Professional handover instead of an automatic rebuild
Vibe coding describes rapid development with AI assistants such as Cursor, ChatGPT, Lovable, or v0. These tools can produce working interfaces and early workflows quickly.
A production B2B app needs more. It requires clear security boundaries, tests, written records, and a repeatable operating process.
We assess the current state without dismissing the code or selling a rebuild by default. Viable parts stay in place while we fix critical gaps in a clear order.
If the product is still at idea stage, we separate the handover from a structured MVP development engagement.
What AI-generated software usually needs us to review
Credentials and secrets
API keys do not belong in a repository. We review permissions, environment variables, and the handling of production credentials.
Authentication and privacy
Roles, tenant separation, input validation, and data flows must match the application. We include GDPR requirements where personal data is involved.
Testing and version control
Automated tests, clear branches, and traceable reviews prevent regressions when people and AI continue working on the same codebase.
Deployment and backups
A release needs repeatable builds, separate environments, backup and restore processes, and a defined rollback path.
Dependencies and licences
We identify libraries, versions, and licence obligations. Unclear or outdated dependencies receive a visible priority.
Architecture and maintainability
Duplicated logic, unclear ownership, and tight coupling make every change expensive. A focused architecture review provides direction.
For sensitive applications, we deepen the review through GDPR-compliant software engineering and add a dedicated testing and quality assurance track where needed.
Audit checklist: the evidence you receive
- Repository, branches, build process, and dependencies
- Rights to source code, assets, and AI-generated components
- Authentication, roles, and tenant separation
- Secrets, API keys, and third-party services
- Data flows, GDPR, logging, and deletion paths
- Test coverage, core flows, and known regressions
- Deployment, hosting, backups, and recovery
- Prioritised roadmap with effort and responsibilities
Five steps from vibe-coded project to stable operations
- 1
Clarify repository access, rights, and credentials
We review source code, dependencies, licences, technical access, and ownership of all components in use.
- 2
Audit risk and production readiness
We assess architecture, authentication, secrets, privacy, tests, data storage, backups, and deployment.
- 3
Prioritise findings and define the roadmap
You receive a clear traffic-light assessment with blockers, effort, dependencies, and an actionable sequence.
- 4
Harden the code and make delivery reproducible
We fix prioritised risks, add tests, CI/CD, logging, and documentation, and prepare a controlled production release.
- 5
Hand over continued development or maintenance
After a stable release, we continue the roadmap or transfer the system to your team with traceable documentation.
We align the target structure with your organisation. Appropriate software architecture consulting does not maximise complexity. It creates a system that fits the team, product, and expected growth.
Three common AI code handover scenarios
Founder MVP with early users
An MVP built with Cursor or Lovable has validated demand. Before more customers arrive, we review authentication, payments, privacy, and scaling and establish a reliable release pipeline.
Internal tool built by a business team
A team has created a useful workflow tool with ChatGPT. We separate test and production data, add roles, logging, and backups, and connect the tool to existing systems under controlled conditions.
v0 front end that needs a real back end
A convincing interface needs to become a dependable product. We review components and licences, structure the API and data model, and replace fragile mock logic with testable business processes.
Where existing systems are involved, we include reliable API and integration engineering early. This prevents a useful prototype from becoming an unmanaged data shadow beside the ERP, CRM, or shop.
Three ways to start with your existing application
1. Code and risk audit
typically EUR 2,800–5,600
3–5 working days
For teams that need an independent assessment. You receive findings, a traffic-light rating, prioritised actions, and a reliable decision about the next step.
2. Production hardening
typically EUR 8,400–28,000
2–8 weeks
For applications approaching launch. We remove blockers and add safeguards, tests, CI/CD, logging, and documented delivery.
3. Continued development
EUR 140/hour excl. VAT
ongoing or milestone-based
For products with real user demand. We own roadmap, releases, and operations or prepare a clean transfer to your internal engineering team.
These ranges are planning values from Groenewold IT project experience and are based on EUR 140 per hour excluding VAT. After the initial review, you receive the audit as a clearly scoped fixed-price phase.
What we deliberately do not do with vibe-coded projects
- We do not dismiss AI-generated code by default or sell a complete rebuild without evidence.
- We do not promise a fictional “100% AI-safe” application; we document concrete risks and safeguards.
- We do not deploy directly to production while backups, access, tests, and rollback remain unresolved.
- We do not pass responsibility to anonymous offshore teams: engineering and project ownership stay in Leer, Germany.
Project references
Selected case studies from our project work
Concrete examples with measurable outcomes — swipe through matching references or open the full case study.
AI code handover cost
Development, consulting, and project management are billed at EUR 140 per hour excluding VAT. After a short first review, we scope the audit as a fixed-price phase.
A generic quote without repository evidence would be misleading. Test coverage, data models, dependencies, and security risks differ from one codebase to the next.
As an orientation, a focused audit typically ranges from EUR 2,800 to EUR 5,600. Comparable technical hardening engagements often plan between EUR 8,400 and EUR 28,000. We define the actual fixed price after the review, so you do not pay for generic risk buffers.
The audit produces a prioritised roadmap. You can then commission hardening, continued development, and ongoing software maintenance separately. Estimates are planning values based on our project experience, not guarantees.
When software rescue is the better starting point
A normal handover is not enough when the app already fails in production. The same applies when releases are blocked or the previous supplier can no longer deliver.
Our software rescue service for critical projects then provides the faster path. It combines diagnosis with immediate stabilisation.
AI code handover is designed for early products that already work at a basic level. The goal is a controlled move into expert engineering, security, and stable operations.
Engineering and project ownership remain Made in Germany with our team in Leer, East Frisia.
Get a professional assessment of your repository
We clarify what already works, which risks must be resolved before launch, and whether an audit, hardening phase, or direct handover is the best next step.





