Vibecoding Bug Cleaning
An AI-generated codebase that works until it does not. We audit it, fix the security and data problems first, and leave something a team can run. For prototypes that now have customers and codebases nobody fully understands.
Who this is for
- A prototype built in a weekend that now has paying customers.
- A codebase generated faster than anyone read it.
- Recurring bugs that get fixed and come back somewhere else.
- A due-diligence request from an investor or acquirer.
What is included. Tick what you need.
Artefacts, not adjectives. Each is something you can point to at the end. Tick the ones your project needs and send the list with your enquiry; we reply with a written scope.
Technologies we use for this
The relevant slice of our technology matrix. Nothing here that we cannot staff today.
- Python (Django, FastAPI, Flask)
- Node.js (Express, NestJS)
- PHP (Laravel)
- Go
- REST
- GraphQL
- gRPC
- WebSockets
- Celery
- Redis Queue
How we deliver it
The five steps every engagement goes through, in the form they take for this service.
Audit
A week reading the code and running it, ending with a prioritised list and the cost of each fix.
Stop the bleeding
Security and data problems fixed and deployed first, before anything cosmetic.
Stabilise
Tests around critical paths, error tracking, and the recurring bugs traced to their cause.
Restructure
Refactor in small, reviewed steps so the product keeps working throughout.
Hand over
Documentation, a reproducible build, and a session with whoever runs it next.
From the blog
- AI coding agents in production: the review gates that make them safeCoding agents now write a lot of software. What we put between an agent's output and production: five review gates, why each exists, and what we measure.
- What we check before taking over someone else's codebaseThe audit we run in the first week on an inherited codebase: the eight questions we answer, in order, and what each one tells you about the months ahead.
- What breaks in AI-generated codebases, in the order it breaksWe have audited many codebases built mostly by AI tools. The same seven problems appear in the same order, from week one to month six. How to catch them early.
Questions we get asked
Should we rewrite it instead?
Usually not. Most AI-generated codebases are salvageable with a structured cleanup, and a rewrite throws away the product knowledge in the working parts. The audit says which.
What do you fix first?
Anything that exposes customer data or lets someone in who should not be. Then data integrity. Then the bugs customers hit most.
How long does the audit take?
About a week for a typical prototype. You get the written list and the cost of each fix, and you choose what to do with it, with us or without.
Can our own AI tools keep working on it afterwards?
Yes, and better. A clean structure with tests is exactly what makes AI tools reliable. We leave the conventions written down.
Do you sign an NDA?
Yes, before we see the code.
Tell us what you are building.
We reply within one business day with how we would build it, what it would cost, and which engagement model fits.
- 01Tell us what you are building
A short form or an email. No deck required, and "not sure yet" is a fine answer.
- 02A call with an engineer
Within one business day. Technical questions get technical answers, from the person who would build it.
- 03A written scope and quote
Fixed price where the scope is defined. The document is yours whether or not you go ahead.