• Nederlands

AI · 6 September 2026 ·

Built an app with AI yourself? Good. Now make sure it keeps running.

Built an app with AI? How we take it into managed service: code review, scalability, privacy and security in order, and an independent pentest.

Netwerkkast achter glas in een licht kantoor, met nette bekabeling en één teal patchkabel

We see it more and more often: an organisation has built something itself. A registration portal, an internal dashboard, an app for handing out invitation codes. Not by a software house, but by an employee with a good idea and an AI tool. A few afternoons of prompting and there is something that works. We think that is a good development: the barrier to building something has never been this low.

But “it works” and “it still works a year from now, with ten times as many users, without anything leaking” are two very different things. And that second one is exactly what we have been working on these past few weeks.

What we did

A client came to us with a vibe-coded app: developed in-house, with the help of AI, and in use. Functionally fine: create codes, hand them out, validate them. But usage grew, and with it the questions. Will it hold up at a peak? Who can actually access the data? What happens if someone tries to abuse the system?

We took the app into managed service and tackled the code on four fronts:

  • Performance: slow parts rewritten, so the app keeps responding quickly under load.
  • Scalability: the architecture set up so that growth is no longer a surprise, but something the system is built for.
  • Privacy: a critical look at which data is really needed and how long it is kept. What is not needed, we do not collect.
  • Security: the known weak spots closed: input validation, access control, the handling of secrets and keys.

And then the most important part: after these changes we had the app fully pentested by an independent party. Not a quick scan, but a real attack simulation. The outcome: no critical and no high findings. That is no coincidence, but the result of the order of work: do the thorough work first, then have it tested.

Why this matters more than it sounds

You might think: AI writes better and better code, doesn’t it? Partly true. In Veracode’s tests, modern models produce syntactically correct code almost every time, and according to the same researchers AI now writes roughly half of all new code. But on security something striking is going on. Veracode’s GenAI Code Security Report 2026 shows that in roughly 44 percent of the tested coding tasks, AI produced code with a known vulnerability. That percentage has barely changed since the previous edition, while the models improved on almost every other front. These are not exotic mistakes but classics from the OWASP Top 10, such as cross-site scripting and injection, as the 2025 edition, which tested over a hundred language models, also shows.

Put differently: AI has become very fast at building, but not at guarding. And whoever builds something alone usually has nobody looking over their shoulder. That is not a reproach. It is simply how it works when you make something on your own.

What “taking it into managed service” means with us

At Twentynext, managed service is not a hosting package with a phone number for when things go wrong. It is one of our four roles, alongside consultancy, people and projects, and we take it seriously. In practice it means that we:

  • review the code and rewrite it where needed before we take responsibility for it;
  • make sure the app can scale and can be monitored, so we see problems before users notice them;
  • set up privacy and security at the level the context requires, and in public administration, safety or healthcare that bar is considerably higher;
  • have the app pentested periodically, so that “no critical findings” is a recurring conclusion and not a snapshot.

What those agreements look like, what we monitor, how fast we respond and who is responsible, is on the Service & Maintenance page. What it takes to go from a quickly built app to a platform you can rely on, we described earlier in From vibe coded app to a mature SaaS platform.

Who is this for?

For anyone who has built an app, site or program themselves with AI and notices that it is becoming more important than intended. A tool that started as an experiment and is now used by hundreds of people. A portal that now processes personal data. A script that “just for now” has become business-critical.

Building it yourself is smart. Continuing to run it yourself is often less smart, certainly if you are not working on it every day. We take it over from you, make it robust and have it tested. So you can keep building while we make sure it keeps running.

Wondering whether your app is ready for managed service? Schedule an introduction, and we will look together at where you stand and what still needs to be done. We respond within one working day. If the question is broader than one app, AI consultancy and support is where we start.

References

Veracode. (2025). 2025 GenAI code security report. https://www.veracode.com/resources/analyst-reports/2025-genai-code-security-report/

Veracode. (2026, July 28). 2026 GenAI code security report: AI is writing more of your code but security hasn’t caught up. https://www.veracode.com/blog/2026-genai-code-security-report-ai-risk/

About this article. We check facts and sources carefully, but cannot guarantee that they are accurate or complete. See our disclaimer.

Example of a scan result: spider chart with four dimensions

Where does your organisation stand?

Sixteen questions, seven minutes, and an instant spider chart showing your strongest and weakest dimension. No e-mail address needed to see the result.

Related articles

Work with us

Realise your project together?

The people who build it also run it afterwards. Eindhoven, since 2014.

Martijn van Grieken

Martijn van Grieken

Director Data & AI

Get in touch