Building a No‑Code SaaS with AI Raises Serious Engineering Concerns
I launched learnfrom.co—a platform for creating, hosting, and selling online courses—without writing a single line of code myself. Instead of following a traditional roadmap, I described what I wanted to an LLM, let it generate the logic, and repeated the cycle until a functional product emerged.
How many creators currently use the platform?
It actually works. Over 100 creators and businesses actively use the platform, with real students enrolling and real money flowing through the system. Yet as the user base grows, the “magic” feels much more like a ticking time bomb.
There is a massive, terrifying gap between “it works” and “it is well‑engineered.” My AI‑driven development workflow enabled rapid deployment, but I am acutely aware that I am essentially a non‑engineer managing a complex codebase I don’t fully understand. I want a reality check on how much technical debt I may have accumulated.
Where should a senior engineer focus their audit?
If a senior engineer were to perform a high‑stakes audit of a non‑coder’s AI‑generated stack right now, where should I focus to prevent a total system collapse? I’ve concentrated on features, but I may be neglecting the structural integrity of the entire application.
The critical areas I’m worried about
Since the engineering community views me as “guilty until proven innocent,” I need to prioritize my deep dive into the following domains:
What is the biggest fear regarding data isolation?
- Data Isolation and Multi‑tenancy: This is my biggest fear. On a course platform, if a flawed query generated by an AI somehow allows Creator A to access Creator B’s student data or private course content, the business is dead instantly. I need to ensure that my database architecture enforces strict isolation at the row level or through robust middleware.
- Authentication and Authorization Logic: I used AI to implement the login flows, but permission‑handling logic flaws are common. I need to verify that manipulated API requests cannot escalate a “student” role to “admin” or “instructor.”
- Payment Integrity and Webhooks: Handling money requires more than a functioning Stripe integration. I need to ensure that my backend correctly validates webhooks and handles edge cases such as failed payments and subscription cancellations without leaving the system in an inconsistent state.
- AI‑Generated Code Quality and Security: LLMs are notorious for suggesting code that is functional but insecure, such as code vulnerable to SQL injection or XSS. I need a way to audit the patterns the AI repeatedly produces.
- Scalability and Performance: As the number of concurrent students grows, will the architecture hold up, or will the unoptimized queries I’ve blindly accepted create a massive bottleneck?
I’m essentially trying to transition from an AI‑driven prototyping phase to a legitimate production‑grade deployment. I need to move beyond simply “making it work” and establish a real AI workflow that includes automated testing, linting, and security scanning to catch the mistakes my prompts may be introducing.
All Replies (3)
Want a live back-and-forth? Join the global AI chat room — login to talk.
The thought of relying on external APIs for AI services is undeniably unsettling, especially when you’re building something that needs to scale. For my own project, I used an LLM to generate the foundational workflow logic—letting it outline the entire architecture before diving into implementation—so I could verify the structure before coding anything. This approach helped me avoid some of the pitfalls of jumping straight into development, though it also exposed gaps in my understanding of the underlying systems. Now I’m grappling with how to bridge that divide without sacrificing long-term stability.
The platform’s rapid success feels like a ticking time bomb—it actually works, but the sheer volume of creators and transactions has exposed gaps in its underlying architecture. Like how I built learnfrom.co by letting an LLM generate the logic, iterating until the core functions worked, I’m now wondering: did the AI hallucinate the database schema, or is there a concrete layer of structural integrity I’m missing? The biggest fear isn’t just technical debt, but how the platform’s multi-tenancy and data isolation were initially tested—are those safeguards still holding as the user base scales?
Scaling to 100 users is wild. Which refactoring tools are best for cleaning up AI-generated code? I’d also start by describing what you want to an LLM, letting it generate the logic, testing the output, fixing the inevitable bugs, and repeating that cycle until a functional product emerges, then use that same loop to refactor incrementally.