AI-built apps, engineered

You vibe coded it. It works. Now make it survive success.

An AI generated your app in an afternoon, and that is genuinely new. What it did not generate is security you can prove, a data model that scales, or code anyone can explain when it breaks at 2am, because no prompt does. A working demo and a business you can trust are different things. We are the engineering team that closes that gap: we take vibe-coded apps to production, software you own outright, one build instead of a bill that climbs every time it breaks.

A working demo is not a business

The tool did everything. That is the problem.

Millions of people can now generate an app from a sentence. Almost none of them can engineer one. If that is you, you are not behind, you are exactly where this wave leaves everyone: with a product that works and a foundation nobody actually built.

Lovable, Bolt, v0, Replit and coding agents turn a prompt into a running app in days. That part is real, and it is why you now have users to worry about. But an AI optimises for exactly one thing: making the screen do what you asked. Not security. Not a data model that survives scale. Not code a human can explain when it fails.

A no-code platform stops you at a capability ceiling: the tool cannot do the next thing. Vibe coding stops you at a trust ceiling: the tool did everything, and nobody can explain what it built. That gap does not show up in the demo. It shows up the first time real users, real money, and real attackers arrive at once. Better prompts do not close it. Engineering does, and that is us.

The 2026 numbers on AI-built apps in production

The prototype phase is over.

Independent research on vibe-coded apps in production is blunt, and it gets worse every month, not better.

58% of scanned vibe-coded production apps shipped with at least one critical vulnerability

None of this means you made a mistake. It means the prototype phase is over.

The five walls of a vibe-coded app

Where working code stops being sound code.

Authentication nobody can explain. It works in the happy path; no human can say what happens in the unhappy ones. The most common critical finding in AI-built apps.

Secrets in the code. API keys and database credentials hard-coded where they can leak, because the AI optimised for working, not for safe.

The credit spiral. Every fix attempt costs credits, each fix breaks something else, and your bill grows precisely because the app has problems.

A data model designed by autocomplete. Fine at 100 users. At 10,000, queries crawl, costs spike, and features become impossible because the foundation was never designed, only generated.

No tests, no monitoring. The app works until it does not, and your first observability tool is a customer complaint.

What "production architecture" actually means

From generated code to engineered system

This is what changes when an app graduates, and what you are actually buying:

Security you can state. Audited auth, rotated and vaulted secrets, access rules an engineer has read and signed off.

A data model designed for your product, so the next feature is a sprint, not a rebuild.

Tests and evals, so a change that breaks something is caught before your users find it.

Observability: errors, latency and cost monitored with alerts, so you know before customers do.

CI/CD and rollback: every release repeatable, every mistake reversible.

Documentation and handover, so your next hire or your investor's technical advisor reads the system and nods.

This is the checklist that separates a demo from a product. If your app is missing half of it, that is not a failing, it is the engineering that was never done, and it is exactly what we do.

How the rescue works

Audit, stabilise, graduate.

01

Audit first

We read what the AI wrote: auth, data access, secrets, dependencies, architecture. Plain-language report of what is solid, fragile, and dangerous. Days, not weeks.

02

Stabilise immediately

Rotate exposed secrets, fix auth, close data-access holes. This lands before anything else.

03

Rebuild only what needs engineering

If it runs on Supabase and Supabase fits, it stays. Your product keeps running; the foundation under it becomes something an engineer can maintain, test, and explain.

04

Keep the AI-era speed, lose the risk

Our engineers use AI coding tools daily, under senior review. You do not go from vibe-speed to enterprise-slow; you go from unreviewed to reviewed.

The builders and agents we take over

We work from the code, whatever generated it.

We do not claim identical depth on every product. We work from the resulting codebase and its architecture, so if your product came out of one of these, we can read it, audit it, and take it to production.

Full-stack AI app builders

Lovable, Bolt, Replit Agent, Base44, Firebase Studio

UI and code generators

v0, Google AI Studio

Coding agents and AI IDEs

Cursor, Windsurf, Claude Code, GitHub Copilot, OpenAI Codex

Where this goes

Every product that lasts ends up as engineered software you own.

The future of building is not better prompts on top of someone else's black box. It is software with security you can state, a data model built for your product, tests, monitoring, and full ownership, delivered once and yours to keep.

Vibe coding is the fastest way to find out an idea works. Custom engineering is how it survives being right. When you are ready for that step, taking AI-built apps there is the whole of what we do.

What it costs

What production-grade costs

The short answer

Taking a vibe-coded app to production at KUMO starts inside the $20K to $50K Starter Build: a security and architecture audit first, urgent fixes within days, then phased engineering of what actually needs rebuilding. Multi-workflow platforms run $50K to $100K. These are the live custom software development bands, no new numbers. If the audit finds your app is sounder than you feared, we will tell you, and you keep your money.

Scale up

Grow Build

$50K to $100K

16 to 24 weeks

A multi-workflow platform: data model, backend and integrations re-engineered for scale, with the app live throughout.

Keep shipping

Support and Growth Team

$5K to $10K per month

Ongoing, cancel with 30 days notice

The engineering team on retainer once the app is production-grade: new features under review, evals, and monitoring.

The audit-and-stabilise step always comes first, inside the Starter Build. You will know what is dangerous within days, and what everything costs before anything is rebuilt.

Proof

Engineered systems on live revenue.

Equipp (Ralco Group). A production B2B and B2C rental marketplace. In the client's own Clutch review, the work included rebuilding the billing system and repairing a broken payment gateway on a live revenue system, exactly the hidden fragility an audit surfaces.

Read the case study →

CampaignHQ. Our own SaaS, built and operated by us end to end: auth, billing, data model, monitoring, the parts a generated app never gets. Live on G2 and Capterra, running on AWS, shipping to customers every day.

Read the case study →

How we ship. Our engineers use the same AI coding tools you do, every day, but under senior review with tests, evals and observability. You keep the speed; every shipped line still answers to an accountable human.

Built with n8n →

Assembled per build

Technologies we build with.

There is no single KUMO stack. Every build gets its own, assembled for your workload, your data, your team, and whoever maintains the system after handover. These are the technologies we assemble those stacks from, and why each earns its place.

01

Languages and runtimes

  • TypeScript logo, KUMO primary language TypeScript
  • Python logo, KUMO language for AI workloads Python
  • Go logo, KUMO language for high-throughput services Go
  • Rust logo, KUMO language for performance-critical paths Rust
  • Node.js logo, KUMO API runtime Node.js
  • Bun logo, KUMO fast JavaScript runtime Bun
  • Ruby on Rails logo, KUMO supports Rails in production Ruby on Rails

TypeScript end to end for most products: one language across frontend and API cuts handover cost and hiring risk. Python where the workload is AI-heavy. Go where raw throughput decides the architecture, and Rust on hot paths where every millisecond is money. We run Node.js and adopt Bun where its speed pays. Our engineers shipped and scaled Ruby on Rails at Volopay, and we still support Rails codebases in production.

02

Product surfaces

  • React logo, KUMO web framework React
  • Next.js logo, KUMO web framework Next.js
  • Astro logo, KUMO framework for content-heavy sites Astro
  • React Native logo, KUMO framework for iOS and Android apps React Native
  • Expo logo, KUMO React Native tooling Expo
  • Tailwind CSS logo, KUMO design-system styling Tailwind CSS
  • shadcn/ui logo, KUMO component system shadcn/ui
  • Radix UI logo, KUMO accessible component primitives Radix UI

React and Next.js for web products. Astro for content-heavy sites where load speed is the feature. React Native with Expo for iOS and Android from one codebase, native modules where the product demands them. Tailwind CSS with shadcn/ui and Radix for design systems that ship fast. Real-time and streaming interfaces with WebSockets and server-sent events, because AI products that make users wait for a full response feel broken.

03

APIs, data, and architecture

  • Convex logo, KUMO real-time serverless backend Convex
  • Node.js logo, KUMO API runtime Node.js
  • Hono logo, KUMO HTTP framework Hono
  • Postgres logo, KUMO default database Postgres
  • Drizzle ORM logo, KUMO typed database access Drizzle
  • Redis logo, KUMO caching and queues Redis
  • Zod logo, KUMO schema validation Zod
  • Better Auth logo, KUMO authentication Better Auth
  • FastAPI logo, KUMO Python API framework FastAPI
  • Supabase logo, KUMO rapid backend platform Supabase

Two backend tracks, chosen per product. Convex for real-time serverless products: queries, mutations, actions, a scheduler, cron jobs, storage, and live subscriptions. Node.js services with Hono and typed oRPC over Postgres and Drizzle ORM for relational, retrieval-heavy products. Postgres is extended with pgvector for vector search and full-text search, so most AI features ship without a second database. Redis for caching and queues. Zod for end-to-end validation, Better Auth for authentication, and FastAPI or Supabase where they fit the job.

04

AI models

  • OpenAI logo, KUMO builds AI on OpenAI GPT models OpenAI
  • Anthropic logo, KUMO builds AI on Anthropic Claude Anthropic
  • Google Gemini logo, KUMO multimodal AI model Gemini
  • Meta Llama logo, KUMO open-weight AI model Llama
  • Mistral logo, KUMO open-weight AI model Mistral
  • DeepSeek logo, KUMO open-weight AI model DeepSeek
  • ElevenLabs logo, KUMO production voice AI ElevenLabs

Model choice is an engineering decision, not a loyalty program. OpenAI GPT and Anthropic Claude for frontier reasoning, Google Gemini where multimodal or context length wins. Open-weight models, Llama, Mistral, DeepSeek, self-hosted when privacy or unit economics demand it. Specialist models where the product needs a specialist: ElevenLabs and dialogue-native TTS for production voice, Whisper for speech to text, dedicated embedding and reranking models for retrieval quality, image and vision models for documents and floor plans. Every model sits behind a provider-swappable abstraction, so switching is a configuration decision, not a rewrite.

05

AI application layer

  • Vercel AI SDK logo, KUMO AI application framework Vercel AI SDK
  • Qdrant logo, KUMO managed vector store Qdrant
  • LangGraph logo, KUMO AI orchestration LangGraph
  • Hugging Face logo, KUMO open-weight model sourcing Hugging Face

AI features are built on the Vercel AI SDK and Convex Agent and RAG components: structured outputs, agentic tool use, streaming, and embeddings. Retrieval on pgvector by default, with Cohere reranking and Tavily web-search fallback, and managed vector stores like Qdrant at scale. Orchestration with LangGraph or custom code, tool connectivity over MCP, the protocol now standardising how AI systems talk to software. And the part that decides whether AI survives production: evals before ship, tracing in production, structured outputs, semantic caching, and model routing to control cost.

06

AI infrastructure and GPU

  • Ollama logo, KUMO self-hosted model runtime Ollama
  • FFmpeg logo, KUMO media processing FFmpeg

We deploy AI through AWS Bedrock, Google Vertex AI, and Azure OpenAI where enterprise controls matter, direct APIs where speed matters, and vLLM or Ollama where self-hosting wins. Self-hosted GPU inference on RunPod with a scale-to-zero strategy, and image models through fal.ai. Media assembly and normalisation with FFmpeg.

07

Cloud, delivery, and jobs

  • AWS logo, KUMO deploys on AWS as an AWS Partner AWS
  • Google Cloud logo, KUMO production cloud Google Cloud
  • Microsoft Azure logo, KUMO production cloud Azure
  • Docker logo, KUMO containerised deployments Docker
  • Coolify logo, KUMO application deployment Coolify
  • Kubernetes logo, KUMO container orchestration Kubernetes
  • Turborepo logo, KUMO monorepo build system Turborepo
  • Terraform logo, KUMO infrastructure as code Terraform
  • GitHub Actions logo, KUMO CI/CD delivery GitHub Actions

AWS first: KUMO is an AWS Partner and runs its own SaaS, CampaignHQ, on AWS in production, with S3, EC2, CloudFront, and Route 53. Also Google Cloud, Azure, and client infrastructure including on-prem. Docker everywhere, Coolify and Kubernetes for deployment, serverless and edge where they fit. Monorepos on Turborepo, infrastructure as code with Terraform, background jobs on Trigger.dev, and delivery through GitHub Actions CI/CD.

08

Observability and quality

  • Sentry logo, KUMO application error monitoring Sentry
  • OpenTelemetry logo, KUMO distributed tracing OpenTelemetry
  • Playwright logo, KUMO end-to-end and AI browser testing Playwright

Sentry for application errors, Langfuse for LLM traces, model metadata, and token usage, and OpenTelemetry for distributed tracing. End-to-end and AI-driven browser testing with Playwright. Cost, latency, and error tracking by workflow and model, so problems surface before customers see them.

09

Payments and integrations

  • Stripe logo, KUMO payments and billing Stripe
  • Razorpay logo, KUMO payments and billing Razorpay
  • Resend logo, KUMO transactional email Resend
  • Discord logo, KUMO team and notification workflows Discord

Billing and payments with Stripe and Razorpay, subscriptions, webhooks, tax, and invoicing. Transactional email through Resend, team workflows over Discord, and the Google ecosystem, OAuth, Drive, and Sheets, wired in where products need it.

FAQ

Vibe coding to production, answered straight.

What is vibe coding?

Building software by describing it to an AI (Lovable, Bolt, v0, Replit, or coding agents) that generates the code for you. It has made product validation radically faster and cheaper, and it has created a new problem: working apps whose own founders cannot explain or safely extend the code underneath.

Can you take over an app built with AI?

Yes. Audit first, urgent security fixes in days, then phased engineering of what needs rebuilding. Parts of the generated stack that fit your product stay.

Is my AI-built app safe?

Find out before your users do: a majority of scanned vibe-coded production apps had security issues, over half at least one critical vulnerability. An audit answers it for your app specifically, in days.

Do I have to stop using my AI builder?

Not necessarily. Some teams keep prompting the frontend while we engineer the backend, auth and data layer. The point is that everything customer-facing and data-touching gets engineered review.

How much does it cost to make a vibe-coded app production-ready?

Starts inside the $20K to $50K Starter Build, audit included, 4 to 16 weeks. Larger platforms $50K to $100K. Ongoing team $5K to $10K per month.

What if the audit finds the app is fine?

Then we say so, you get the report, and you come back when scale makes it untrue. The audit is the start of the Starter Build, not a separate fee, and we do not invent work.

Who owns the code afterwards?

You do, from day one, in your GitHub organisation: source, infrastructure as code, docs. Full IP transfer.

Tell us what you built and what scares you about it.

30 minutes, no deck. Tell us the tool, the traction, and the thing you cannot explain. We will tell you what needs securing this week, what can wait, and what it costs to make the whole thing boring and reliable. Honest answers, and only some of them are us.