12 min read
What actually breaks in a vibe-coded app: the audit we run before we quote
The six-gate audit we run on vibe-coded apps before quoting a rescue: auth, data, security, backups, observability, tests. Run the checks yourself first.
ReadWe build custom web applications, AI automation and internal systems for growing companies. While your market still runs on spreadsheets, your processes run in a system of your own.
12+ projects delivered
every one on deadline, in production
Fixed price and deadline
in writing, and if we slip, the next payment waits
Reply within 24 hours
on working days, to every enquiry
You are building something new, rescuing something that already exists, or replacing manual work.
Your routine work runs as software: documents, email, translation, quotes.
Price
After the assessment
Inbound document processing, correspondence drafting, multilingual communication, quote assembly and marketing copy with human approval. We start with one chosen process: live typically 2-4 weeks after the assessment, with a monthly written before-and-after measurement of the hours it takes. EU AI Act labelling and logging are built in.
More on: AI automationYour half-finished app, turned into something that holds under its first real load.
Price
Quoted after the code audit
Got a vibe-coded MVP, a prototype or a system patched over the years? Technical debt now eats 40-50% of the IT budget at many companies. We audit it, close the security holes, fix the architecture and bring it up to production quality. Then we keep it maintained.
The percentages come from industry research.
More on: Software rescue and modernisationA client portal, a SaaS or a marketplace, built on your own process.
Price
Quoted after scoping
SaaS platforms, client portals, marketplaces, subscription products and custom workflows. Off-the-shelf tools go unused on 85-90% of their features, yet you keep paying for all of them. Yours is built around your process, and the full source code transfers to you on the final invoice.
The percentages come from industry research.
More on: Web application developmentOne codebase, two platforms, one team maintaining both.
Price
Quoted after scoping
iOS and Android apps from a single codebase, on React Native and Expo. One codebase costs up to 30-50% less than building native twice.
The percentages come from industry research.
More on: Mobile app developmentStock, CRM and approvals in one system, instead of the shared spreadsheet.
Price
Quoted after scoping
Inventory management, CRM, approval workflows and bespoke internal tools. 88% of spreadsheets contain errors, and most stay hidden until they cause damage. We turn the work your team pushes through email and Excel into software, fitted to your roles and existing tools.
The percentages come from industry research.
More on: Internal systems and ERPA custom Shopify theme, with its load time measured.
Price
Starting price, on request
Shopify stores with a custom theme and clean code. A one-second delay in load time cuts conversion by roughly 7%. We build the buying journey around your brand, and we measure the store’s load time before launch and after it.
The percentages come from industry research.
More on: Shopify developmentA website you edit yourself afterwards, with no developer in the loop.
Price
Starting price, on request
Company and marketing sites on Next.js with a built-in CMS. In Google’s own study, a 0.1-second speed gain lifted conversion by 8.4%, yet only 53% of mobile sites pass Core Web Vitals. You update the content yourself, without a separate development round for every change.
The percentages come from industry research.
More on: Website developmentOne offer, one CTA, measurable leads.
Price
Starting price, on request
Campaign landing pages with conversion-first structure. One offer, one audience, one CTA: no menu pulling visitors away. Forms stay short because 81% of started forms are abandoned. Live in days, ready for A/B testing.
The percentages come from industry research.
More on: Landing pagesThe assessment shows where it pays off for you, and we hand it over running in production. For Hungarian companies of 5-50 people with no IT team: the first process is typically live 2-4 weeks after the assessment.
Vibe-coded MVPs and quickly assembled prototypes reach a working demo. Then real load arrives: data leaks, the server falls over, and the login only looks like it protects anything. We audit the code, fix it, and bring it up to production quality.
Industry research puts AI tools at 70-80% of the way. The rest is what survives a traffic spike without dropping logins or double-charging cards.
Code audit in a few days, then production-ready usually in 3-6 weeks.
The six checks, at audit and at handover
audit → handover
Login works; the server never checks who is allowed to see what.
Test and production data run on separate database instances.
Secrets committed to the repository, and incoming data is never validated.
Nightly backups run; nobody has ever tried a restore.
Structured logging and failure alerts are live.
No automated tests, and releases go out to production by hand.
Sample data. Yours reads your own codebase, against these same six checks.
By the end of the scoping you know the price and the deadline. Everything after that is a schedule.
Thirty minutes on what the software has to solve: business goal, processes, deadlines. We close by telling you what we recommend, including when less will do.
A written summary with a precise scope, a fixed price and a schedule. That is the proposal, and the price holds to the end of the project.
At every stage of the schedule you get a clickable preview link, not a status report. Design, data model and code evolve as one system, with tests and code review.
Production deployment, then a clean handover: source code, credentials, documentation. We watch the first week with you, measurements included.
Monthly maintenance with a set response time: updates, fixes, extensions, and the measurements watched as your product grows.
Step 1
Step 2
Step 3
Step 4
Step 5
In the contract, itemised
When it takes effect
Call
Scoping
Build
Live
Operations
The figure in the proposal holds to the end of the project. A new requirement gets priced before it is built.
Fixed in the proposal
Fixed in the proposal
The timeline is part of the proposal. We work in sprints, and if we ever slip, the next payment waits until we deliver.
Fixed in the proposal
Fixed in the proposal
AI is a tool here: research, prototyping, test generation. Architecture and every production decision sit with an experienced engineer who answers for them.
Throughout the build
Throughout the build
Full source code and IP transfer to you on the final payment, with every credential.
Takes effect at handover
Takes effect at handover
Monthly maintenance with a set response time. Its price is in the first proposal.
Monthly, ongoing
Monthly, ongoing
Companies we've built for
Scope decides it: how many processes go in, how many roles work inside it, and how many existing systems we have to touch. On anything larger the scoping stage produces the number.
It depends on the project. The clock starts once every piece of material is in: from there a landing page takes 5 to 7 days and a website 1 to 3 weeks. Webshops, web applications and anything larger get their deadline from the proposal's schedule, in writing.
Four situations, and we say so before you pay for anything: an urgent date ahead of real traffic, the cheapest quote winning, an hourly rate against an open scope, and an off-the-shelf product that already covers it.
Most of the time, yes. On the call you know your process and we know the AI, and that is enough to start. We hand it over built: your team learns to use it, and the technical operation is part of monthly maintenance. You do not need to hire an AI specialist.
The rule we build to is the EU AI Act’s transparency requirement, in force since 2 August 2026: where AI answers, it says so, and AI-written content is labelled. We build that into every system wherever it runs, because it is the strictest regime we work under. If you sell into the EU, it is the rule you need. If you do not, you still get the labelling and a full audit trail.
That is the most common condition we hear, and it holds. The proposal states which provider's model sees what, configured so it does not train on your data. Sensitive steps run tied to human approval, and every AI operation is logged. We align the data-protection side with your existing GDPR processes.
The people who built it are the people who run it.
The first year after launch, month by month.
First month
A clean handover, a watched launch Source code, credentials and documentation in your hands. We watch the first week with you, measurements included.
Every month
Maintenance that keeps it moving Updates, fixes, extensions, and the measurements watched as your product grows.
If something breaks
You write, we answer A first reply within 24 hours on working days, to every enquiry.
Write a few sentences about the goal. Within 24 hours on a working day we write back with what we would build first and what we would leave for later.