Modernization and software Guide

Vibe-Coded Apps in 2026: When an AI-Built App Can Run Your Business

AI app builders can turn a description into a working app in an afternoon, and some of those apps now run real businesses. The audits, benchmarks and the builders' own terms show where that is safe and where it is not. This guide sets out what the tools generate and charge, what keeps going wrong, and the engineering a prototype needs before customers, money or personal data go in.

For founders, business owners and product leaders who have built an app with an AI app builder, or are deciding whether one can carry a real business process.

Published
Reviewed
Reading time
17 min

The short answer

An app built with Lovable, Bolt, Replit, v0 or Base44 can run as generated when it is a prototype, a demo or a small internal tool with no sensitive data. Once it has logins, customer records, payments or outside users, it needs engineering first: access rules enforced on the server, separate development and production data, tested backups, and code and data the business controls.

Key takeaways

  • The UK's National Cyber Security Centre says full vibe coding "can often be perfectly fine" for low-risk internal tools, and points login logic, sensitive data, secrets and anything where a flaw would be serious toward human-written and reviewed code.1
  • One researcher's scan of 1,645 Lovable apps found 170 (about 10.3%) with database access rules weak enough to expose data, and the CVE that followed lists no fixed version.23
  • An academic audit of 200 deployed apps built with Claude Code and Lovable found 91% with at least one vulnerability, and 65.77% of the 1,186 flaws rated critical or high.4
  • On a benchmark that deploys generated apps and tests them in a browser, the best model completed 61.8% of workflows; when agents must keep extending their own code, no agent finished any problem end to end.56
  • Every major builder bills AI work by credits, tokens or effort, so the agent's own bug fixing is metered; one Replit user went from $180 to $200 a month to $1,000 in a week after Agent 3 launched.789
  • The builders' terms assign the customer whatever rights exist in the output, and US law gives no copyright to the mere provision of prompts.101112

Vibe coding means describing an app to an AI in plain language and accepting what it builds without reading the code. Andrej Karpathy named it on February 2, 2025, as a way of working where you "forget that the code even exists", and called it "not too bad for throwaway weekend projects".13 AI app builders such as Lovable, Bolt, Replit, v0 and Base44 turned that into a product: a chat on one side, a running app with a database and logins on the other. Simon Willison's test is the useful one for a business. If a person reviewed the AI's code, tested it thoroughly and can explain how it works, "that's not vibe coding, it's software development".14 The question this guide answers is which apps can stay on the first side of that line and what it takes to move the rest across.

  • 10.3%of 1,645 Lovable apps scanned in 2025 had database access rules weak enough to expose data2
  • 61.8%of workflows the best model completed when its generated apps were deployed and tested in a browser5
  • 17.2%the best checkpoint score when agents had to keep extending their own code; none finished a problem6

Where an AI-built app is enough

The clearest official guidance comes from the UK's National Cyber Security Centre, which in June 2026 described a "vibe coding spectrum" on the principle that different code deserves different levels of oversight. For a proof of concept or an internal tool with limited risk, it says, "full vibe coding in these contexts can often be perfectly fine". For authentication on a public site, code that processes sensitive customer data, anything handling secret tokens or credentials, and anything where "the consequences of a security flaw would be significant", it tells teams to slide toward manual coding with AI assistance.1

The builders' own contracts draw a similar line. Replit's shared-responsibility model gives the customer the job of "verifying correctness, security, and licensing of Agent output".15 Lovable's terms forbid using AI output "without appropriate review in high-risk or sensitive contexts (including medical, legal, financial, or safety-critical uses)".16 The marketing says build and run a business; the terms say the review is yours.

People who build software for a living use these tools more carefully than the demos suggest. In Retool's survey of 817 of its customers and builders, 51% had built production software their teams use and 35% had replaced at least one SaaS tool, mostly workflow automations and internal admin tools. Among those who had shipped, 72% used AI for discrete pieces of code inside larger projects, only 8% used AI code without changes, and 41% named security and compliance as a top blocker.17 In Stack Overflow's 2025 survey, 72% of developers said vibe coding is not part of their professional work.18 Its 2026 survey found developers use AI mostly to generate code in familiar areas (67%) and to debug (61%), and only 20% use it to deploy, operate or troubleshoot production systems.19

The fear that companies would replace their software vendors with AI-built apps moved markets this year. The S&P 500 software and services index lost more than 26% from late January to its April low in what traders called the "SaaSpocalypse", then by October 6 stood at its highest level since November 2025, with one strategist calling AI "more of an enabler" for these companies.20 The best-known replacement story is thinner than its retelling: Klarna's chief executive said "we did not replace SaaS with an LLM", and described an internal stack built on a graph database and other tools.21

What the app doesCan it run as generated?What it needs first
Clickable prototype, investor demo, landing page without loginsYesNothing beyond a domain you own
Internal tool for a small team, no personal or payment dataYes, with careA named owner, a backup and a way to export it
Customer-facing app with accounts, user records or rolesNot yetAccess rules reviewed and enforced on the server, tested with real accounts2
Payments, health, financial or children's data, or regulated workNoFull review, testing, separate environments and compliance work116
A core system the business will extend for yearsUse it as the specificationA codebase, database and login system the business controls6
Our synthesis of the NCSC guidance, the builders' terms and the audits below.

What the builders generate and how they charge

The code these tools write is ordinary modern web code. What ties an app to the builder is the hosted backend around it. Lovable's built-in backend is a managed Supabase Postgres database with authentication and storage, and its documentation warns that "moving the PostgreSQL database alone does not move authentication, storage, realtime, or Edge Functions".22 Bolt Cloud runs its backends on Supabase.23 v0 deploys to Vercel.24 Google moved its app building into AI Studio, which sets up Firestore and Firebase Authentication, and is sunsetting Firebase Studio, which stays accessible until March 22, 2027.25

BuilderEntry paid plansHow AI work is metered
Lovable$25 a month for 100 credits, $50 for 20026Credits per message by complexity; adding authentication used 1.20 credits in Lovable's own example7
BoltPro $25 a month, Teams $30 per member27Tokens; each automatic fix attempt uses tokens8
ReplitCore $20 a month, Pro $10028Effort-based: from about $0.06 to several dollars a request29
v0 (Vercel)Plus $30 per user a month, Business $10024Monthly credits included per user, then usage
Base44$16 to $160 a month, billed annually30Message credits per month
US list prices read on October 7, 2026. Hosting, databases and AI used inside the app are billed on top.

The seat price is rarely the bill. Bolt's own help pages tell users to "avoid clicking Attempt fix over and over", because each attempt uses tokens.8 Replit replaced a flat $0.25 per checkpoint with effort-based pricing in 2025, once its agent began running for up to 20 minutes at a time.29 After Agent 3 launched in September 2025, one user told The Register: "In the last week alone it charged me $1K since the new agent dropped whereas before it was never more than $180-200 a month for the same effort."9 Lovable says its current chat pricing applies through October 31, 2026, and that its monthly Cloud and AI grants are "a temporary offering and subject to change".7

The vendors are now large companies. Lovable reached $500 million in annualized revenue in June 2026, says it hosts 60 million projects, and raised $400 million at a $13.3 billion valuation in August.31 Wix reported about $150 million of annual recurring revenue for Base44 as of May 2026.32 Use is less steady than revenue: Barclays analysts put Lovable's traffic down 40% from its peak by September 2025,33 and Bolt's chief executive said consumer users churned too fast to build around, with enterprise customers about 25% of revenue.34 Size lowers the risk that a platform disappears. It does not change who is responsible for the app.

What the security audits found

Apps on Supabase-backed builders talk to their database straight from the browser using a public key. That is safe only when row level security rules in the database decide which rows each user may read or change. Every large audit finds those rules missing or wrong. Matt Palmer's 2025 scan found 303 vulnerable endpoints across 170 of 1,645 Lovable projects, about 10.3%, with inadequate rules.2 The CVE he filed, CVE-2025-48757, lists all versions as vulnerable and no fixed version, because the flaw sits in each generated app.3

Later studies count differently and agree on the pattern. Escape analyzed more than 5,600 publicly available vibe-coded apps and found more than 2,000 vulnerabilities, over 400 exposed secrets and 175 exposures of personal data, including medical records and bank account numbers.35 Symbiotic Security, which sells scanning, scanned 1,072 such apps and found 431 critical issues and 172 sites where anyone could delete records without logging in.36 An academic audit of 200 deployed apps built with Claude Code and Lovable found 91% with at least one vulnerability and 65.77% of the 1,186 flaws rated critical or high, concentrated in broken access control, injection and authentication.4 In September 2026 UpGuard told TechCrunch it had found about 16,000 databases hosted on Supabase exposing personal data. It did not show those apps were AI-built, and Supabase answered that its projects are "secure by default" and that security is shared with customers.37

IncidentWhat happenedThe control that was missing
Replit and SaaStr, July 2025The agent deleted a production database during a code freeze, generated a 4,000-record database of fictional people, and wrongly said rollback was impossible3839Separate development and production data, and an agent without write access to live data
Moltbook, 2026A founder who said he "didn't write a single line of code" shipped a database exposing 1.5 million API keys and 35,000 emails; fixed within hours40Access rules on every table, and no keys in the browser
Base44, July 2025A non-secret app ID let anyone register on private enterprise apps and bypass single sign-on; fixed in under 24 hours with no evidence of abuse41Platform login checks, which a customer cannot see or fix
Lovable, February to April 2026Chat history and source code of public projects could be read by other logged-in users; Lovable first said it "did not suffer a data breach", then apologized4243Treating anything stored on a builder as potentially public

Newer models have not closed the gap. Veracode's spring 2026 update, covering more than 150 models, found code that compiles more than 95% of the time and a security pass rate stuck at about 55%, with Java at 29%.44 On BaxBench, even the best model wrote correct backends 62% of the time, and about half of the correct programs could be exploited.45 On SusVibes, an agent built on Claude 4 Sonnet produced functionally correct solutions to 57% of real feature requests and secure ones to 11.8%.46 Models also invent software packages: 19.7% of 2.23 million suggested packages did not exist, and 43% of those invented names came back on every repeat of the prompt, which lets an attacker publish a malicious package under the name.47

The builders have added scanners. Lovable runs a basic scan of database configuration and access rules each time an app is published, and enterprise admins can schedule recurring deep scans.48 Replit says its publishing checks "complement, rather than replace" a full security scan.49 No scanner knows the business rules, such as which customer may see which invoice, so the rules still need a person who knows the business to write them down and test them.

Why the second feature is harder than the first

Building a first version is the part these tools do best. Vibe Code Bench, from Vals AI and MIT, gives models 100 app specifications, deploys what they build and tests the result with a browser agent. The best model, GPT-5.3-Codex, completed 61.8% of workflows and Claude Opus 4.6 57.6%. Of the failures, 46.7% were missing features, 20.4% were sign-up or login that did not work, and 14.8% were access policies blocking the user.5

Businesses live on the second, tenth and fiftieth change, and that is where agents struggle. On FeatureBench, Claude 4.5 Opus resolved 74.4% of SWE-bench tasks and only 11.0% of feature-development tasks.50 SlopCodeBench makes agents keep extending their own code as the specification changes; across 11 models no agent solved any problem end to end, the best checkpoint score was 17.2%, and structural erosion rose in 80% of runs. Prompting for clean code gave a cleaner start, and the decline then resumed at the same rate.6 A study of projects that adopted Cursor found a 281% rise in lines added in the first month that faded within two months, while static-analysis warnings rose 30% and code complexity 41%.51 CodeRabbit, which sells code review, counted 10.83 issues per AI-authored pull request against 6.45 for human-only ones, with security issues up to 2.74 times higher.52

The famous success statistic comes with a qualifier. Y Combinator said a quarter of its Winter 2025 batch had 95% of their code written by AI, and its managing partner added: "Every one of these people is highly technical, completely capable of building their own products from scratch."53 The founders getting good results from AI-written code are the ones who can read it.

What a demo never tests

Several properties of a production system are invisible when the owner tries the app. Access rules look right because the owner can see everything. One environment looks fine until an agent changes live data, which is how the SaaStr database was lost; Replit's answer was to separate development and production databases.39 Usage-billed hosting costs nothing at ten users. The artists' network Cara, which was not AI-built, received a $96,280 Vercel bill for one week after growing from 40,000 to 650,000 users.54 No benchmark found in our research measures how generated apps handle load, backups or monitoring, which means nobody is grading those properties for you.

Outside rules apply to the app whoever wrote it. Card payment pages fall under PCI DSS v4.0.1, whose payment-page script requirements 6.4.3 and 11.6.1 now reach merchants through a new eligibility check, and the PCI Council says the change does "not remove or diminish the underlying requirements".55 Apple's guideline 5.1.2(i) requires an app to disclose and get permission before sharing personal data with third-party AI,56 and in March 2026 Apple blocked App Store updates for the Replit and Vibecode apps, citing guideline 2.5.2 on code that changes an app after review.57

A trade has formed around these gaps. 404 Media reported in September 2025 that "vibe coding cleanup specialist", a LinkedIn joke, had become a growing profession, with freelancers and whole firms fixing apps built by non-engineers.58 We found no independent study of how many AI-built prototypes are kept, hardened or rebuilt, or what that costs. The cost depends on how much of the data model and access logic must be redone, whether the app has to leave the builder's backend, and how many tests must be written from nothing.

Who owns the app, the data and the exit

Each builder tells customers they own what they build, and each qualifies it. Lovable says "as between us, you own your Customer Data, including the applications".16 StackBlitz, which runs Bolt, assigns its rights in AI output "if any" and notes that the service "may generate the same or similar output for other users".10 Base44 grants ownership "to the extent such rights exist under applicable law".11 The qualifiers matter because the US Copyright Office says copyright can cover human creative arrangements or modifications of AI output, "but not the mere provision of prompts",12 and the Supreme Court declined on March 2, 2026 to hear the case on AI authorship.59 An app built from prompts alone may have little protection; the human design and changes recorded in a repository are what a business can defend.

The licenses also run toward the vendor. Lovable takes "a worldwide, perpetual, royalty-free license" to use customer data for its business purposes.16 Base44 takes an "irrevocable, non-exclusive, worldwide, royalty-free, perpetual" license over customer data.11 Vercel may train its models on content from Hobby and trial Pro accounts.60 Where an app collects personal data, the business is the controller under GDPR and "shall use only processors providing sufficient guarantees" under a written contract.61 Lovable's terms say it does not guarantee processing "in any particular country or region", and a Lovable Cloud project's region "is locked and cannot be changed" once chosen.1662 India's DPDP Rules, notified on November 14, 2025 with an eighteen-month phase-in, put penalties of up to ₹250 crore on a Data Fiduciary that fails to keep reasonable security safeguards, whoever wrote the code.63

Platforms change. Replit "reserves the right to modify, deprecate, or remove features of the Service at any time and for any reason", without refunds.64 Vercel may remove content "for no reason at all", with extra protections for European users.60 Firebase Studio will have run for less than two years when it closes.25 Four questions settle the exit: can the code, the database and the login system all be exported; does the app run somewhere else; is it on a domain the business owns; and can the monthly bill be predicted. An app that fails them is a good prototype and a weak foundation.

How to take a prototype to production

  1. Place the app on the spectrum List what it touches: logins, personal data, payments, secrets, outside users. If none, keep it on the builder with an owner and a backup. If any, plan the work below.1
  2. Move the code where you control it Sync it to a repository the business owns, record the human design decisions, and confirm the database and login system can be exported too.22
  3. Rewrite access rules on the server Write down who may read and change each kind of record, enforce it in the database or API, and test it with two ordinary accounts trying to read each other's data.2
  4. Separate environments and test a restore Give development and production their own data, keep the agent away from live data, and restore a backup once before launch.39
  5. Take secrets out of the browser Move API keys and paid-service calls to server functions, and check every package the AI added actually exists and is the one intended.4047
  6. Test the flows the business depends on Write automated tests for sign-up, login, payment and the core records before adding features, so each change shows what it broke.5
  7. Watch errors and cost Add error tracking, uptime checks and spending alerts on hosting and AI usage before marketing brings traffic.54
  8. Sign the paperwork Put a data processing agreement in place, choose the data region deliberately, and check the plan's training default before any customer data goes in.6162

Before customers, money or personal data go in

  • Has someone who can read code reviewed the access rules for every table and endpoint?
  • Can one ordinary user read or change another user's records?
  • Are any keys, tokens or paid-service calls visible in the browser?
  • Are development and production data separate, and has a restore been tested?
  • Do automated tests cover sign-up, login, payment and the core records?
  • Will someone be alerted when errors spike or the hosting bill jumps?
  • Can the code, database and login system leave the builder, and is the app on your own domain?
  • Is a data processing agreement signed, and where is the data stored?

AI app builders have changed what a prototype is worth. A working app that a founder or product manager built in a week is a better specification than most requirement documents, and it settles arguments about what to build before money is spent. The same evidence shows where it stops: the agent does not decide who may see which record, keep live data away from its own mistakes, or keep a growing codebase coherent. Those decisions belong to whoever answers for the app when something goes wrong.

This is how we approach AI-built apps in our custom software development work: start from the working prototype as the specification, move it into a repository and backend the client owns, rewrite access rules and secrets handling on the server, separate environments, and put tests, monitoring and cost alerts in place before real users arrive.

Questions leaders ask

Can I run my business on an app built with Lovable, Bolt or Replit?

For a prototype, a demo or a small internal tool without sensitive data, yes. Once the app has customer accounts, personal data, payments or outside users, it needs access rules enforced on the server, separate development and production data, tested backups and a review by someone who can read the code. The UK NCSC draws the same line.

Are vibe-coded apps secure?

Often not as generated. One scan found about 10% of 1,645 Lovable apps exposing data through weak database rules, and an academic audit found 91% of 200 deployed apps with at least one vulnerability. The most common fault is access control: rules that should stop one user reading another user's records are missing or wrong.

What is row level security and why does it matter for AI-built apps?

Row level security is a database feature that decides which rows each user may read or change. Builders that use Supabase let the app talk to the database from the browser with a public key, so these rules are the only thing protecting the data. When they are missing or too broad, anyone can read or alter records.

Do I own the code an AI app builder generates?

The terms assign you whatever rights exist, with qualifiers such as "if any" and "to the extent such rights exist". The US Copyright Office says prompts alone do not create copyright, while human creative changes to the output can be protected. Keep the code in your own repository and record the human design work.

How much does an AI app builder cost?

Entry paid plans run from about $16 to $100 a month, read on October 7, 2026. AI work is metered by credits, tokens or effort, and hosting, databases and AI used inside the app are billed separately. Bills grow with how much the agent works, including the attempts it spends fixing its own errors.

Should I rebuild a vibe-coded app or harden it?

It depends on how much of the data model and access logic is sound, whether the app must leave the builder's backend, and how far it will grow. Benchmarks show agents struggle to keep extending their own code, so a core system the business will extend for years usually earns a codebase it controls.

Can I export my app from the builder?

The front-end code usually syncs to GitHub. The backend is harder: Lovable's documentation says moving the PostgreSQL database alone does not move authentication, storage, realtime or edge functions. Check that the code, the database and the login system can all leave before the app becomes critical.

Sources

  1. The vibe coding spectrum: an approach to AI-assisted software developmentUK National Cyber Security Centre, June 2026
  2. Statement on CVE-2025-48757Matt Palmer, May 2025
  3. CVE-2025-48757Matt Palmer, May 2025
  4. Understanding the (in)security of vibe-coded applicationsarXiv 2606.23130, 2026
  5. Vibe Code BenchVals AI and MIT, arXiv 2603.04601, 2026
  6. SlopCodeBencharXiv 2603.24755, 2026
  7. Plans and creditsLovable Docs
  8. Maximizing token efficiencyBolt Support
  9. Replit's Agent 3 pricingThe Register, September 18, 2025
  10. Terms of ServiceStackBlitz (Bolt)
  11. Terms of ServiceBase44
  12. Copyright Office releases Part 2 of its report on copyright and artificial intelligenceUS Copyright Office, January 29, 2025
  13. There's a new kind of coding I call "vibe coding"Andrej Karpathy on X, February 2, 2025
  14. Not all AI-assisted programming is vibe coding (but vibe coding rocks)Simon Willison, March 19, 2025
  15. Shared responsibility modelReplit Docs
  16. Terms of ServiceLovable, updated August 28, 2026
  17. The 2026 build vs. buy shiftRetool, February 2026
  18. 2025 Developer Survey: AIStack Overflow, 2025
  19. The results of the 2026 Developer Survey are hereStack Overflow, October 6, 2026
  20. US software stocks scale fresh highsReuters, October 6, 2026
  21. Klarna CEO doubts that other companies will replace Salesforce with AITechCrunch, March 4, 2025
  22. Deployment, hosting and ownershipLovable Docs
  23. Bolt Cloud launchSupabase
  24. v0 pricingVercel
  25. Announcing the AI Studio integrationFirebase Blog, March 19, 2026
  26. Subscription plansLovable Docs
  27. Bolt pricingBolt
  28. Replit pricingReplit
  29. Effort-based pricing recapReplit, 2025
  30. Base44 pricingBase44
  31. Lovable confirms new $13.3B valuation, raises another $400MTechCrunch, August 12, 2026
  32. Wix reports first quarter 2026 resultsWix, May 2026
  33. Lovable says it's nearing 8 million usersTechCrunch, November 10, 2025
  34. Eric Simons, CEO of Bolt, on B2B vibe codingSacra, February 17, 2026
  35. Methodology: how we discovered vulnerabilities in apps built with vibe codingEscape, October 29, 2025
  36. We scanned 1,072 vibe-coded appsSymbiotic Security, 2026
  37. Some Supabase customers are publicly exposing reams of people's data to the webTechCrunch, September 25, 2026
  38. Vibe coding service Replit deleted production databaseThe Register, July 21, 2025
  39. Vibe coding service Replit deletes production databaseheise online, July 2025
  40. Exposed Moltbook database reveals millions of API keysWiz, 2026
  41. Critical vulnerability in Base44Wiz, July 2025
  42. Our response to the April 2026 incidentLovable, April 2026
  43. Lovable denies data leak, cites intentional behaviorThe Register, April 21, 2026
  44. Spring 2026 GenAI code security updateVeracode, March 24, 2026
  45. BaxBench: can LLMs generate correct and secure backends?Vero et al., arXiv 2502.11844, 2025
  46. Is vibe coding safe? Benchmarking vulnerability of agent-generated code in real-world tasksarXiv 2512.03262, ICML 2026
  47. We have a package for you! A comprehensive analysis of package hallucinations by code generating LLMsSpracklen et al., USENIX Security 2025
  48. SecurityLovable
  49. Security scannerReplit Docs
  50. FeatureBench: benchmarking agentic coding for complex feature developmentarXiv 2602.10975, 2026
  51. Does AI-assisted coding deliver? A difference-in-differences study of Cursor's impactarXiv 2511.04427, 2025
  52. State of AI vs. human code generation reportCodeRabbit, December 2025
  53. A quarter of startups in YC's current cohort have codebases that are almost entirely AI-generatedTechCrunch, March 6, 2025
  54. A social app for creatives, Cara, grew from 40k to 650k users in a weekTechCrunch, June 6, 2024
  55. Important updates announced for merchants validating to Self-Assessment Questionnaire APCI Security Standards Council, January 30, 2025
  56. Apple's new App Review Guidelines clamp down on apps sharing personal data with third-party AITechCrunch, November 13, 2025
  57. Apple blocks updates for vibe coding appsMacRumors, March 18, 2026
  58. The software engineers paid to fix vibe coded messes404 Media, September 2025
  59. The final word: Supreme Court refuses to hear case on AI authorshipHolland & Knight, March 2026
  60. Terms of ServiceVercel
  61. Article 28 GDPR: processorRegulation (EU) 2016/679
  62. Lovable CloudLovable Docs
  63. Digital Personal Data Protection Rules, 2025: explainerPress Information Bureau, Government of India, November 2025
  64. Terms of ServiceReplit

Written by DigyAi Engineering from the systems we build and run. Every figure links to its public source, and every link and figure was checked on October 7, 2026. No client data appears in our insights.

Read next

All insights
  • On one plinth, a coding agent works inside a glass sandbox and sends pull request after pull request to a tray that keeps filling; every change runs along lit conduits into a glowing review and CI gate under a shield, which stops one with a red mark and passes the next, and a lit production tower rises under a beam of light.

    Modernization and software Guide

    AI Coding Agents in the Enterprise: What They Speed Up, What They Break and How to Govern Them

    For CTOs and VPs of engineering rolling out Claude Code, Copilot, Codex, Cursor or similar agents across their teams, deciding how far to trust them, what to measure and which controls to require.

    16 min read

  • A stepped cream ERP core stands at the centre of a lit plinth inside a ring, with a vendor upgrade landed on its roof. Your own extension towers and an AI agent stand beside it, each connected through a port on the ring, and each shows a green tick after the upgrade.

    Modernization and software Guide

    Custom ERP vs Off-the-Shelf: When to Build, Buy or Extend

    For CIOs, CTOs and CFOs deciding what to do with an SAP, Oracle or Microsoft Dynamics estate before a migration, upgrade or renewal commits the budget.

    16 min read

  • On one plinth, a small glass prototype sits on a workbench at the front and drums of live data wait behind it; both run along lit conduits into a glowing go-live gate under a shield, and once it passes them a lit production tower rises at full height under a beam of light.

    Economics and buying Playbook

    AI Pilot to Production: How to Rescue, Restart, Buy or Stop a Stalled Pilot

    For CTOs, CIOs and heads of AI with a pilot that worked in the demo and has not been signed off to run for real, deciding whether to rescue it, rebuild it, buy instead or stop.

    22 min read

Get in touch

Tell us what you are building.

Write it as big as you imagine it.