Skip to content
SELFOIA
Free check
Open menu

Vibe Code Audit · Security & code review for AI-built apps

Vibe Code Audit: find the problems in your AI‑built app before your customers do.

A Vibe Code Audit is a fixed-price review of an app built with Lovable, Bolt, Cursor, Replit or another AI tool. We check five areas (leaks, break-ins, money, speed and your safety net) and send a plain-English report with a fix prompt for every finding in 3 business days, for $500 at launch.

Launch price for the first 10 audits, then $950 · We take 3 new audits a week · Every report is read and signed by Denys.

Example reportyour-app.example
  • Anyone can read your users tableCritical
  • Admin page opens without logging inCritical
  • Unlimited password guesses on loginHigh
  • Backups never tested, files not includedHigh
  • AI cost per user is unknownMedium
  • Order list loads every row at onceMedium
Read and signed by Denys

Is an audit right for you now?

You built something real with AI. An audit makes sense once there's something to lose:

  • You take payments, or you're about to.

  • You store personal data: names, emails, files, messages.

  • A customer, partner or investor asked about security.

  • Your AI bill jumped and you don't know why.

  • You're scared to change anything because the last fix broke something else.

Not a fit: Hobby projects with no users, companies with their own security team, and anyone who needs a formal penetration test for compliance.

What does a vibe code audit check?

Five zones, 24 common problems, plus anything specific to your app. We run the free scanners first, so your fee goes on what they miss.

01 · Leaks

“Can anyone see my keys or my users' data?”

  • E01Keys anyone can copy. Secret keys for OpenAI, Anthropic, Stripe or Supabase shipped inside your pages, where any visitor can take them and spend your money. (Public “publishable” keys are fine; we tell you which is which.)
  • E02A database open to strangers. Supabase Row Level Security (RLS), the rules that decide who can read and change which rows, switched off or too loose. Or Firebase rules still in “test mode”.
  • E03Private files anyone can open. Uploads stored so that anyone with the link can download them.
  • E04User data sent where users don't expect it. What people type going to AI or analytics services your privacy policy doesn't mention.

02 · Break-ins

“Can someone see or change other people's stuff?”

  • E05Users seeing each other's data. The screen hides it, but your database or API (the behind-the-scenes connection your app fetches data through) hands it over if someone changes an ID in the link.
  • E06Admin pages anyone can open. Checks that only happen in the browser, so typing the right address is enough.
  • E07A login that lets people keep guessing. No limit on password attempts, no email verification, or a password reset that can be abused.
  • E08Links that act for your users. Missing protection against requests forged by other sites, and features that fetch any web address someone gives them.

03 · Money

“Can people get Pro for free, or run up my AI bill?”

  • E09Pro without paying. A Stripe webhook (the message Stripe sends your app when someone pays) that your app doesn't verify, or a “paid” setting the browser can change.
  • E10Prices your server doesn't check. Quantities, prices or totals that can be changed before checkout, like an order for −1 items.
  • E11Unlimited AI use. No rate limit (a cap on how often someone can use a feature) or daily quota, so one person or a bot can run up your AI bill.
  • E12A chatbot that can be talked into things. Prompt injection (tricking your AI into ignoring its instructions), and secrets written into prompts.
  • E13AI costs growing faster than revenue. No idea what each user costs you, chat history that grows forever, retry loops, an expensive model doing simple jobs.

04 · Speed

“It gets slow when more people use it.”

  • E14Fast for you, slow with real data. Missing database indexes (lookup shortcuts), pages that load every row, one database call per item on a list.
  • E15Slow on phones. Heavy code and images, and poor Core Web Vitals (Google's speed and stability scores).
  • E16Invisible to Google and ChatGPT. Main text that only appears after JavaScript runs, so some crawlers see an empty page.
  • E17Limits you didn't know you had. Free plans that pause your project, or login emails that hit a sending cap on launch day.

05 · Safety net

“I find out it's broken from customers.”

  • E18Backups you've never tested. No backups, or backups nobody has ever restored. Uploaded files are often not included.
  • E19AI tools with keys to your live data. A coding agent (Cursor, Claude Code, Replit) that can change your live database, with no separate test copy.
  • E20No alerts. You hear about broken sign-ups or failed payments from customers, not from your app.
  • E21Risky packages. Outdated, vulnerable or made-up libraries (ready-made code) that the AI added.
  • E22Code you're afraid to touch. The same logic copied in many places and no tests, so every fix breaks something else.
  • E23Missing browser protections. Security headers (settings that tell browsers what to block) that aren't set.
  • E24Privacy basics for users in Europe. A privacy policy, a list of services that receive user data, a way to delete an account. (Not legal advice.)

E00 · Anything specific to your app. Your own rules: who can invite whom, what a free trial allows, what happens when a payment fails. Run the same 24 checks yourself with our free checklist

What's in your audit report

  1. 1.

    A one-page summary. What to fix before your next user or payment, in order.

  2. 2.

    Every finding, explained. What's wrong, in plain English. What it means for you and your users. Its severity. How we confirmed it, on our own test account. A ready-to-paste fix prompt for your tool. How to check the fix worked. How long the fix should take.

  3. 3.

    What's fine. What we checked and found in good shape, so you know where not to worry.

  4. 4.

    A video walkthrough with subtitles, and a 30-minute call if you want one.

  5. 5.

    Signed. Every report is read and signed by Denys.

How we rank findings

These definitions are public because our half-refund rule depends on them.

LevelWhat it means for youWhen to fix
CriticalA stranger could reach your users' data or your money, take over accounts, or get your secret keys, right now and without special skills or access.Before your next user or payment.
HighA real way to lose data, money or access, but it needs some effort, a login, or a specific situation. It also covers a realistic path to a serious outage, data loss without a backup, or runaway costs.Within days, before you grow or launch.
MediumMakes your app weaker, slower or more expensive, but isn't an open door today.In the next few weeks.
LowGood practice that makes future problems less likely.When it's convenient.

Why every finding comes with a fix prompt

A vague request is how one AI fix breaks something else. “Make my app secure” gets a confident answer and a new bug. Our prompts name the exact problem, where it lives and what must not change, then tell you how to check the result. Fix it yourself, or have us do it.

E01CriticalKeys anyone can copy

Secret keys for OpenAI, Anthropic, Stripe or Supabase shipped inside your pages, where any visitor can take them and spend your money.

Fix prompt · Lovable with Supabase

My app calls OpenAI directly from the browser, so the OpenAI key is visible to visitors. Move this call into a Supabase Edge Function named generate-summary. Read the key from a Supabase secret called OPENAI_API_KEY. Only let logged-in users call the function. Change the page to call the function instead. Don't change anything else, and list every file you changed.

Check it worked

open your live site in Chrome, open developer tools (F12, or Cmd+Option+I on a Mac), press Ctrl+Shift+F (Cmd+Option+F on a Mac) and search for “sk-”. Nothing should come up. Then create a new OpenAI key and delete the old one, because the old one may already have been copied.

Scanner, audit or penetration test?

They do different jobs. Here's where an audit fits.

Automated scannerVibe Code AuditPenetration test
Who does itSoftwareA person who reads your code; Denys signs every reportA security tester
Finds known patterns, like exposed keys and missing headers✓✓✓
Checks your app's own rules: who can see what, who has paidLimited✓Usually
Looks at your AI bill, speed and backups—✓Usually not
Written for a non-technical founder, with a fix prompt per finding—✓Usually technical
Example price, as of September 2026CheckVibe: $0–$99/month$500 launch price, then $950Aikido: “typical pentest $4,000”
Best forA regular first passBefore you grow, take payments or answer a customer's security questionsCompliance and large customers

CheckVibe pricing ↗ (opens in a new tab) · Aikido pricing ↗ (opens in a new tab)

How the audit works, day by day

  1. 1

    Day 0 · Book.

    Pay by card, or ask for a company invoice. You get a setup email with the next steps.

  2. 2

    Day 0–1 · Share access.

    Read-only access to your code on GitHub, or a zip. An export of your database structure and access rules: we send you the exact queries to run. And a short written OK to test your app, naming which copy we may use. We test from our own test accounts, ideally on a copy with fake data.

  3. 3

    Days 1–3 · We review.

    The 3 business days start once we have access. We run the free scanners first, then check all five zones by hand.

  4. 4

    Day 3 · Your report.

    The report, a video walkthrough and a 30-minute call if you want one.

  5. 5

    After · You fix.

    Use the fix prompts yourself, or book a sprint. Your audit fee counts toward a Fix Sprint or Speed & AI-Cost Sprint booked within 30 days.

We never ask for database passwords, service_role keys (the master key to your Supabase database) or data exports. If you send us a secret by mistake, we'll tell you to replace it. How we handle your code, keys and data

What the audit costs

Vibe Code Audit

$500

launch price for the first 10 audits, then $950

Report in 3 business days

Your audit fee counts toward a Fix Sprint or Speed & AI-Cost Sprint booked within 30 days. If we find nothing Critical or High, you get half your fee back.

We take 3 new audits a week.

Unusually large app? We'll tell you after the free check and give you a fixed quote before you pay.

Included

  • all five zones and 24 common problems, plus your app's own rules
  • a plain-English report ranked by severity
  • a fix prompt, a way to check it, and a time estimate for every finding
  • a video walkthrough and an optional 30-minute call
  • read and signed by Denys

Not included

  • making the fixes (use the prompts, or book a Fix Sprint)
  • a penetration test or a certificate
  • legal advice on GDPR or other laws
  • tests that put heavy traffic on your live app

Who does the audit

Denys Kharkovskyy · Founder & lead engineer

Denys Kharkovskyy, founder and lead engineer of SELFOIA, reviews your app and code. Every report is read and signed by Denys.
  • 10+ years building software
  • 20+ AI-built apps reviewed
  • Worked on a real-time analytics platform used by 200+ companies
  • 5.0 on Upwork (opens in a new tab)
  • A team lead who reviews other engineers' code every day
More about Denys

Vibe code audit questions

My Lovable scan says I'm fine. Why pay for an audit?

Keep running it; we start there. A scanner looks for known patterns. As of September 2026, Lovable's own docs say its scans “cannot guarantee complete security” and “do not replace a thorough security review.” That review is what we do: a person checks how your app behaves with real test accounts, where users see each other's data, get Pro for free or run up your AI bill. Your fee goes on what the scanner misses.

Is this a penetration test?

No. A Vibe Code Audit is a hands-on review of your app and code, ranked by risk and written in plain English. A penetration test is a formal simulated attack, usually needed for compliance or large customers; Aikido, for example, lists a typical pentest at $4,000 (as of September 2026). If you need one later, fix what our audit finds first so the tester's time goes on the hard parts.

Will you see my customers' data?

No. We work from your code, your database structure and test accounts we create. We don't ask for database passwords or your customers' data. If a check shows real customer data, we stop at the first proof and copy nothing. We sign an NDA on request. How we work explains every step.

What access do you need?

Read-only access to your code on GitHub, or a zip. An export of your database structure, access rules, functions and storage settings; we send you the exact queries to run. And your written OK to test, from our own test accounts, ideally on a copy of your app with fake data. We never ask for database passwords or service_role keys.

What if you find nothing serious?

Then you get that in writing: what we checked, what's in good shape, and the Medium and Low items worth fixing as you grow. If we find nothing Critical or High, you get half your fee back. Our severity definitions are published on this page, so you can see exactly how we decided.

Which tools do you cover?

Lovable, Bolt, Cursor, Replit, v0, Base44 and Claude Code, and the stack they usually set up: Supabase or Firebase, Stripe, OpenAI or Anthropic, Vercel or Netlify. Built with something else? The same problems show up whichever tool wrote the code. We earn no platform commission. Stay, harden or leave: we'll tell you what's best.

How much does a security review of a small app cost?

Ours is a fixed $500 at launch (the first 10 audits), then $950, for all five zones and a report in 3 business days. For comparison, as of September 2026, automated scanners such as CheckVibe cost $0–$99 a month, and Aikido lists a typical penetration test at $4,000. Unusually large apps get a fixed quote after the free check.

How long does it take?

3 business days from the moment we have access to your code and your database export. Allow a day to share access; we send step-by-step instructions. If you book a Fix Sprint afterwards, it takes 1–2 weeks. We take 3 new audits a week.

Can I fix the problems myself?

Yes. Every finding comes with a ready-to-paste prompt for your tool that names the exact problem and what must not change, plus a simple way to check the fix worked. If you'd rather not do it yourself, book a Fix Sprint: your audit fee counts toward it if you book within 30 days.

What happens after the audit?

You choose. Fix things yourself with the prompts, book a Fix Sprint or Speed & AI-Cost Sprint, or keep an engineer close with On-call CTO. If you want someone to keep watching after the fixes, Guard is $390 a month, month to month, and only available after an audit: a monthly outside re-check, alerts for AI-bill spikes and errors, and a quarterly review of new changes.

Know what to fix first, in 3 business days.

Book the audit now, or start with a free check if you're not sure yet.