Logo Global Orange Contact

From vibe coding to production

Book icon 6 min
Colourful building blocks with AI at the centre

Vibe coding has quickly become part of software development. You describe what you want to build in plain language, an AI model generates the code, and within a few hours you have a working application. That speed is a real advantage for many teams. Discussions from Reddit threads to YouTube tutorials often use an iceberg metaphor: a polished prototype above the surface, with a large amount of work underneath that never appears in a demo. We recognise that picture. Here, we explain what sits below the waterline and why it matters.

In this article

What vibe coding delivers

A proof of concept that once took a week can now be ready in an afternoon. Testing an idea, making a user flow tangible or convincing a stakeholder with something that already works: these are strengths of vibe coding, and the gains are real. We use AI daily to accelerate prototypes, generate documentation and deliver code components.

Production software needs to keep working when a user clicks the same button three times, a colleague types an unusual character into a search field or a hundred people log in at once on a Monday morning. Cyberattacks add another challenge: Check Point Research reported an average of 1,925 weekly attacks per organisation worldwide in Q1 2025. A digital product’s requirements extend to everything around the generated code: authentication, error handling, monitoring and capacity.

The same prototype often soon gets labelled an MVP. That label brings expectations: a working login flow, meaningful error messages and a way to detect problems without a developer watching. Although a prototype and an MVP can look similar, they are not the same thing.

MVP and exceptional viable product development

The invisible part of the work

The iceberg metaphor captures this well. We previously used a similar picture to explain what it takes to move from an AI prototype to a production-ready platform (article in Dutch). Below the waterline sits work that rarely appears in a pitch: authentication beyond a test account; an environment that keeps secrets out of source code; a plan for an AI provider retiring a model or changing its prices; GDPR compliance when external models access business data; audit logging; rate limiting; and architecture that serves multiple customers or departments without exposing one customer’s data to another.

These are established software engineering disciplines with known solutions. An AI model can raise them when explicitly asked. A task management application with individual logins, role-based permissions and an audit trail needs a precise prompt. That precision requires knowledge that does not usually emerge simply from prompting more often.

The same applies to database choices, error handling and how data moves across the network. An AI model often chooses a default solution that works well for a demo. Considering scalability, cost per user and behaviour under a thousand times more traffic requires a separate step, one a model does not automatically take.

The production software iceberg: architecture, security, scalability and operations beneath the prototype

Architecture is not an optional extra

Architecture determines whether something works today and whether you can extend it six months from now. Teams that start building without a plan eventually reach a point where a new feature or structural change no longer fits what exists. Rebuilding then costs considerable time and budget, including when AI is used. That is why every GlobalOrange engagement starts with a Product Discovery Workshop. Spending a few days considering scope, users and future growth can prevent having to start again months later.

This connects to a distinction we regularly make between software development and product development (article in Dutch). Vibe coding turns intent into code. Product development starts with choices about what to build and, especially, what to leave out; research into what users actually need; and a vision beyond the next demo. Working code is a product’s starting point.

“A working prototype proves that an idea is possible. It says nothing yet about how the system will hold up with a hundred users, an auditor or a rising cloud bill. You establish that through architecture and a team that knows what to look for.”

Werner Bootsman GlobalOrange
Werner Bootsman
Delivery Manager GlobalOrange

Engineering direction determines the result

Experienced developers use AI to iterate faster precisely because they know which question to ask, which solution to check and which assumption to correct before it becomes embedded in the codebase. That direction shapes the result as much as the model itself.

Two teams using the same tools can therefore achieve very different outcomes. Writing and reviewing code is only part of the work needed to bring software into production. The rest includes keeping it performant under load, setting up predictable deployments and resolving incidents before they become outages. A misconfigured workflow or an endless loop in a deployment can quickly create unexpectedly high cloud costs. Building without experienced oversight makes these risks harder to spot.

The cost of ignoring it

The risks of treating a prototype as a product too soon are rarely theoretical. An organisation may discover only after a successful demo that its security policy prohibits using an external AI model with business data. It then has to work out how a comparable solution can run locally or within its own infrastructure. A security incident that a few hours of input validation could have prevented can cost weeks of recovery and damage customer trust. A team that keeps building on an unstructured foundation finds each new feature takes longer than the last.

This is particularly familiar in regulated sectors, where compliance is a prerequisite. ComplianceWise (case in Dutch), for example, replaced consultancy with a scalable SaaS platform in a sector where security and legal accuracy matter as much as functionality. The question was always whether the platform would withstand oversight, growth and an auditor asking exactly where data comes from and who can access it.

“We increasingly meet clients who proudly show us a working prototype. We then ask how they have handled access management or GDPR. That is where the real work starts for us.”

Yvo Gortemaker, CEO of GlobalOrange
Yvo Gortemaker
CEO GlobalOrange

Our approach: speed built on a solid foundation

We use AI to accelerate part of our work. From day one, multidisciplinary teams spanning UX, product management and technology consider what you are building, who it is for and what it means for architecture, security and scalability. We use proven frameworks to avoid dependence on a single supplier or model.

This starts with clear choices about what to build and what to leave out, an approach central to the critical phase between the first idea and a working product (article in Dutch). It also means involving the right people at the right time, through an internal team or a hybrid partnership, as discussed in our article on in-house versus hybrid development teams (in Dutch). Whether used for vibe coding or as a product feature, AI never carries final responsibility. This also connects to the future of SaaS (article in Dutch) and the shift in where value is created.

We ask the question that comes before a feature request: what are you trying to solve, and is this the right way to do it? That takes experts who look beyond the next sprint and a team willing to challenge a client when speed threatens to undermine a foundation that will be expensive to repair later.

Frequently asked questions about vibe coding

When is vibe coding suitable, and when is it not?

Vibe coding is a useful tool for testing an initial idea, making an internal demo or quickly validating a user flow. Once real users, paying customers or sensitive data are involved, a prompt alone is not enough. You need an approach that accounts for security, scalability and ongoing management.

What are the risks of putting a vibe-coded prototype into production?

The largest risks lie in what you do not immediately see: missing access controls, accidentally exposed API keys, no protection against peak usage and unanswered questions about privacy requirements.

How do I combine AI speed with a stable, secure product?

Use AI under the guidance of people who know which questions to ask about architecture, security and scalability. That means using AI within a structure designed for growth from day one.

How do I move from a prototype to a production-ready platform?

Start by clarifying who your users are and what they need before extending what you already have. Then review authentication, database structure, monitoring and compliance, and build with proven technology. A Product Discovery Workshop helps many of our clients define these steps in two days before development begins.

Yvo Gortemaker

Curious how AI can add value to your product?

With our AI Opportunity Map, our senior product and AI experts work with you over two days to identify opportunities and turn them into a product with a solid foundation for growth. Or contact us directly:

More articles

  • Blog
    AI technical debt keeps growing
    AI Technical debt slows good products down
  • Blog
    From vibe coding to production
    The software iceberg: architecture, security, scalability and operations beneath a working prototype
  • Blog
    The SaaS growth ceiling: how churn and pricing shape growth
    Working harder while SaaS revenue stops growing
  • Blog
    Agent-led growth: winning customers through AI agents
    Agent-led growth with AI agents advising your product
Yvo Gortemaker
Author: Yvo Gortemaker
“What I enjoy most about my work is helping our clients realise their digital ambitions. That means combining a solid technical foundation and AI with a clear understanding of what users value and what supports the business objectives. The result: fewer IT worries and more focus on growth.”