
AI · 6 September 2026 ·
Built an app with AI? How we take it into managed service: code review, scalability, privacy and security in order, and an independent pentest.

We see it more and more often: an organisation has built something itself. A registration portal, an internal dashboard, an app for handing out invitation codes. Not by a software house, but by an employee with a good idea and an AI tool. A few afternoons of prompting and there is something that works. We think that is a good development: the barrier to building something has never been this low.
But “it works” and “it still works a year from now, with ten times as many users, without anything leaking” are two very different things. And that second one is exactly what we have been working on these past few weeks.
A client came to us with a vibe-coded app: developed in-house, with the help of AI, and in use. Functionally fine: create codes, hand them out, validate them. But usage grew, and with it the questions. Will it hold up at a peak? Who can actually access the data? What happens if someone tries to abuse the system?
We took the app into managed service and tackled the code on four fronts:
And then the most important part: after these changes we had the app fully pentested by an independent party. Not a quick scan, but a real attack simulation. The outcome: no critical and no high findings. That is no coincidence, but the result of the order of work: do the thorough work first, then have it tested.
You might think: AI writes better and better code, doesn’t it? Partly true. In Veracode’s tests, modern models produce syntactically correct code almost every time, and according to the same researchers AI now writes roughly half of all new code. But on security something striking is going on. Veracode’s GenAI Code Security Report 2026 shows that in roughly 44 percent of the tested coding tasks, AI produced code with a known vulnerability. That percentage has barely changed since the previous edition, while the models improved on almost every other front. These are not exotic mistakes but classics from the OWASP Top 10, such as cross-site scripting and injection, as the 2025 edition, which tested over a hundred language models, also shows.
Put differently: AI has become very fast at building, but not at guarding. And whoever builds something alone usually has nobody looking over their shoulder. That is not a reproach. It is simply how it works when you make something on your own.
At Twentynext, managed service is not a hosting package with a phone number for when things go wrong. It is one of our four roles, alongside consultancy, people and projects, and we take it seriously. In practice it means that we:
What those agreements look like, what we monitor, how fast we respond and who is responsible, is on the Service & Maintenance page. What it takes to go from a quickly built app to a platform you can rely on, we described earlier in From vibe coded app to a mature SaaS platform.
For anyone who has built an app, site or program themselves with AI and notices that it is becoming more important than intended. A tool that started as an experiment and is now used by hundreds of people. A portal that now processes personal data. A script that “just for now” has become business-critical.
Building it yourself is smart. Continuing to run it yourself is often less smart, certainly if you are not working on it every day. We take it over from you, make it robust and have it tested. So you can keep building while we make sure it keeps running.
Wondering whether your app is ready for managed service? Schedule an introduction, and we will look together at where you stand and what still needs to be done. We respond within one working day. If the question is broader than one app, AI consultancy and support is where we start.
Veracode. (2025). 2025 GenAI code security report. https://www.veracode.com/resources/analyst-reports/2025-genai-code-security-report/
Veracode. (2026, July 28). 2026 GenAI code security report: AI is writing more of your code but security hasn’t caught up. https://www.veracode.com/blog/2026-genai-code-security-report-ai-risk/
About this article. We check facts and sources carefully, but cannot guarantee that they are accurate or complete. See our disclaimer.

Sixteen questions, seven minutes, and an instant spider chart showing your strongest and weakest dimension. No e-mail address needed to see the result.

AI · 21 September 2026
Sixteen questions, seven minutes, four dimensions on five levels, no email needed. What the scan measures, how it compares and how to use it.
Read the article →

Cases · 6 September 2026
Read the article →

Cases · 6 September 2026
Real-time object recognition and indoor navigation on smartphone and smart glasses, fully on-device, for travellers with a visual impairment.
Read the article →
Work with us
The people who build it also run it afterwards. Eindhoven, since 2014.

Martijn van Grieken
Director Data & AI
We use Google Tag Manager to measure visits and Leadinfo to recognise which company is visiting. Neither loads unless you agree. If you choose essential only, the site works as normal and we measure nothing. If you arrived via an advertisement in ChatGPT, we also use the OpenAI measurement pixel to attribute conversions to that advertisement. Cookie statement · Privacy statement