The $200 API Bill and Other Things Vibe Coding Won't Warn You About
About this session
AI tools have reduced the time from idea to working app, but "working" and "ready" are very different milestones. After using Lovable and Claude to build Vizibly, her event data portrait platform, Michelle discovered the unglamorous second half of shipping: a security audit that surfaced real vulnerabilities (SSRF, unsafe file uploads, exposed credentials), API calls that were quietly burning money until caching and deduplication fixed them, and privacy obligations like GDPR data deletion that AI tools will not implement by default. This talk is a practical post-build checklist for non-traditional developers: checks to run, and how to use AI itself to audit the code AI wrote. You'll leave knowing exactly what to do after your first vibe coded app functions, and before anyone else touches it.
Speaker
Key takeaways
- A prioritized post-build checklist covering security, API cost efficiency, and privacy compliance, with real examples of what each check caught in a live product
- How to use AI tools to audit AI-generated code, including prompting strategies
- The minimum viable privacy setup (data deletion, consent, third-party data handling) every app needs before real users show up
Related sessions
- From Problem to Production: What I Learned Building an AI Product That Delivered Real Commercial Value
- Building Real AI-Augmented Products as a Solo Technical Founder
- Start Small: From Simple Prompts to Building with Agentic AI
- From Product to Platform: Ecosystem Strategy and Data Privacy in the Generative AI Era