Charles BurtAI Code Audit & Rescue
Available now · London-based · Remote-first · Global

AI code audit & vibe-code rescue, from AI prototype to production.

Building it yourself was the right call. I ship production software with AI every week, under my own architecture. I’m not here to tell you AI was a mistake.

Send me the app → See the verdicts

When an AI-built app needs a software rescue.

People arrive here in one of four situations. All four start the same way: a fixed-fee triage of your code. Under each one, where I’ve done the work before.

You built it yourself with AI and it’s breaking under use.

The demo was fine. Under users it slows, errors appear, and each AI fix changes things you stopped checking. You’ve been stuck on the same bug for days.

Ships production software with Claude Code under my own architecture · AI-assisted delivery subscription product launching 2026

You paid someone who built it with AI, and nobody can maintain it.

It runs, mostly. There are no tests, no documentation, and functions hundreds of lines long. Every new feature costs several times what it should.

3-year AI-assisted power user · reviewed countless lines of AI and human code · assessed the ~30-person dev partner behind the McDonald’s Happy Meal app · ~£2m in annual savings found (R/GA)

It works, but you can’t tell if it’s secure.

The code looks convincing when you read it. What you can’t see is the exposed key, the open access rule, the database anyone can query. One founder found his payment keys hard-coded into the frontend.

Technical due diligence on multi-million-pound operations · architecture, scalability, risk, cost

A developer told you it can only be rebuilt.

Sometimes that’s true. But rebuilding is the default advice, and it writes off everything you’ve already spent. Before you pay it, get a verdict argued from your own code, in writing.

Cut development cost 40% on a JP Morgan / Contex-City engagement through architecture and process redesign

What the AI code audit covers.

A fixed-fee assessment of your entire codebase. You’ll get a clear picture of what’s been built, the state it’s in today, and what each realistic path forward will cost. Whether you built it yourself with AI or paid someone else to do it, you’ll get the same unbiased assessment.

Architecture. I map the system, explain how everything fits together, and document it so any experienced engineer can quickly understand it.
Security posture. Exposed secrets, overly permissive access rules, weak permissions, and anything an attacker could realistically reach.
Maintainability. Code structure, tests, documentation and overall quality — how easy it is for another developer to work on safely.
Behaviour under load. Testing beyond the happy path to identify what happens when real users start using the system.
Data & integrations. Database, third-party services, APIs, authentication, payments, and integrations such as Supabase — implemented correctly.
Clear next steps. Every finding ends with a practical recommendation and separate estimates for keeping, refactoring, or rebuilding — a decision made on evidence rather than guesswork.

I also offer this as: a codebase audit · a code audit service · a software rescue · vibe coding rescue · vibe code cleanup.

Keep, refactor or rebuild.

Every audit ends with one of three recommendations. Each verdict is backed by evidence from your code and includes a clear breakdown of the work and cost involved.

Verdict 01

Keep

A solid foundation · targeted fixes

  • Keep the parts that are structurally sound, with clear justification.
  • Prioritised list of issues, costed and ordered by impact.
  • In many rescue projects, the frontend is already in good shape and can stay.
Verdict 02

Refactor

The product works · the internals don’t

  • Preserve the existing behaviour while replacing the fragile internals.
  • Move secrets out of the code, tighten database permissions, and separate staging from production.
  • Deliver the work in phases, with testing and review at every stage.
Verdict 03

Rebuild

When the foundation isn’t worth saving

  • Recommended only when the evidence shows rebuilding is the most practical and cost-effective option.
  • Everything worth keeping is identified first — product decisions, validated features, and often the frontend.
  • A new architecture built for long-term stability, with AI accelerating delivery under my technical direction and review.
“Developers keep telling me AI code can’t be fixed, only rebuilt. Won’t you say the same?”

No. Rebuilding is only recommended when the code genuinely leaves no sensible alternative. Many projects land in the middle: keep what’s structurally sound — often the frontend — and rebuild what’s holding the product back, typically the backend, infrastructure and security.

A code review service, so you can keep vibe coding.

AI lets you build faster than ever. The problem isn’t using AI — it’s shipping code that hasn’t had a senior engineering review.

Any refactor or rebuild I do ships with a regression test suite, handed over and yours. After that, an AI change that silently breaks something gets caught before your users find it.

AI-generated code review, before it ships

Keep building with Lovable, Cursor, Claude Code, or whatever tools fit your workflow. I review each milestone before release, catching issues while they are still cheap to fix. Senior engineering reviews are commonly priced around $500 per milestone (a reported market figure); I quote based on the scope and complexity of your project. When you need more than reviews, that becomes fractional CTO support.

What does an AI code audit cost?

What the market publishes:

Rapid AI-code audit (market)
From £495

Market price for a 48-hour diagnostic review of an AI-generated app.

Senior milestone review (market)
Around $500 per review

A senior engineer’s read of one milestone before it ships. Reported on developer forums, 2025; US figure.

Hardening & refactor (UK market)
£800–£1,600 per day

Provider-published UK senior day rates for architecture hardening and refactoring.

The cautionary pair
$18,000 build, $40,000 rebuild

One founder’s reported numbers for an AI-built MVP nobody could maintain, and its rewrite (developer forums, 2025). The triage exists to catch this before it happens.

How I price

The audit itself is a fixed-fee assessment, quoted once I’ve seen your product and codebase. If the verdict is to refactor or rebuild, that work is priced separately with clear scope, costs, and staged payments. I both audit and build, so the process stays transparent: the report belongs to you and can go to any developer or agency. Continue with me and the full audit fee credits against the implementation. You pay for clarity first; the decision on what happens next stays yours.

Who this isn’t for

This isn’t a service that tells you your app is fine just because you want reassurance. The verdict follows the code, not expectations. If you haven’t built anything yet and you’re deciding what to build, you need the venture readiness audit instead — this is for rescuing something that already exists.

Send me the app →

The receipts.

Four engagements that mirror the situations I help with: building with AI from the start, assessing AI-built software, refactoring instead of throwing everything away, and rescuing projects when delivery has gone off track.

AI-assisted delivery · Claude Code · 2023–present

I ship with the tools that built your app

A subscription productivity product taken from idea to near-launch, part-time and without funding: I direct the architecture and every product decision while Claude Code executes under my review. Alongside it, AI and data features shipped for Coca-Cola, Mars, Unilever and L’Oréal at ImpactXP.ai.

Launching 2026 · built AI-assisted under my direction
Assessing someone else’s build · R/GA · 2017

McDonald’s Happy Meal app: ~£2m in annual savings found

Trusted with the release of the global Happy Meal app across ~40 markets and 42 languages. Assessed the ~30-person external development partner behind it: performance, processes and commercials. Identified ~£2m in potential annual savings inside a three-month contract.

R/GA responded with the offer of a permanent role heading the function
Architecture & cost · JP Morgan / Contex-City

Development cost cut 40%

Through architecture and process redesign on a JP Morgan / Contex-City engagement, cut development cost by 40%.

Delivered through the consultancy I founded and staffed
Rescue under pressure · NEOM · 2021

Overdue programme, dependable delivery restored

Inherited an overdue digital-twin programme for NEOM’s giga-project. Diagnosed the issues across team, delivery practice, architecture and platform, then restored dependable execution across a distributed international team.

Strategic recommendations presented to the CEO and board

The consultancy I founded delivered for JP Morgan, HP, IBM, McDonald’s and EE. I founded Colossal Games and took Commando Jack to #1 in 36 countries with EA Games / Chillingo and won a Microsoft award (top 10 of 150+ studios). Track record, products and demo videos: the work · the validation.

From two sentences to a clear verdict.

01

Send the app

Tell me what’s breaking, where it runs, and what built it. Two sentences is enough to start. Read-only repository access is fine, and an NDA is no problem. I’ll give you a fixed-fee triage quote before any work begins.

02

Triage

I read the code, map the architecture, and check the risks: exposed keys, access rules, weak points, and what happens beyond the demo path.

03

The verdict, in writing

Keep, refactor, or rebuild — based on what the code actually shows. Each option comes with the reasoning, scope, and cost. The report is yours, whether you continue with me or take it elsewhere.

04

The fix, if you choose me

Refactor or rebuild under a clear architecture, with staged payments, a regression test suite handed over at the end, and ongoing milestone reviews if you want continued oversight.

Questions people ask.

Is it possible to get a vibe-coded app production-ready?

Often, yes. The pattern across rescues is that the frontend is usually the part worth keeping, while the backend, infrastructure, and security are where problems tend to appear. The triage gives you the answer for your app, in writing, with each option priced.

I built my app with Cursor and it’s a mess. What do I do?

Stop prompting at the bug. At a certain point, every AI fix can change something else you were relying on, and days disappear into the loop. Freeze the code, get it reviewed, and make the next decision from evidence rather than another prompt.

What’s your process for fixing a broken Lovable or Cursor build?

First, I audit the code, architecture, and security risks. Then you get a written verdict: keep, refactor, or rebuild, with the cost of each option. If you choose me for the fix, the work is done under a proper architecture with a regression test suite handed over at the end.

Do I have to rebuild from scratch?

Sometimes. When the code shows that rebuilding is the sensible option, I’ll explain why and what it will cost. It is not the default answer. Anything structurally sound gets kept, and that often includes the frontend.

What does an AI code audit cost?

Rapid AI-code audits in the market start around £495, with UK senior engineering rates for follow-on work commonly around £800–£1,600 per day. My triage is fixed-fee and quoted after I’ve seen your app. If you continue with me, the audit fee is credited against the implementation work.

Which tools and stacks do you cover?

It’s highly likely I can audit any stack, such as Lovable, Bolt, Cursor, Replit and Claude Code. The audit also covers the systems around them, including databases, APIs, authentication, payments, and services such as Supabase.

The app was built by a freelancer or an agency, not by me. Same service?

Yes. The code matters. I’ve assessed external development partners, including the ~30-person team behind the McDonald’s Happy Meal app, identifying around £2m in potential annual savings.

Can I keep vibe coding afterwards?

Yes. That is exactly where a review process helps. A regression test suite catches changes that break existing behaviour before your users do. Add milestone reviews and you keep the speed of AI tools with senior engineering oversight.

I haven’t built anything yet. Should I start with AI tools?

That is a different question: what to build, what it should cost, and how to approach delivery. That is covered by a venture readiness audit, not a rescue audit.

I’m an investor or acquirer looking at an AI-built company.

Then the right service is technical due diligence: a fixed-fee assessment with an executive summary, severity-rated findings, and a costed remediation roadmap.

Send me the app.

Two sentences on what’s breaking is enough. Read-only access and an NDA are both fine. You get someone who ships production software with AI every week, under his own architecture, and who isn’t going to tell you AI was a mistake. I read everything and reply if it’s a fit.

LinkedIn · /in/charles-burt Full profile · charlesburt.me