks (keys in the client, public repos, or plaintext configs)
- Auth that actually protects records, not just a login screen
- Database and storage rules (Firestore, Supabase, S3-style buckets, admin APIs)
- Payment and PII handling: Stripe (or similar) without storing card data, and who can read customer rows
- Error states, retries and duplicate-charge or duplicate-signup paths
- Hosting, backups and whether anyone can restore if Vercel, Firebase or the model vendor hiccups
- Privacy and consent gaps: what you collect, cookies, and whether EU or Australian rules even got a look
- Whether a human can safely change the code without breaking the happy path
HOW WE START
- Send the live URL or repo, what the app does, who uses it, and what done looks like.
- I review security, privacy and consent gaps, bugs and debt, then send a written ranked list.
- We agree a quote to fix what blocks launch or sleep, or I say honestly if a rebuild is cheaper.
RELATED OFFERS
After the audit, work usually lands in Cyber security & penetration testing, website repairs, or a CRM and payment rescue. No new product: the same Melbourne delivery, scoped to what you actually shipped.
- Cyber security & penetration testingSpecialised penetration testing for web apps, APIs and cloud-facing systems, with clear reports and fix guidance.Learn more →
- Website fixesTargeted fixes for broken layouts, slow pages, unreliable forms and tracking issues.Learn more →
- Workflow & CRM fixesFixed-price rescue work for broken Stripe, Firebase, CRM and internal workflows.Learn more →
FAQCommon questions
- Is a vibe-coded or AI-built app safe to launch?
- Usually not as shipped. Demos hide missing auth, leaked secrets, open data rules and unhandled error paths. A production-readiness audit ranks what will hurt you first so you can launch with eyes open, or pause until the doors are closed.
- Does my Lovable, Bolt or Cursor app need GDPR or Australian privacy work?
- If you collect names, emails, location or anything that identifies a person, Australian Privacy Act (APPs) applies to most Australian businesses. GDPR can apply if you have EU users. I review the technical gaps (what you store, who can read it, consent and cookies). I do not issue legal certificates or replace a lawyer. Counsel still owns legal opinions.
- Can you fix an app I did not write myself?
- Yes. Most of this work is reading someone else's (or a model's) code, mapping the live behaviour, then patching the dangerous parts. Send the live URL, repo if you have it, and how you deploy. I say early if a rebuild is cheaper than patching.
- What does a production-readiness audit include?
- Secrets and env leaks, auth and permissions, payment and PII handling, error states, backups, hosting, and basic privacy or consent gaps. You get a written ranked list and a quote to fix what blocks launch or sleep. Related: penetration testing when you need a scoped attack-surface test, or website fixes for launch blockers.
- How much does a vibe-coded app audit cost?
- Quoted after I see the live app or repo. A narrow broken payment or form path can fit a fixed-price workflow rescue from around A$699. Broader security and production audits are scoped like other specialised work, with written deliverables before we start. I will say if I am not the right fit.
Project brief
Send the live URL or repo
Tell me what the app does, who uses it, and what done looks like. I reply with whether an audit is the right first step.
- I reply within one business day — or say honestly if I am not the fit.
- Fixed-price rescue, phased build, or retainer — clear next step either way.
- Prefer phone? Call 0428 474 145