Authentication nobody can explain. It works in the happy path; no human can say what happens in the unhappy ones. The most common critical finding in AI-built apps.
AI-built apps, engineered
You vibe coded it. It works. Now make it survive success.
An AI generated your app in an afternoon, and that is genuinely new. What it did not generate is security you can prove, a data model that scales, or code anyone can explain when it breaks at 2am, because no prompt does. A working demo and a business you can trust are different things. We are the engineering team that closes that gap: we take vibe-coded apps to production, software you own outright, one build instead of a bill that climbs every time it breaks.
A working demo is not a business
The tool did everything. That is the problem.
Millions of people can now generate an app from a sentence. Almost none of them can engineer one. If that is you, you are not behind, you are exactly where this wave leaves everyone: with a product that works and a foundation nobody actually built.
Lovable, Bolt, v0, Replit and coding agents turn a prompt into a running app in days. That part is real, and it is why you now have users to worry about. But an AI optimises for exactly one thing: making the screen do what you asked. Not security. Not a data model that survives scale. Not code a human can explain when it fails.
A no-code platform stops you at a capability ceiling: the tool cannot do the next thing. Vibe coding stops you at a trust ceiling: the tool did everything, and nobody can explain what it built. That gap does not show up in the demo. It shows up the first time real users, real money, and real attackers arrive at once. Better prompts do not close it. Engineering does, and that is us.
The 2026 numbers on AI-built apps in production
The prototype phase is over.
Independent research on vibe-coded apps in production is blunt, and it gets worse every month, not better.
- A security firm's scan of over 1,400 vibe-coded production apps found 65% with security issues and 58% with at least one critical vulnerability, including hundreds of exposed secrets and exposed personal data.
- University tracking logged 35 new security vulnerabilities from AI-generated code in March 2026 alone, up from six in January.
- Studies consistently find AI-generated code carries flaws at roughly 2.7 times the rate of engineer-written code.
- Documented incidents in 2025 and 2026 include over a million exposed API keys and production databases wiped by AI agents.
None of this means you made a mistake. It means the prototype phase is over.
The five walls of a vibe-coded app
Where working code stops being sound code.
Secrets in the code. API keys and database credentials hard-coded where they can leak, because the AI optimised for working, not for safe.
The credit spiral. Every fix attempt costs credits, each fix breaks something else, and your bill grows precisely because the app has problems.
A data model designed by autocomplete. Fine at 100 users. At 10,000, queries crawl, costs spike, and features become impossible because the foundation was never designed, only generated.
No tests, no monitoring. The app works until it does not, and your first observability tool is a customer complaint.
What "production architecture" actually means
From generated code to engineered system
This is what changes when an app graduates, and what you are actually buying:
Security you can state. Audited auth, rotated and vaulted secrets, access rules an engineer has read and signed off.
A data model designed for your product, so the next feature is a sprint, not a rebuild.
Tests and evals, so a change that breaks something is caught before your users find it.
Observability: errors, latency and cost monitored with alerts, so you know before customers do.
CI/CD and rollback: every release repeatable, every mistake reversible.
Documentation and handover, so your next hire or your investor's technical advisor reads the system and nods.
This is the checklist that separates a demo from a product. If your app is missing half of it, that is not a failing, it is the engineering that was never done, and it is exactly what we do.
How the rescue works
Audit, stabilise, graduate.
Audit first
We read what the AI wrote: auth, data access, secrets, dependencies, architecture. Plain-language report of what is solid, fragile, and dangerous. Days, not weeks.
Stabilise immediately
Rotate exposed secrets, fix auth, close data-access holes. This lands before anything else.
Rebuild only what needs engineering
If it runs on Supabase and Supabase fits, it stays. Your product keeps running; the foundation under it becomes something an engineer can maintain, test, and explain.
Keep the AI-era speed, lose the risk
Our engineers use AI coding tools daily, under senior review. You do not go from vibe-speed to enterprise-slow; you go from unreviewed to reviewed.
The builders and agents we take over
We work from the code, whatever generated it.
We do not claim identical depth on every product. We work from the resulting codebase and its architecture, so if your product came out of one of these, we can read it, audit it, and take it to production.
Full-stack AI app builders
Lovable, Bolt, Replit Agent, Base44, Firebase Studio
UI and code generators
v0, Google AI Studio
Coding agents and AI IDEs
Cursor, Windsurf, Claude Code, GitHub Copilot, OpenAI Codex
Lovable is one of the most popular AI builders, and its apps have a specific anatomy: a managed Supabase-style backend (Lovable Cloud or your own Supabase), a generated React frontend, GitHub export. We work on Lovable codebases enough that it has its own page. Bolt, v0, Replit and agent-built codebases follow the same audit-stabilise-graduate path on their own stacks.
Where this goes
Every product that lasts ends up as engineered software you own.
The future of building is not better prompts on top of someone else's black box. It is software with security you can state, a data model built for your product, tests, monitoring, and full ownership, delivered once and yours to keep.
Vibe coding is the fastest way to find out an idea works. Custom engineering is how it survives being right. When you are ready for that step, taking AI-built apps there is the whole of what we do.
What it costs
What production-grade costs
The short answer
Taking a vibe-coded app to production at KUMO starts inside the $20K to $50K Starter Build: a security and architecture audit first, urgent fixes within days, then phased engineering of what actually needs rebuilding. Multi-workflow platforms run $50K to $100K. These are the live custom software development bands, no new numbers. If the audit finds your app is sounder than you feared, we will tell you, and you keep your money.
Starter Build
$20K to $50K
4 to 16 weeks
Audit and stabilise first, then the first phase of engineering: security fixes in days, the rest rebuilt only where it needs to be.
Grow Build
$50K to $100K
16 to 24 weeks
A multi-workflow platform: data model, backend and integrations re-engineered for scale, with the app live throughout.
Support and Growth Team
$5K to $10K per month
Ongoing, cancel with 30 days notice
The engineering team on retainer once the app is production-grade: new features under review, evals, and monitoring.
The audit-and-stabilise step always comes first, inside the Starter Build. You will know what is dangerous within days, and what everything costs before anything is rebuilt.
Proof
Engineered systems on live revenue.
Equipp (Ralco Group). A production B2B and B2C rental marketplace. In the client's own Clutch review, the work included rebuilding the billing system and repairing a broken payment gateway on a live revenue system, exactly the hidden fragility an audit surfaces.
Read the case study →CampaignHQ. Our own SaaS, built and operated by us end to end: auth, billing, data model, monitoring, the parts a generated app never gets. Live on G2 and Capterra, running on AWS, shipping to customers every day.
Read the case study →How we ship. Our engineers use the same AI coding tools you do, every day, but under senior review with tests, evals and observability. You keep the speed; every shipped line still answers to an accountable human.
Built with n8n →Assembled per build
Technologies we build with.
There is no single KUMO stack. Every build gets its own, assembled for your workload, your data, your team, and whoever maintains the system after handover. These are the technologies we assemble those stacks from, and why each earns its place.
Languages and runtimes
- TypeScript
- Python
- Go
- Rust
- Node.js
- Bun
- Ruby on Rails
TypeScript end to end for most products: one language across frontend and API cuts handover cost and hiring risk. Python where the workload is AI-heavy. Go where raw throughput decides the architecture, and Rust on hot paths where every millisecond is money. We run Node.js and adopt Bun where its speed pays. Our engineers shipped and scaled Ruby on Rails at Volopay, and we still support Rails codebases in production.
Product surfaces
- React
- Next.js
- Astro
- React Native
- Expo
- Tailwind CSS
- shadcn/ui
- Radix UI
React and Next.js for web products. Astro for content-heavy sites where load speed is the feature. React Native with Expo for iOS and Android from one codebase, native modules where the product demands them. Tailwind CSS with shadcn/ui and Radix for design systems that ship fast. Real-time and streaming interfaces with WebSockets and server-sent events, because AI products that make users wait for a full response feel broken.
APIs, data, and architecture
- Convex
- Node.js
- Hono
- Postgres
- Drizzle
- Redis
- Zod
- Better Auth
- FastAPI
- Supabase
Two backend tracks, chosen per product. Convex for real-time serverless products: queries, mutations, actions, a scheduler, cron jobs, storage, and live subscriptions. Node.js services with Hono and typed oRPC over Postgres and Drizzle ORM for relational, retrieval-heavy products. Postgres is extended with pgvector for vector search and full-text search, so most AI features ship without a second database. Redis for caching and queues. Zod for end-to-end validation, Better Auth for authentication, and FastAPI or Supabase where they fit the job.
AI models
- OpenAI
- Anthropic
- Gemini
- Llama
- Mistral
- DeepSeek
- ElevenLabs
Model choice is an engineering decision, not a loyalty program. OpenAI GPT and Anthropic Claude for frontier reasoning, Google Gemini where multimodal or context length wins. Open-weight models, Llama, Mistral, DeepSeek, self-hosted when privacy or unit economics demand it. Specialist models where the product needs a specialist: ElevenLabs and dialogue-native TTS for production voice, Whisper for speech to text, dedicated embedding and reranking models for retrieval quality, image and vision models for documents and floor plans. Every model sits behind a provider-swappable abstraction, so switching is a configuration decision, not a rewrite.
AI application layer
- Vercel AI SDK
- Qdrant
- LangGraph
- Hugging Face
AI features are built on the Vercel AI SDK and Convex Agent and RAG components: structured outputs, agentic tool use, streaming, and embeddings. Retrieval on pgvector by default, with Cohere reranking and Tavily web-search fallback, and managed vector stores like Qdrant at scale. Orchestration with LangGraph or custom code, tool connectivity over MCP, the protocol now standardising how AI systems talk to software. And the part that decides whether AI survives production: evals before ship, tracing in production, structured outputs, semantic caching, and model routing to control cost.
AI infrastructure and GPU
- Ollama
- FFmpeg
We deploy AI through AWS Bedrock, Google Vertex AI, and Azure OpenAI where enterprise controls matter, direct APIs where speed matters, and vLLM or Ollama where self-hosting wins. Self-hosted GPU inference on RunPod with a scale-to-zero strategy, and image models through fal.ai. Media assembly and normalisation with FFmpeg.
Cloud, delivery, and jobs
- AWS
- Google Cloud
- Azure
- Docker
- Coolify
- Kubernetes
- Turborepo
- Terraform
- GitHub Actions
AWS first: KUMO is an AWS Partner and runs its own SaaS, CampaignHQ, on AWS in production, with S3, EC2, CloudFront, and Route 53. Also Google Cloud, Azure, and client infrastructure including on-prem. Docker everywhere, Coolify and Kubernetes for deployment, serverless and edge where they fit. Monorepos on Turborepo, infrastructure as code with Terraform, background jobs on Trigger.dev, and delivery through GitHub Actions CI/CD.
Observability and quality
- Sentry
- OpenTelemetry
- Playwright
Sentry for application errors, Langfuse for LLM traces, model metadata, and token usage, and OpenTelemetry for distributed tracing. End-to-end and AI-driven browser testing with Playwright. Cost, latency, and error tracking by workflow and model, so problems surface before customers see them.
Payments and integrations
- Stripe
- Razorpay
- Resend
- Discord
Billing and payments with Stripe and Razorpay, subscriptions, webhooks, tax, and invoicing. Transactional email through Resend, team workflows over Discord, and the Google ecosystem, OAuth, Drive, and Sheets, wired in where products need it.
FAQ
Vibe coding to production, answered straight.
What is vibe coding?+
Building software by describing it to an AI (Lovable, Bolt, v0, Replit, or coding agents) that generates the code for you. It has made product validation radically faster and cheaper, and it has created a new problem: working apps whose own founders cannot explain or safely extend the code underneath.
Can you take over an app built with AI?+
Yes. Audit first, urgent security fixes in days, then phased engineering of what needs rebuilding. Parts of the generated stack that fit your product stay.
Is my AI-built app safe?+
Find out before your users do: a majority of scanned vibe-coded production apps had security issues, over half at least one critical vulnerability. An audit answers it for your app specifically, in days.
Do I have to stop using my AI builder?+
Not necessarily. Some teams keep prompting the frontend while we engineer the backend, auth and data layer. The point is that everything customer-facing and data-touching gets engineered review.
How much does it cost to make a vibe-coded app production-ready?+
Starts inside the $20K to $50K Starter Build, audit included, 4 to 16 weeks. Larger platforms $50K to $100K. Ongoing team $5K to $10K per month.
What if the audit finds the app is fine?+
Then we say so, you get the report, and you come back when scale makes it untrue. The audit is the start of the Starter Build, not a separate fee, and we do not invent work.
Who owns the code afterwards?+
You do, from day one, in your GitHub organisation: source, infrastructure as code, docs. Full IP transfer.
Tell us what you built and what scares you about it.
30 minutes, no deck. Tell us the tool, the traction, and the thing you cannot explain. We will tell you what needs securing this week, what can wait, and what it costs to make the whole thing boring and reliable. Honest answers, and only some of them are us.