This week on the Rogue Startups, Craig gets roasted. He brought in experienced software engineer Brandon Hancock after building the AI-powered SaaS app Outlier largely through “vibe coding,” so Brandon could audit the entire codebase live during the episode. The result? An honest but useful breakdown of what happens when non-technical founders ship fast with AI tools.
Brandon digs into real security risks, common architecture mistakes, and the best practices every founder should follow when building AI-driven products. If you’re launching SaaS with tools like Next.js, Supabase, and Claude, or simply adding AI features to your existing product, this episode offers practical lessons on building faster without accidentally breaking everything.
Check the episode out on YouTube to see Brandon dig through Craig’s code onscreen.
Highlights from Craig and Brandon’s conversation:
What “vibe coding” looks like when building a real production startupHow a single exposed Supabase key can create major security risksWhy row-level security is critical for protecting user dataUsing AI to audit code and uncover vulnerabilities in minutesSimple fixes that dramatically improve SaaS securityWhy many AI code review tools miss critical issuesThe danger of exposing backend clients in frontend codeHow server actions can replace many API endpointsBest practices for managing database migrations with Drizzle ORMWhy staging environments save founders from catastrophic production mistakesThe difference between moving fast and building responsiblyHow to structure AI documentation for better development workflowsUsing task templates to teach AI your coding standardsPractical lessons for founders building SaaS products with AI toolsResources and Links from This Episode
Shipkit.ai: https://www.shipkit.ai/ Brandon on LinkedIn: https://www.linkedin.com/in/brandon-hancock-ai Brandon’s website: https://brandonhancock.io/ Brandon on YouTube: https://www.youtube.com/@aiwithbrandon Rogue Startups on YouTube: https://www.youtube.com/@roguestartups Castos Free Tools: castos.com/toolsEmail me: [email protected] Find me on Twitter: @TheCraigHewittIf you feel like Rogue Startups has benefited you, and it might benefit someone else, please share it with them. If you have a chance, give Rogue Startups a review on iTunes.
Do you have any comments, questions, or topic ideas for future episodes? Feel free to reach out to me:
Twitter: @TheCraigHewittLinkedIn: Craig HewittEmail: [email protected]