Back
Christof Jori

8 min read · 16 Jun 2026
Last reviewed

Next
Made on your device, with no Instagram connection. We copy the post link for Instagram’s Link sticker.

What Does It Cost to Make a Vibe-Coded App Production-Ready?

If an AI-assisted prototype is moving toward real users, the next question is what evidence and engineering it needs for the intended exposure. This post is about planning money and time, not declaring vibe-coding good or bad. AI-assisted code may be sound or unsafe, just like human-written code; the architecture and verification decide.

The numbers here are Wavect planning ranges from prior AI-generated-code engagements, reviewed on 2 September 2026. They are neither market benchmarks nor quotes. Scope depends on repository access, architecture, data, users, integrations, deployment, threat model, regulation, evidence quality, and the target service level.

Shipped without reading the code?

 Book a Free Consultation

What are you actually paying for?

You are paying to establish evidence and treat the gaps found: authorization, isolation, credentials, validation, failure behavior, performance, recovery, components, tests, deployment, monitoring, and operational ownership. Do not assume the model omitted each control or that a demo cannot exercise it. Inspect the actual system against a defined production target.

The work splits into two phases, and they price differently. The first is the audit: a structured read to find what is hiding. The second is the hardening: fixing what the read turned up. Most of the time and money is in the second, but the first is what tells you how big the second is.

What does the audit itself cost?

For Wavect, an initial audit often means a few focused days to roughly a week, but that range assumes accessible source, a bounded architecture, and timely stakeholder answers. It does not buy certainty or prove the absence of defects. A useful deliverable records scope and limitations, evidence, reproducible findings, severity rationale, remediation options, and an updated estimate. Products handling payments, sensitive data, privileged actions, complex tenants, hardware, or regulated outcomes may require specialist testing beyond that range. You can read the structure in our vibe-coded software audit writeup.

What does the hardening cost?

This is where the real spend lands, and it scales with what the audit found. The honest way to talk about it is in bands, because two products with the same feature list can need very different work depending on what the model left behind.

Product typeTypical effortWhat drives it
Bounded low-impact internal toolWavect planning range: a few daysSmall surface, limited integrations, tested access, low recovery burden
Single-tenant app with moderate exposureWavect planning range: about one to two weeksAuthorization, validation, error handling, credentials, deployment, tests
Multi-tenant SaaS with paymentsWavect planning range: two to four weeks or moreEffective isolation, payment replay, reconciliation, load, observability, recovery
Core rebuild neededRe-scoped as a buildBroken data model or one bad pattern copied everywhere

Treat these as directional Wavect assumptions. Variance also comes from code and test quality, architecture, dependencies, deployment, integrations, data migration, compliance, documentation, reviewer access, and the agreed target. Obtain a scoped quote after evidence collection.

Where does the time actually go?

There is no stable cross-project percentage split. Track effort by workstream after the audit instead of treating the following areas as a universal budget formula.

  • Understanding and reproduction. Map architecture, data flows, deployment, trust boundaries, and expected behavior, then reproduce material findings before changing code.
  • Authorization and data access. Enforce object, function, property, and tenant rules at trusted boundaries and test direct, inherited, public-link, administrative, and revocation paths.
  • Failure paths, validation, and credentials. Cover external failures, resource limits, untrusted input and output, privileged secrets, rotation, and recovery.
  • Verification and operations. Add proportionate tests, observability, deployment controls, backups, restore exercises, runbooks, and ownership.

New feature work may be small or dominant. Keep it separate from remediation so buyers can see which spend is required for the target risk level and which changes product scope.

Christof Jori

"The cost of making vibe-coded software safe is not the cost of rewriting it. It is the cost of the work the prompt never asked for, and that work did not disappear because a model wrote the first draft."

What does the audit typically find?

Wavect engagements have found recurring issues in authorization, tenant isolation, credential handling, failure paths, performance, recovery, and regression evidence, but that is practitioner experience rather than a representative study of all vibe-coded apps. The full review areas are in our QA for AI-generated code post, and the migration work is in from Lovable and Cursor prototype to production.

What is the cost of not doing it?

Compare remediation cost with the expected likelihood and impact of failure, plus contractual, regulatory, operational, and opportunity costs. An exposed credential or authorization flaw creates risk, but whether an incident or personal-data breach occurred depends on facts. An audit reduces uncertainty within its scope; it is not insurance and cannot guarantee that every defect will be found.

When is a rebuild cheaper than hardening?

Compare remediation and replacement when defects are systemic, the architecture cannot meet requirements, dependencies are unsupported, or migration risk dominates. A rebuild is not automatically cheaper: it adds feature-parity, migration, cutover, retraining, and new-defect risk. Use written options with assumptions, cost ranges, rollback, and acceptance criteria.

How does Wavect price this work?

We use agile fixed price once the audit has removed the biggest unknowns. The audit is scoped tight and small. The hardening is scoped from what the audit found, with blockers, highs, and cleanup separated so you decide what to fund and when. You are never asked to sign a fixed figure for work nobody has looked at yet. This is the front end of our software quality assurance service.

Final thoughts

Production-readiness cost follows the target architecture, exposure, data, integrations, regulation, service level, and evidence gap, not whether a human or model wrote the first draft. Wavect's time bands are planning history, not market benchmarks or quotes.

Begin with a bounded audit that states scope and limitations, reproduces material findings, prioritizes by credible risk, and separates remediation from new features. Then compare hardening with replacement using explicit assumptions, migration risk, acceptance criteria, and a scoped quote. The audit reduces uncertainty; it does not provide certainty or insure against every incident.

Primary sources used in this audit guide

The effort bands are Wavect planning ranges reviewed on 2 September 2026. These standards provide broader security and software-supply-chain requirements from which a risk-based audit can select controls.

From prototype to production

Got a vibe-coded or AI-generated product that needs to survive real users, due diligence, or investor scrutiny? Wavect audits, hardens, and rebuilds the parts that matter.

Best next step:

Inbox, without the noise

Follow the work that matters to you

Get a short email when we publish something new. Follow the whole blog or only the problems you care about.

What would you like to receive?
Choose your topics

Free, double opt-in, no tracking pixels.

Back
Christof Jori

8 min read · 16 Jun 2026
Last reviewed

Next

Get the next Delivery and QA field note

One concise email when we publish. No tracking pixels, and no inbox filler.

Free, double opt-in, no tracking pixels.