v-code.ai
A live reference site about vibe coding, built on this platform from a single brief. Worth a look if you want to see what one description turns into.
Personal vibe-coding platform
Q-Code builds websites, platforms and apps from a conversation, and ships them ready for AI to find, understand and use.
You describe what you want in plain English, watch it build, check it on a live preview, and publish in about twenty seconds. What comes out is answer-ready for the engines that now do the finding, scored on how machines see it, and able to serve an AI assistant as tools rather than pages. Every site ships hardened by default, and the hosting account, the repository, the domain and the database are all in your name.
A site for my bike shop. Opening hours, a repair booking form, and it has to look calm rather than shouty.
Building a four-page site: home, repairs, opening hours and contact. Adding the bookings module for the repair slots, and taking a deposit is one switch if you want it later.
warm neutral base · one amber accent
Build 14
AI-readiness
A growing share of visits starts with an AI doing the looking, and some of them are not people at all. Every site built here is prepared for that in three layers, and all three ship by default.
01 · Found by AI
The parts an answer engine looks for are written on every build rather than added later, because a site that leaves them out is one an AI has to guess about.
02 · Measured and fixed
The visibility engine reads the HTML a crawler actually receives, plus, for security, the live response headers and the database, and returns one report, with each finding written as a sentence and a button rather than as homework. Measuring agent readiness at all is an unusual thing for a site builder to do.
03 · Usable by AI
One module turns the site into an MCP server at /mcp, so an assistant working for a visitor can ask it questions instead of scraping it. Its tools are derived from the modules the site has installed.
The loop
Four steps, and the third one is the reason the other three are safe: nothing reaches your domain until you have looked at it.
01
Say what you want in the words you would use to a person. No brief, no wireframe, no ticket.
02
The build narrates itself as it goes, in plain English, so you can tell whether it understood you before it finishes.
03
Every build lands on a real preview URL first. You see it before anybody else can.
04
One click puts it on your own domain, with a certificate, in about twenty seconds.
Security by default
Security is not a module you remember to install or a checklist handed back to you at the end. Every site built here comes with the controls below already set, and the platform’s own security lens scores a default site 99 out of 100.
Every site can publish a public trust page saying, in plain English, how it is secured, where it runs and how it handles what you send it. It is maintained from the site’s own configuration rather than written by hand, so it cannot quietly describe a site that no longer exists.
Ownership
Most builders of this kind hand you a website and keep the ground it stands on. Q-Code puts the ground in your name first and builds on top of it.
Capabilities
Each of these is an engine rather than a page: told what your project is, it reshapes itself instead of asking you to fill in a fixed form.
Visibility
Machine visibility, conversion, security and agent readiness, measured on the HTML a crawler actually receives, then handed back as a fix.
Read about visibilityCatalogue
Cars, property, products or services. You define the fields; the filters, the gallery and the descriptions follow from them.
Read about catalogueContent
One brand voice every generated word passes through, and a blog that reads the site’s own audit before choosing a topic.
Read about contentDomains
Three ways to attach a custom domain, SSL in minutes, and sending from your own address rather than a shared relay.
Read about domainsVisibility
Every build is audited against six pillars: SEO, AEO, LLMO, conversion, security and agent readiness. Most are read from the HTML a crawler actually receives rather than the source it was written from; security also reads the live response headers and the database directly. The score is one number, each finding is a sentence you can act on, and the fix is a button rather than a homework assignment.
Answer engines are included on purpose. A growing share of visits begin with an AI reading the page and answering on your behalf, so the audit checks whether your answer is near the top of the page where it can be quoted, and whether the site publishes a machine-readable description of itself.
Visibility score
90/100
+11 since last build
Conversion
The repairs page asks for a booking twice and never says what it costs.
Fix this
AEO
Two pages open with background instead of the answer.
Fix this
Running it
Four small things that decide whether a platform is pleasant to live with: you can see the sites, hand it files, see what it costs, and trust a long job to finish.
Every project is a card carrying a real screenshot of the site as it looks now, captured at the edge. Not an icon, not a stock thumbnail, so a board of eight projects reads at a glance.
Attach a logo and say rebrand, or drop in photographs and say add these to the gallery. The files are used directly, rather than uploaded somewhere else first and referred to later.
Spend is shown per build and per month, with a budget warning before a budget is crossed. Cost is a number in front of you rather than a statement you go and open.
A long change checkpoints its progress and continues, rather than stopping at an error you cannot get past. If it is about to spend past a ceiling, it warns you and asks first.
Coming from Lovable
A guided wizard brings a Lovable project across into a Q-Code project you own, in five visible steps. Your domain is the last thing to move, because it is the thing a visitor notices going wrong.
An imported React site gets the same owner admin console a site built here from scratch gets, with an overview, analytics, brand voice and access, drawn in the imported site’s own palette rather than the platform’s.
Nothing dangerous is automated away. The wizard does the tedious part and holds the consequential part until you have checked it.
Module library
A module is a feature that has already been written, argued about and hardened on somebody else’s project. Installing one is a switch, not a build.
Every module carries its own admin panel, structured data and audit rules, so installing one does not quietly cost you a point of visibility.
Built on it
The shortest answer to what this produces is a site it produced.
A live reference site about vibe coding, built on this platform from a single brief. Worth a look if you want to see what one description turns into.
The web agency that runs on Q-Code and builds every client site on it. The platform is not a side project it sells; it is the one it uses.
Q&A
Vibe coding is building software by describing what you want in natural language and letting an AI write the code. You review the result rather than the syntax. Q-Code adds the parts that decide whether the result is usable: a live preview, a real domain, an audit, and ownership of everything it produces.
Mostly in where the result lives. Q-Code builds onto infrastructure held in your name, meaning your Cloudflare account, your repository, your domain and your database, and bills you directly for it. There are also no message limits, and a shared library of modules that have already been built and hardened on other projects.
No. Every build narrates what it is doing in plain English, and the things you change most often, such as copy, photographs, prices, opening hours and testimonials, are rows you edit in a panel without a build at all.
Marketing sites, catalogues, booking systems, member areas, internal tools and small apps. There are 20 installable modules across five groups, so most projects are assembled from things that already work rather than written from nothing.
Every page is static HTML on a global edge network, ships no JavaScript unless a feature needs it, and is checked on every build for one h1, heading order, alt text, meta description, valid structured data and anything that would overflow a phone.
Yes, and nothing is asked of you to make it so. Every site ships with HTTPS and HSTS, secure response headers, an enforced content-security-policy and row-level security on the data. A managed firewall sits in front of the endpoints that take public input, and dependencies and code are scanned for known vulnerabilities and leaked secrets on every change.
Yes, through a guided import wizard that runs in five steps: source, pre-flight, import, gates and result. Three verification gates have to clear before your domain moves: a real member signs in on the imported site, a real payment event arrives from the provider, and the secrets are rotated.
Yes. Spend is shown per build and per month, with a budget warning before a budget is crossed, so cost is a number in front of you rather than a surprise at the end of the month. A build about to spend past a ceiling stops and asks you first.
You keep the site. The hosting, domain, repository and database are on accounts in your name, so what stops is the building, not the running.
Describe the thing you want to exist. The first preview is usually up before you have finished explaining it.