Security testing a vibe coded app
A security test of an AI-built app is a person trying to break the running product the way an attacker would, then telling you exactly what broke and how to fix it. For a small app it runs two to five days of testing and $2,000 to $12,000 CAD.
A security test of a vibe coded app costs $2,000 to $12,000 CAD for most small products and takes one to three weeks from the first call to the report. A tester logs in as each kind of user, maps what each one is allowed to do, and then tries everything they are not allowed to do: read another customer's records, call admin functions, skip payment, pull secrets out of the front end, flood the endpoints. What comes back is a list of what worked, ranked by harm, with a fix for each one written plainly enough to paste back into your AI tool.
Why AI-built apps need this more, not less
The AI tool writes code that satisfies the prompt. The prompt was "let users see their invoices", not "and never anyone else's". So the endpoint returns the invoice for whatever ID it is given, the page only asks for the logged-in user's, and in the demo nothing looks wrong. This is the most common serious finding in AI-built apps and it is invisible from the screen. See what IDOR is.
The second reason is volume. A founder who did not write the code cannot review it line by line, and the tool will not tell you which checks it skipped. The first person to read it adversarially should be someone you hired, not the first curious user.
What the test covers
| Area | What the tester tries |
|---|---|
| Authentication | Weak sign-up and reset flows, tokens that never expire, magic links that work twice, missing email verification |
| Authorization | Reading and changing other users' records by ID, calling admin routes as a normal user, tenant crossover |
| Backend rules | Supabase row level security, Firebase security rules, storage buckets, direct database access with the public key |
| Secrets | API keys and service keys in front-end bundles, source maps, environment files, public repositories |
| Input handling | Injection into queries, stored scripts in user content, file uploads that execute, unsafe redirects |
| Abuse and limits | Unlimited sign-ups, login guessing, AI endpoints that run up your bill, email and SMS sending loops |
| Payments | Changing the price in the request, reusing a checkout, trusting a client-side "paid" flag, webhook spoofing |
| AI features, if any | Prompt injection, system prompt leakage, data from other users in answers, tool calls the model should not make |
How an engagement runs
- A 30 minute scoping call. What the app does, who uses it, what data it holds, what it is built on, and who is asking for the test.
- A written scope and a fixed price. Roles to test, environments, any AI features, and whether a retest is included.
- Access. Test accounts for each role, the URL, and code access if the engagement includes a review of the source. See what to give the testers.
- Testing, usually two to five working days for a small app.
- The report: findings ranked by what an attacker could do, reproduction steps, and a fix for each.
- You fix, then a retest confirms the fixes closed the holes. Ask whether it is included; see retests.
A scanner is not this
An automated scanner checks headers, TLS settings and known library versions. It does not log in as two customers and try to swap their data, because it does not know what your app is supposed to allow. Scanners are worth running in your build. They do not answer the question a customer or an investor is asking. More on whether a scanner is enough.
What it costs
| Scope | Tester days | Typical range |
|---|---|---|
| Small app, one or two roles, no AI features, review and QA | 1 to 3 | $2,000 to $6,000 |
| Small app plus a penetration test of the running product | 3 to 5 | $5,000 to $12,000 |
| Multi-tenant app with payments and an AI feature | 5 to 10 | $10,000 to $25,000 |
Qualified testers in Canada cost roughly $1,500 to $2,800 CAD a day. The range comes from how many roles, endpoints and integrations there are, not from how the code was written. Full detail on testing costs in Canada, or price your own with the estimator.
What you get at the end
- Every finding with a severity, the steps to reproduce it and the fix.
- Findings ranked by what an attacker could actually do, not by a scanner score alone.
- Fixes written so you can paste them into your AI tool or hand them to a developer.
- If scoped for it, a report or a summary letter you can show a customer, an investor or an auditor. See using the report for SOC 2.
How to read what comes back is on reading a security test report.
Where TrazTech fits
TrazTech sells this as vibe-coding QA and security review, listed from $2,000 CAD, with QA, security review, fuzzing and a penetration test of the running app. Get at least one other quote on the same scope. The questions to ask a testing firm apply to everyone.
Testing by city
Testing is remote, so price does not change by city. Privacy law and local buyers do. Guides for founders in Toronto, Montreal, Vancouver, Calgary, Ottawa, Edmonton, Quebec City, Winnipeg, Hamilton, Kitchener-Waterloo, London, Halifax, Victoria, Windsor, Oshawa, Saskatoon, Regina, St. John's, Barrie and Kelowna.
Get a scope and a price
Tell us what you built and what it holds. You get a written scope back before anyone asks you to commit.
Get matchedCommon questions
Do the testers need my source code?
Not for a test of the running app, but it helps. With the code, a tester finds missing checks faster and can point to the exact line. Without it, the test is black box and takes longer for the same coverage.
Will testing break my app?
Testing against a staging copy avoids the risk. If you only have production, agree test accounts, rate limits and a contact in writing, and testers avoid destructive actions on real data.
What if the test finds something serious?
That is the point of it. Serious findings are reported the same day rather than held for the report, so you can fix them before anyone else finds them.
Is one test enough?
One test before launch is the minimum. Test again after a big change to login, roles, payments or an AI feature. See how often to retest.