The $200 API Bill and Other Things Vibe Coding Won't Warn You About

About this session

AI tools have reduced the time from idea to working app, but "working" and "ready" are very different milestones. After using Lovable and Claude to build Vizibly, her event data portrait platform, Michelle discovered the unglamorous second half of shipping: a security audit that surfaced real vulnerabilities (SSRF, unsafe file uploads, exposed credentials), API calls that were quietly burning money until caching and deduplication fixed them, and privacy obligations like GDPR data deletion that AI tools will not implement by default. This talk is a practical post-build checklist for non-traditional developers: checks to run, and how to use AI itself to audit the code AI wrote. You'll leave knowing exactly what to do after your first vibe coded app functions, and before anyone else touches it.

Speaker

Key takeaways

  • A prioritized post-build checklist covering security, API cost efficiency, and privacy compliance, with real examples of what each check caught in a live product
  • How to use AI tools to audit AI-generated code, including prompting strategies
  • The minimum viable privacy setup (data deletion, consent, third-party data handling) every app needs before real users show up

Related sessions