You built it yourself,
now it has to be real.
Every tool gets stuck in a different place. Bolt on the server side, v0 on the data, Replit on the environment, Cursor on permissions and migrations. Pick what you started with and you see exactly what sits between your version and production.
In half a minute I show what almost always sits below the waterline in a project like this: everyone can reach all the data, payments that only work in the demo, and an environment that does not run outside the tool. Recognise it? Send your link.
In every case the route is the same: first I look at what is there for free, then you hear whether building on beats starting over, and only after that do you get a fixed price. You talk to the same person who builds it the whole way. Want it in writing, with risks and prices per block, then the vibecode assessment is the next step. Still unsure about the tool itself? They sit side by side here.
- Who
- Bas Voets, one-person agency, building since 2021
- Where
- Hazerswoude-Dorp, Alphen aan den Rijn, and Berkel en Rodenrijs
- Working area
- Remote across Europe, on-site in the Netherlands
- Tools I take over
- Lovable, Bolt.new, v0, Replit, Cursor
- Stack
- Next.js, React, TypeScript, Supabase, Stripe, Mollie
- Hosting
- Inside the EU as standard, on your own account
- Rating
- 5.0 average from 8 Google reviews
Six things decide whether
your app can go live.
This is the list I work through before anything gets built. You get it back in writing, with per point what is there, what is missing and what it costs to have it right.
Code quality and maintainability
Is the same logic in five places? Is there version control with a readable history, or only a list of prompts? This decides whether building on is cheaper than starting over.
Security
Keys sent along in the browser, authentication that only lives in the screen, and database-level permissions switched off. These are the three that are wrong by default in practically every AI project.
Data model and migrations
Do the tables roughly add up, or is everything in one table with columns like extra_1? Is there a migration history, so you can trace when a column appeared and why?
Performance and scalability
What happens at a hundred simultaneous users instead of one? Usually the bottleneck is not the code but queries that run another query per row.
Deployment and environments
Does everything run on one environment, so you test on your real customers? A separate test environment is half an hour of work and the difference between discovering problems and explaining them.
Monitoring and backups
Do you know when something falls over, or do you hear it from a customer? And has a single backup ever been restored, or is its existence an assumption?
Even if you pick someone else.
Have it investigated first, build after
A party that says it has to be rebuilt without seeing your code is selling a project, not a solution. What should happen is a review that ends in a list: this stays, this we replace, this can wait. With a price per part.
Ask who owns the code afterwards
Repository, hosting and domain belong in your name, not the agency's. The hesitation at that question says more than the answer. You have just learned how it feels to depend on a platform; do not repeat it.
See whether they take your prototype seriously
What you built is the sharpest specification you will ever get: you tried it out instead of writing it down. An agency that dismisses that as amateur work is going to ask you the same design questions again, and you pay the hours.
Ask who actually works on it
In this kind of track the value sits in someone who holds the whole codebase in their head. Rotating teams work fine on new builds and badly on taking over someone else's code, because the context is not in the documentation.
There are more parties who do this, and for a project with a team of ten I am not the right choice. What you read above applies to any of them; ask them the same four questions. If you are torn between building on yourself, an agency or someone like me, that is worked out point by point here.
Which agency can make my Lovable app production-ready?
What does making an AI prototype production-ready cost?
Does my app have to be rebuilt entirely?
Can I keep vibecoding afterwards?
Do you work remotely?
This compiles,
and it still goes wrong.
Fourteen lines of code as they roll out of a prototype. It runs, the demo works, and that is how it goes live. Hit scan and see what an audit pulls out of it.
1// app/api/orders/route.ts2import { createClient } from '@supabase/supabase-js'3 4const SUPABASE_KEY = "eyJhbGciOiJIUzI1NiIsInR5cCI6..."5 6export async function GET(req) {7 const supabase = createClient(URL, SUPABASE_KEY)8 9 const { data } = await supabase10 .from('orders')11 .select('*')12 13 return Response.json(data)14}This compiles, works in the demo and goes live. Click scan.
Fourteen lines, three holes of which two open your entire database. A real audit runs through your whole project like this.
Answers, without
having to call.
The things everyone runs into who wants to take Lovable, Bolt or Cursor further than a prototype. Written out, with what you can check yourself before bringing anyone in.
Betalingen werken in test, maar niet live
De testbetaling gaat door en de echte niet. Vijf oorzaken, waarvan er één zo vaak voorkomt dat je daar het beste kunt beginnen.
5 min readMijn AI-app is ineens traag geworden
Hij deed het prima met tien rijen en kruipt nu bij duizend. Vier oorzaken die bijna altijd de verklaring zijn, van makkelijkst naar vervelendst om te repareren.
5 min readMijn API-sleutels staan in de frontend. Hoe erg is dat?
Kort antwoord: dat hangt af van welke sleutel het is. Hoe je in twee minuten ziet of de jouwe onschuldig is of dat je hem vanavond nog moet vervangen.
6 min readWaarom werkt mijn app in de preview wel en live niet?
Hij deed het net nog. Vier oorzaken die samen zo goed als elk 'lokaal wel, live niet'-probleem verklaren, en hoe je in vijf minuten ziet welke van de vier het bij jou is.
6 min readIs je AI-gebouwde app veilig voor echte klanten? 9 checks
Je app werkt, dus hij lijkt af. De gaten die AI-tools standaard laten vallen zijn onzichtbaar zolang jij de enige gebruiker bent. Negen dingen die je vanmiddag zelf kunt nakijken.
8 min readDoorbouwen op mijn AI-prototype of opnieuw beginnen?
De duurste keuze is niet de verkeerde, maar de uitgestelde. Vijf vragen die bepalen of je project te redden is, en waarom opnieuw beginnen zelden betekent dat je werk weggooit.
6 min readWaarom kunnen mijn gebruikers elkaars gegevens zien?
Het scherm laat de juiste dingen zien, dus het lijkt goed. Tot iemand een cijfer in de URL verandert. Wat Row Level Security is, waarom het uit staat, en hoe je het controleert zonder developer.
7 min readKan ik mijn Lovable- of Bolt-app exporteren en zelf hosten?
Ja, en dat is verstandiger dan het uitstellen. Wat je precies meekrijgt bij een export, wat er níét in zit, en waar je op moet letten voordat je de knop indrukt.
6 min readWaarom breekt mijn Lovable-app bij elke wijziging?
Je vraagt om één aanpassing en er gaat iets stuk in een scherm dat je niet hebt aangeraakt. Dat is geen pech en het gaat niet vanzelf over. Wat er onder de motorkap gebeurt, en hoe je het stopt.
7 min readVijf signalen dat je AI-prototype tegen zijn grens loopt
Lovable, Bolt en v0 brengen je verrassend ver. Tot het punt waarop elke wijziging iets anders sloopt. Hoe je dat moment herkent voordat het je project kost.
6 min readHave your current site or tool scanned
You do not have to want to buy anything yet. Send what you have and I will tell you honestly what I would keep, what I would replace and whether that is worth the investment. Including when the answer is that you are better off doing nothing.
The scan is a first impression, not a security audit.
- 01Send a link to your site, your tool or your repository
- 02I look at speed, structure, data and security
- 03Usually within two working days you hear what I would replace and what that costs