Daniel Brosed

SECURITY AUDIT · AI-BUILT APPS

Vibe coding security audit.

You shipped your app in a weekend with Lovable, Cursor or Bolt. Nobody has checked whether it is secure. I review it by hand against the OWASP checklist and hand you a report with every hole and its exact fix. From €600, public pricing, EU-based.

Book a 30-min callSee pricing

How much does a vibe coding security audit cost?

A vibe coding security audit costs between €600 and €2,500, excluding VAT. Express (from €600) covers the full app-level OWASP checklist in 1-2 business days. Full (from €1,500) adds a deep review of RLS, secrets and authentication. Hardening (from €2,500) includes the fixes implemented as Pull Requests. Fixed prices, published here before you ever write to me.

Express

from €600

Turnaround: 1-2 business days

For MVPs and AI-built apps not yet making money

  • Full app-level OWASP checklist
  • Report with findings ranked by severity
  • The concrete fix for every finding

Out of scope

  • Not a penetration test
  • Does not include implementing the fixes
  • No compliance certification (SOC 2, GDPR)

Full

from €1,500

Turnaround: 4-5 business days

For production apps with users or payments

  • Everything in Express
  • Deep review of RLS/Supabase, secrets, auth and headers
  • A 30-min call to walk you through it all

Out of scope

  • Not a penetration test
  • Does not include implementing the fixes

Hardening

from €2,500

Turnaround: 8-10 business days

For teams that want the problem solved, not just diagnosed

  • Everything in Full
  • I implement the fixes as Pull Requests
  • Verification re-test + 30 days of support

Out of scope

  • Not a penetration test
  • No compliance certification (SOC 2, GDPR)

Prices exclude VAT: Spain +21%; EU businesses with a VAT number, reverse charge; outside the EU, no VAT applies.

Lovable, Cursor, Bolt and v0 apps

The tool does not matter much: the pattern repeats. AI generates fast and leaves the same holes behind: keys in the code, Supabase RLS policies never configured, open API routes, default CORS and headers. I build with these same tools every day, so I know exactly where to look.

Lovable

Apps with Supabase behind them. First things I check: RLS policies, anon and service_role keys, and what sits in public storage.

Cursor and Claude Code

Custom code that grows very fast. I check authentication, input validation and secrets forgotten in the repository.

Bolt

MVPs deployed in hours. I check environment variables, API routes and what got exposed to the browser by accident.

v0

Interfaces wired to real APIs. I check what travels to the client and what should have stayed on the server.

EU-based and GDPR-aware

I work from Barcelona and invoice from Spain. I review your app with GDPR in mind too: exposed personal data, forms sending information where it should not go, permissions that show more than they should. I do not certify compliance: I show you what is exposed and how to close it.

Your code never leaves my machine, I do not share it, and I delete it when the project closes. If you want an NDA, we sign it before you show me anything. EU businesses with a VAT number get a reverse-charge invoice; outside the EU, no VAT applies.

An audit with fixes included

I do not leave you with a list of scares. In Express and Full, every finding comes with its severity, its real impact and the concrete fix: what to change, where, and why. In Hardening I implement the fixes myself as Pull Requests on your repository, with a verification re-test and 30 days of support.

And if you asked the AI to review its own code, you already know what it said: everything looks fine. It repeats the same blind spots it created. This is not a penetration test and not a certification: it is the honest review your app needs before facing real users.

I call this service VaultAudit. Same method, same pricing, under its own name.

Vibe coding security audit FAQ

Does this work if my app was not built with AI?

Yes. The methodology is the same: the OWASP checklist applied to the application layer. AI-built apps are most of what I review because they are the ones that ship with the least review.

What exactly do I get?

A written report with every finding: severity, impact and the concrete fix. In Full I also walk you through it on a 30-minute call. In Hardening, the fixes come implemented as Pull Requests.

What do you need to start?

Read access to the repository (or a ZIP of the code) and the app URL. If there is a database, the schema and its policies. That is enough for the Express.

Is this a penetration test?

No. It is an application-layer audit: I review the code and the configuration from the inside. I do not attack the app from the outside and I do not certify compliance (SOC 2, GDPR).

How long does it take?

Express, 1-2 business days. Full, 4-5. Hardening, 8-10. Turnaround is part of the written proposal.

How do we start?

Book a 30-minute call or write to me on WhatsApp. It leads to a proposal with a fixed price and a fixed scope.

Want me to review your app?

No pitch, no pressure. You tell me what you built, I tell you honestly whether I am a fit, and it leads to a fixed-price proposal.

Book a 30-min callMessage me on WhatsApp

No pitch, no pressure. Just a conversation about your app.

← Back to danielbrosed.com