Sooner or later someone with leverage asks how your app was built. An investor doing technical diligence. An enterprise customer’s security questionnaire. A co-founder or CTO you’re trying to recruit. An acquirer. “We vibe-coded it” is a fine answer to the how — what they’re really asking is a dozen specific questions about the state, and those questions have right answers you can prepare. Here they are, with what a good answer sounds like.
The reframe
Nobody serious penalises you for using AI to build fast. They penalise not knowing what you have. Every question below is answerable with a short, honest, specific sentence — and the preparation is exactly the 12-point audit. Do it before the conversation, not during.
Twelve questions, and what “good” sounds like
1
“Who owns the code, and where does it live?”
2
“Can someone else deploy it from scratch?”
Good: “Yes — README, env var list, CI deploys on merge, staging and production separated.” This is the bus-factor question in disguise.
3
“What’s your test coverage?”
Good: “End-to-end tests on the five core flows, run in CI on every PR, plus unit tests on billing and permissions.” Not a percentage — a description.
How to get there in a day.
4
“How do you know user A can’t see user B’s data?”
Good: “Row-level security on every table, owner-keyed policies, and an automated two-user test.” This is the question enterprise security teams lead with.
Supabase /
Firebase versions.
5
“Where are your secrets, and have any ever been exposed?”
Good: “Server-side env vars per environment, secret scanning on the repo, and yes — one key leaked in month two, rotated within the hour, here’s the log.” Honesty about a handled incident reads better than a claim of perfection.
The rotation order.
6
“What happens if the database is deleted at 3 a.m.?”
7
“How would you know if it went down or got breached?”
Good: “Error tracking and uptime alerts to a phone; auth and API logs retained 90 days.” Bad: “Customers would email us.”
8
“What third-party services do you depend on, and what does each one see?”
Good: a one-page list — hosting, database, auth, payments, email, AI provider, analytics — with the data each receives. The AI-provider line gets extra scrutiny: what user content goes to it, and is it trained on?
AI features, done properly.
9
“Is the data model going to survive the roadmap?”
A technical diligence classic.
Good: “Single-tenant today, multi-tenant on the roadmap; we’ve scoped the membership model and it’s a two-week migration.”
The seven smells they’ll look for.
10
“How much of this is AI-generated, and who reviewed it?”
Good: “Most of it, and a senior engineer has reviewed the auth, billing and data layers; here’s the findings list and what we fixed.” The honest answer plus the review beats a vague “we use AI as a tool.”
11
“What licences are in your dependencies, and did any AI-generated code copy something it shouldn’t?”
Good: “Dependency audit run, licences listed, nothing copyleft in the product; no verbatim third-party code in generated files that we know of.” Run the audit; keep the output.
12
“Who’s on call, and what’s the plan if you’re unavailable?”
Good: a name and a fallback — a studio on retainer, a technical co-founder, a documented runbook.
The hybrid model most solo founders end up with.
How to prepare in a week
Run the 12-point audit (or have it run), fix the red items, and write the answers above into a two-page document with links to evidence: the repo, the CI run, the restore log, the policy list, the dependency audit. That document is your technical diligence pack, your security-questionnaire answer bank, and your CTO-recruitment brief in one. It takes a week the first time and an hour to update after that.
If the honest answers to more than a few of these are “we don’t know,” that’s not a reason to avoid the conversation — it’s the hardening tier, which is a few weeks, and most of it is exactly the work that turns a prototype into a product anyway.
FAQ
Will investors reject a vibe-coded app?
Not for being AI-built. They’ll discount for unknowns — unowned code, no tests, no security story, a data model that can’t scale. All of which are fixable in weeks, and all of which they’ll ask about.
A customer sent a 200-question security questionnaire. What now?
Most of it maps to questions 4–8 above. Answer honestly, mark what’s in progress with a date, and don’t claim controls you don’t have — questionnaires get re-checked at renewal.
Should I get a SOC 2 or ISO 27001?
Only when a customer’s contract requires it. Before that, the twelve answers above are what a reasonable buyer actually wants, at a fraction of the cost.
Can Syntaxa do the diligence pack?
Yes — it’s the audit plus the write-up, and it’s a fixed-scope engagement. It’s also useful before you need it: founders who’ve done it once tend to build differently afterwards.
Diligence or a security questionnaire coming up?
We run the audit, fix the red items and write the two-page evidence pack — the same document that answers investors, enterprise buyers and the CTO you’re trying to hire.
Prepare the Diligence Pack →