Production recovery

Stuck with AI another vendor could not ship?

About a third of our AI engagements start exactly there.

Recover the build →
Case studies Book a 30-minute discovery call

Vibe coding to production: how to harden an AI-built app

Going from vibe coding to production means closing eight gaps the prototype never had to face, starting with database access rules and secret keys. Veracode's 2026 GenAI Code Security Report found AI models wrote secure code in only 56% of test tasks, so treat generated code as a first draft: run the hardening checklist below, then decide whether to harden in place, refactor or rebuild.

Kanika Mathur
By Kanika Mathur, Head of Service Delivery
Reviewed by Resourcifi engineeringPublished Sep 23, 2026Updated Sep 23, 202611 min read
Engineering
A desk by a window with a laptop showing a blurred mobile app prototype of coloured blocks, a second screen with a dark terminal, a printed checklist with empty tick boxes, blank sticky notes on the wall, a small plant and a desk lamp, no people
Key takeaways

The short version

  • Keep the prototype, not its defaults. The screens, the rough data model and the user evidence carry forward. The access rules, key handling and release habits usually do not.
  • Data access is the first gap. Supabase says a table in an exposed schema without row-level security is readable and writable, and one scan by researchers at Replit of Lovable's Launched showcase found 170 of 1,645 projects (about 10.3%) with inadequate RLS (CVE-2025-48757).
  • AI code needs a security pass. Veracode's July 2026 GenAI Code Security Report found secure code in only 56% of tasks, with cross-site scripting at 15% and log injection at 12%.
  • Work a 16-line checklist in order. Data rules, secrets, code patterns, dependencies, tests, release path, backups and launch operations, each with a test that proves it is done.
  • Hardening is weeks, a rebuild is an MVP. On illustrative hours and Clutch's September 2026 bands of $25 to $49 and $50 to $99 an hour, hardening runs about $2,000 to $16,000 and a rebuild about $15,000 to $120,000.

Vibe coding gets you to a clickable product fast. Lovable, Bolt.new, v0 and Cursor turn a written brief into real code, a working interface and a connected database, which is what you need to test demand. What they do not do by default is decide who may read which row, where the keys live, or how you roll back a bad release. That work is the real move from vibe coding to production.

Stack Overflow's 2025 survey defines vibe coding as generating software from LLM prompts, and 84% of respondents in 2025 used or planned to use AI tools in their work1.

Keep what the prototype has already earned you:

  • A settled interface. Screens users have clicked through are a better spec than any document.
  • A rough data model. The generated tables show which entities the product needs, even if the access rules are wrong.
  • Code you own. Lovable's docs say what you create is yours and can be exported or synced to your own Git repository8. Bolt and v0 also connect to GitHub910.
  • Evidence. Sign-ups, feedback and the features nobody touched decide what is worth hardening.

The catch sits in the survey's own frustrations list. The top complaint, from 66% of developers, is AI output that is "almost right, but not quite", and 45% say debugging AI-generated code takes longer1. A prototype hides the gap because you only walk the happy path.

The 8 production gaps in a vibe-coded app

A vibe-coded app is usually not production ready as generated. The eight gaps that matter are access control, secrets, insecure code patterns, dependencies, tests and review, the release process, data safety and launch operations. The first two are the dangerous ones, because a public app that talks straight to its database is only as safe as its row-level security policies.

0
Approximate share of AI coding tasks that introduced a known security vulnerability in Veracode's tests.
Veracode GenAI Code Security Report, July 2026
10.3%
Projects on Lovable's Launched showcase (170 of 1,645) with inadequate row-level security, found by checking homepages only.
Researchers at Replit, CVE-2025-48757, 2025
0
Developers who have hit AI output that is almost right, but not quite, the most cited AI frustration.
Stack Overflow Developer Survey, 2025
  1. Access control. Lovable and Bolt can both run on Supabase. In the apps scanned in 2025, Lovable's generated front ends called the database directly from the browser with a public key, relying on row-level security (RLS) to protect it4. Supabase's docs are blunt: a table in an exposed schema without RLS is readable and writable by any role with a grant on it, and adding policies does not remove those grants5.
  2. Secrets and keys. Supabase's API keys docs say the publishable key (the legacy anon key) is meant to be public, because it only reaches what RLS allows. The secret key (the legacy service_role key) bypasses RLS and must stay on the server5. Check that no prompt put it, or a payment or AI provider key, into front-end code.
  3. Insecure code patterns. Veracode's July 2026 report, covering more than 100 models, found syntax correct nearly 100% of the time but secure code in only 56% of tasks. In the latest round, large models averaged 53% and medium and small ones 51%2. The chart below shows where the failures cluster.
  4. Dependencies. Generated projects pull in npm packages you did not choose. Lovable's own Quick scan includes a dependency audit for known vulnerabilities7.
  5. Tests and review. If the prototype has no automated tests, nothing catches regressions. Cursor's checkpoints let you restore files after a bad agent turn, but they are stored locally and are not a test suite11.
  6. Release process. v0 lets you deploy to production immediately or open a pull request for review10. The first option is the prototype habit. Production needs a staging environment, pull requests and a rollback you have rehearsed.
  7. Data safety. Supabase recommends point-in-time recovery for databases expected to pass 4 GB, and may pause Free Plan projects with low activity in a 7-day period6.
  8. Launch operations. With a custom SMTP provider, Supabase's default auth email rate limit is 30 new users per hour, which it says a major public announcement will likely exceed6. Add error monitoring, uptime alerts and multi-factor authentication on every admin account before launch day.

The public record for gap 1 is CVE-2025-48757: NIST's database describes an insufficient RLS policy in Lovable through 15 April 2025 that let unauthenticated attackers read or write arbitrary tables of generated sites, scored 9.3 (critical) by MITRE and disputed by Lovable, which says each customer is responsible for their own app's data3. The Replit researchers behind it scanned 1,645 projects listed on Lovable's Launched showcase and found 303 exposed endpoints across 170 of them, from homepages alone, exposing names, phone numbers, API keys and payment details4.

AI models handle SQL injection well and cross-site scripting badly
Share of Veracode test tasks that produced secure code, by vulnerability type. Higher is better; the dashed line is the 56% average across all tasks.
Security pass rate of AI-generated code by vulnerability type Veracode July 2026 pass rates by weakness, with the 56 percent overall average. 0%25%50%75%100% All tasks 56% 87%83%15%12% Insecurecryptography SQLinjection Cross-sitescripting Loginjection
Data behind this chart
Vulnerability typeSecure code
Insecure cryptographic algorithms87%
SQL injection83%
Cross-site scripting15%
Log injection12%
Average across all tasks and models tested56%
Source: Veracode, 2026 GenAI Code Security Report (July 2026), with per-weakness rates from Veracode's report summary and The Next Web's coverage.

For a vibe-coded web app, check cross-site scripting and log injection first.

Lovable, Bolt.new, v0 and Cursor: tool-by-tool

The four tools leave you in different places. Lovable and Bolt.new generate a full app with a hosted backend, so your first job is database rules. v0 generates code that deploys to Vercel with one click, so your first job is the release path. Cursor edits a codebase you already own, so the gaps are review and tests.

What each tool gives you and where to start hardening
ToolWhat it buildsBackendBuilt-in safety netFirst hardening step
LovableFull web app; new apps on TanStack Start, older ones React + ViteBuilt-in Cloud backend on Supabase's foundation, or your own SupabaseQuick scan on every publish; Deep scanAudit RLS and grants on every table, then Git sync to your repo
Bolt.newFull-stack JavaScript app; Expo for mobileNode.js only; Bolt Cloud database or SupabaseVersion history and GitHubMove secrets server-side; review database rules
v0Full-stack apps and components, deployed on VercelConnects to a backend you choosePull request option before deployTurn off direct-to-production; add staging and review
CursorEdits your existing codebase through an agentWhatever your stack already isLocal checkpoints that restore filesAdd tests and require review on agent diffs

Sources for the table: Lovable's ownership and security docs78 and its Supabase integration docs, Bolt's supported technologies page9, Vercel's v0 docs10 and Cursor's agent overview11. Lovable apps created from 13 May 2026 run server code on TanStack Start while older ones build to static files, so check which you have before planning a migration. Bolt supports only JavaScript back ends.

If you built with Lovable and want to know how to make it production ready, the vendor's own answer is a good start. Its docs say the scans "do not replace a thorough security review" and recommend a professional review for apps handling sensitive data7. Run the Quick scan, fix what it flags, then work the checklist below: a scan checks settings, not whether a policy matches your business rules.

The hardening checklist

Work the checklist in order: lock down data first, then secrets, then code, then the release path and operations. Each line has a test you can run, so "done" means verified rather than believed.

Hardening checklist, in priority order
#AreaCheckDone when
1DataRLS enabled on every table in an exposed schemaSecurity Advisor is clean and a signed-out request returns nothing private
2DataDefault anon and authenticated grants revoked where not neededA table protected only by policies no longer accepts anonymous inserts
3DataNo access rule that lets everyone through, such as USING (true) on sensitive tablesPolicy tests pass for owner, other user and signed-out cases
4SecretsSupabase secret key (legacy service_role) and provider keys only on the serverA search of the built front-end bundle finds no secret keys
5SecretsEvery key that was ever in client code rotatedOld keys return errors
6CodeOutput encoding on user content; no raw HTML renderingAn XSS payload in every text field renders as text
7CodeLogs strip newlines and never record tokens or personal dataA log review shows no secrets or forged lines
8CodeServer-side validation and rate limits on auth and write endpointsScripted abuse is rejected
9DependenciesKnown-vulnerable npm packages upgraded, lockfile committedThe audit shows no high or critical findings
10TestsAutomated tests on sign-up, login, payment and core writesThey run on every pull request and block the merge on failure
11ReleaseCode in your own repository with pull requests and reviewNo change reaches production without a reviewed PR
12ReleaseSeparate staging and production projects and keysStaging can be wiped without touching real data
13Data safetyBackups on, point-in-time recovery if the database will pass 4 GB, paid plan so the project cannot pauseA restore to a test project has been done once
14PlatformSSL enforcement, network restrictions, MFA on every admin accountAll three show enabled in the dashboard
15OperationsCustom SMTP and an auth email rate limit sized for launchA load test of sign-ups at launch volume succeeds
16OperationsError monitoring, uptime alerts and a named on-call ownerA test error pages the owner

Lines 1, 2, 13 and 14 follow Supabase's RLS guide and production checklist56, and line 3 mirrors Lovable's Quick scan check for access rules that let everyone through7. Lines 6 and 7 target the two weaknesses Veracode found models fail most often2. For a mobile front end the same list applies, plus store and device issues covered in our mobile app security guide. If the app calls a language model, add prompt injection and output handling from our notes on securing AI features.

Line 10 is the one founders skip, and it makes the rest stick: tests stop an AI agent from quietly undoing line 1 next month. If nobody on the team writes tests, bring in a QA engineer for the critical flows before launch.

Refactor or rebuild?

Harden in place when the data model fits the product and the problems are settings, keys and missing tests. Refactor the core when the interface is right but business logic lives in the browser or the schema needs reshaping. Rebuild when the stack cannot do what the product needs, or when nobody can explain how the code works. In every case, keep the prototype as the spec.

Decision matrix: harden, refactor or rebuild
SignalHarden in placeRefactor the coreRebuild
Data modelFits the productNeeds new tables or relationshipsWrong at the root
Business logicAlready server-side or trivialIn the browser, needs moving to the serverScattered and contradictory
StackSuits the roadmapSuits it with changesBlocks a must-have, such as a Python service on Bolt
Code understandingA developer can explain itParts are opaqueNobody can explain it
Data at stakeLow sensitivityPersonal dataPayments, health or regulated data with no audit trail

A rebuild is not starting over: the screens, flows and user evidence carry forward. And do not let sunk cost decide. Stack Overflow's survey found 46% of developers distrust the accuracy of AI tools and only 3% highly trust the output1, so a second opinion from someone who did not prompt the code is worth having before you commit. Our guide to choosing a development partner lists what to ask.

Check portability early. Lovable says you can export code and data and self-host8, but its Supabase integration docs note there is no one-click migration between its built-in backend and a separate Supabase project. Decide where the data will live before you refactor anything that touches it.

What it costs to take vibe coding to production, and how long

Hardening a small vibe-coded app in place is a job of weeks, not months, and a rebuild on the prototype's spec is closer to a new MVP. Using illustrative hours and Clutch's September 2026 rate bands, hardening runs about $2,000 to $16,000, refactoring about $6,000 to $48,000, and a rebuild about $15,000 to $120,000. The hours are our assumptions for a small web app, not a benchmark; your audit sets the real number.

Illustrative cost and timeline by path (hours are our assumptions; rates from Clutch, September 2026)
PathHoursTeam and weeksAt $25 to $49 an hourAt $50 to $99 an hour
Harden in place80 to 1601 engineer, 2 to 4$2,000 to $7,840$4,000 to $15,840
Refactor the core240 to 4802 engineers, 3 to 6$6,000 to $23,520$12,000 to $47,520
Rebuild on the prototype's spec600 to 1,2002 engineers, 7.5 to 15$15,000 to $58,800$30,000 to $118,800

The rate columns are Clutch's bands for software development firms: $25 to $49 an hour in India and $50 to $99 in the United States12. Weeks assume 40 hours per engineer per week. Add hosting, a paid database plan and any security review on top.

For context, our guide to how long an MVP usually takes notes that many MVPs ship in about 8 to 12 weeks, and our median time to production is 90 days. The rebuild row overlaps that range, which is the point: a rebuild on a validated prototype takes about as long as a fresh MVP, with far less guesswork about what to build.

  • What pushes cost up: payments, regulated data, a backend migration and a mobile app.
  • What keeps it down: a data model that fits, code in your own repository and a short launch feature list.
  • Order of work: run the audit, fix lines 1 to 5 of the checklist immediately, then decide the path. Exposure first, architecture second.

If you want a team to run the audit and take the app the rest of the way, our MVP development team starts from what you have built rather than from a blank page.

Frequently asked

Vibe coding to production questions

Is a vibe-coded app production ready?
Usually not as generated. The interface and data model can be sound, but the defaults that matter in production are often missing: row-level security on every table, secret keys kept on the server, tests on sign-up and payment, a staging environment, backups and monitoring. Treat the prototype as a validated spec and a first draft of the code. Run a hardening checklist and fix data access and keys before you invite real users.
What are the security risks of AI-generated code?
The main risks are missing access control, exposed secrets, injection flaws and vulnerable dependencies. Veracode's July 2026 GenAI Code Security Report found secure code in only 56% of tasks, with cross-site scripting passing just 15% of the time and log injection 12%. Syntax was correct nearly 100% of the time, so the code looks fine and runs, which is why the flaws survive into production.
I built my app with Lovable, how do I make it production ready?
Start with the database. Run Lovable's Quick scan, then check that row-level security is on for every table, that no policy lets everyone through, and that the secret key (the legacy service_role key) never reaches the browser. Sync the code to your own Git repository, add tests on the core flows, set up staging, turn on backups and move to a paid database plan. Lovable itself recommends a professional review for apps handling sensitive data.
Should I refactor or rebuild my vibe-coded MVP?
Harden in place if the data model fits and the problems are settings, keys and missing tests. Refactor if the interface is right but business logic sits in the browser or the schema needs reshaping. Rebuild if the stack blocks a must-have feature or nobody can explain how the code works. Either way, keep the prototype's screens and user evidence as the spec, so a rebuild is not starting over.
How long does it take to harden an AI-built MVP?
For a small web app, hardening in place takes one engineer roughly two to four weeks, based on illustrative hours of 80 to 160 that are an assumption, not a benchmark. On the same illustrative assumptions, refactoring the core takes about three to six weeks with two engineers, and a rebuild on the prototype's spec about 7.5 to 15 weeks. Our guide to how long an MVP usually takes notes many MVPs ship in 8 to 12 weeks, which the rebuild range overlaps.
Is it safe that my Supabase key is visible in the browser?
Supabase's API keys docs say the publishable key (the legacy anon key) is designed to be public, because it can only reach what row-level security allows. That makes RLS the whole defence, so every table in an exposed schema needs it switched on with policies that match your rules, and unneeded default grants revoked. The secret key (the legacy service_role key) is different: it bypasses row-level security and must stay on the server. If it was ever in client code, rotate it.
Do Lovable's built-in security scans make my app secure?
No, and Lovable says so. Its docs describe the Quick scan, which runs every time you publish and checks database access rules, npm dependencies and exposed MCP servers, plus a deeper scan. The same docs state that these tools do not replace a thorough security review and that you are responsible for your app's security. A scan checks settings; it cannot tell whether a policy matches your business rules.
Kanika Mathur

Kanika Mathur

Head of Service Delivery, Resourcifi

Kanika Mathur is Head of Service Delivery at Resourcifi. She leads the engineering pods that scope, build and run client software, from mobile apps to AI systems, and she reviews the process and figures in our engineering guides for accuracy.

Resourcifi on LinkedIn →

Sources

  1. Stack Overflow, 2025 Developer Survey: AI (84% use or plan to use AI tools; vibe coding definition; 66% encountered AI output almost right but not quite, the most cited frustration (select all that apply); 45% debugging AI code takes longer; 46% distrust, 3% highly trust).
  2. Veracode, 2026 GenAI Code Security Report: 100+ Models Tested (primary: 56% average security pass rate across more than 100 models tested over four years; 80 tasks. Corroborated by Veracode's report blog of 28 July 2026 (https://www.veracode.com/blog/2026-genai-code-security-report-ai-risk/: roughly 44% of tasks with a known vulnerability, syntax nearly 100%, SQL injection 83%, cryptography 87%, XSS 15%, log injection 12%, large models 53% vs 51% medium and small) and The Next Web (https://thenextweb.com/news/veracode-2026-genai-code-security-56-percent-pass-rate)).
  3. US National Institute of Standards and Technology, National Vulnerability Database, CVE-2025-48757 Detail (insufficient RLS policy in Lovable through 2025-04-15; unauthenticated read or write of arbitrary tables; disputed by the supplier; CVSS 3.1 score 9.3 critical from MITRE).
  4. Matt Palmer, Replit Developer Relations, Statement on CVE-2025-48757 (303 endpoints across 170 of 1,645 projects listed on Lovable Launched (about 10.3%) with inadequate RLS, from homepages only; names, phone numbers, API keys, payment details exposed; author works at Replit. Corroborated by Semafor, 29 May 2025).
  5. Supabase, Row Level Security (tables without RLS readable and writable; enable RLS on every exposed table; policies do not remove grants; revoke default grants; service_role (legacy name of the secret key) bypasses RLS and stays server-side).
  6. Supabase, Production Checklist (Security Advisor; RLS on all tables; SSL enforcement; network restrictions; MFA; PITR above 4 GB; custom SMTP; 30 new users per hour auth email limit; Free Plan pause after a low-activity 7-day period).
  7. Lovable, Security overview (Quick scan on every publish covering database rules, npm dependency audit and MCP server check; Deep scan; scans do not replace a thorough security review; user responsibility; professional review for sensitive data).
  8. Lovable, Deployment, hosting, and ownership options (never locked in; export code and data; you own what you create; Git sync; new apps from May 13, 2026 on TanStack Start, older on React + Vite; backend and connectors are separate services).
  9. Bolt, Supported technologies (Node.js-only backends; any JavaScript front end; Bolt Cloud database or Supabase; Expo for mobile; version history and GitHub).
  10. Vercel, What is v0? (v0 creates real code and full-stack apps; deploy to production immediately or open a pull request for review; connect to backend; one-click deploy on Vercel).
  11. Cursor, Agent overview (agent built from instructions, tools and model; checkpoints before significant changes, stored locally, restoring reverts files only).
  12. Clutch, Software Development Company Pricing Guide 2026 (hourly bands for software development firms: $50 to $99 in the United States, $25 to $49 in India (updated September 2026)).
Keep reading
Related guides worth your time
Backend Frameworks Comparison Web & software Backend Frameworks Comparison A 2026 comparison of backend frameworks across Node, Django, Spring, Laravel, Go and more, by performance, ecosystem and... Read guide → Django vs Flask: choosing a Python web framework Web & software Django vs Flask: choosing a Python web framework Django vs Flask: compare the two leading Python web frameworks on structure, scale, ORM, and learning curve. Expert guida... Read guide → Healthcare technology trends Web & software Healthcare technology trends The healthcare technology trends that matter: AI in clinical workflows, FHIR interoperability, telehealth, wearables and... Read guide → Laravel Core Concepts Web & software Laravel Core Concepts What is Laravel? A PHP web framework with routing, Eloquent ORM, Blade, and queues built in. The core concepts explained... Read guide → Magento to Shopify migration checklist: data, redirects and SEO, step by step Web & software Magento to Shopify migration checklist: data, redirects and SEO, step by step A step-by-step Magento to Shopify migration checklist covering data, URLs and redirects, SEO, apps, checkout, testing and... Read guide → Next.js vs React Web & software Next.js vs React Next.js is a framework built on React, not a replacement. Compare server rendering, routing, and when to use each for you... Read guide → 25 mobile app ideas worth building, with costs and revenue models Mobile & apps 25 mobile app ideas worth building, with costs and revenue models 25 mobile app ideas across AI, health, fintech and commerce, with the core features, a sourced build cost range and the m... Read guide → AI in UX Design: How AI Is Changing User Experience Product & UX AI in UX Design: How AI Is Changing User Experience How AI is changing UX design: personalization, predictive flows, generative UI, and faster research, with concrete app ex... Read guide → App development tools Mobile & apps App development tools The app development tools you actually need, by category: IDEs, frameworks, backend and BaaS, testing, CI/CD, and design... Read guide →
MVP development

Turn the idea into a working MVP.