<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Dravin AI · Blog · Market research</title><description>Market research on the Dravin AI blog: what AI agencies and AI code-cleanup firms sell, which offers are crowded or thin, and what a buyer should check.</description><link>https://dravin.ai/blog/tags/market-research/</link><language>en-gb</language><image><url>https://dravin.ai/apple-touch-icon.png</url><title>Dravin AI · Blog · Market research</title><link>https://dravin.ai/blog/tags/market-research/</link></image><lastBuildDate>Mon, 21 Sep 2026 18:30:00 GMT</lastBuildDate><atom:link href="https://dravin.ai/blog/tags/market-research/rss.xml" rel="self" type="application/rss+xml"/><item><title>The 90 firms that fix AI-generated code</title><link>https://dravin.ai/blog/who-cleans-up-ai-generated-code/</link><guid isPermaLink="true">https://dravin.ai/blog/who-cleans-up-ai-generated-code/</guid><description>What the 90 firms say breaks in AI-built apps, how they package the work, what none of them sells, and a checklist to use on any of them, including us.</description><pubDate>Mon, 21 Sep 2026 18:30:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;strong&gt;TL;DR&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;We found 90 firms that fix apps built with AI tools. Over half name security as the problem; only two name duplicated logic.&lt;/li&gt;&lt;li&gt;Not one of the 90 names runaway AI API spend as something they fix.&lt;/li&gt;&lt;li&gt;The market has settled on one sequence: read the code, stabilise what is dangerous, refactor or rebuild what will not hold, then watch it.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;In September 2026 we went looking for companies that sell cleanup of AI-generated code: apps built with Lovable, Bolt, Cursor, Replit, v0, Claude Code and similar tools, by people who then got stuck. We found 90. This post is what those 90 say they fix, how they package the work, and what we think a buyer should demand from any of them.&lt;/p&gt;
&lt;h2 id=&quot;why-this-category-exists&quot;&gt;Why this category exists&lt;/h2&gt;
&lt;p&gt;In our reading of the 90 service descriptions, the typical caller in 2026 is a business owner, a product manager or a COO who built something real with an AI tool and then met real users, a payment that fails, or a security email from a stranger.&lt;/p&gt;
&lt;p&gt;The demand is visible in public. On r/ExperiencedDevs, the thread “Getting more calls to fix ai generated codebases than actual new builds lately” reached 405 upvotes and 102 comments; one comment: “Cleanup contracts are gonna be a whole market segment.” On r/SaaS, an MVP dev shop said it lost half its pipeline to Claude Code in 2025; of the prospects who tried it instead, about a third shipped, a third broke in production, and three came back for cleanups. On r/vibecoding, a post pointing to a vibe-code fix service, asking builders about getting their “mess” fixed, drew 1,086 upvotes and 125 comments.&lt;/p&gt;
&lt;p&gt;The failure rate is measurable. Veracode’s 2025 report found that AI-generated code introduced security flaws in 45% of its tests. How Bad Is It?, a public URL scanner for Lovable, Bolt and v0 apps, publishes a running counter: 4,271 apps reviewed, median score 38 out of 100.&lt;/p&gt;
&lt;figure&gt;&lt;ul&gt;&lt;li&gt;&lt;strong&gt;45%&lt;/strong&gt; of Veracode tests where AI-generated code introduced a security flaw. Source: Veracode, 2025&lt;/li&gt;&lt;li&gt;&lt;strong&gt;38&lt;/strong&gt; median score out of 100 across 4,271 Lovable, Bolt and v0 apps scanned. Source: How Bad Is It?&lt;/li&gt;&lt;/ul&gt;&lt;/figure&gt;
&lt;h2 id=&quot;who-the-90-are&quot;&gt;Who the 90 are&lt;/h2&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Type of firm&lt;/th&gt;
&lt;th&gt;Count&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Established dev agencies that added a cleanup service line&lt;/td&gt;
&lt;td&gt;48&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Human audit specialists&lt;/td&gt;
&lt;td&gt;13&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Agencies formed for rescue work&lt;/td&gt;
&lt;td&gt;10&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Automated scanners&lt;/td&gt;
&lt;td&gt;10&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Solo fixers and freelance studios&lt;/td&gt;
&lt;td&gt;6&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Marketplaces and expert networks&lt;/td&gt;
&lt;td&gt;3&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;Twenty are in the USA, 18 in Europe outside the UK, 7 in India, 6 in the UK, 4 in Canada, 11 elsewhere, and 24 give no location. Size is mostly undisclosed (53 of 90); of the rest, 6 have 250 or more people, 10 are mid-sized and 21 are small, micro or one-person.&lt;/p&gt;
&lt;p&gt;It is a young and thin market. We could open 75 of the 90 websites; 15 are known only from directory listings, and three domains (Vibe App Rescue, VibeCheckAudit, VibeFixLab) no longer resolve. Fifty-five name an AI builder in their service copy; Lovable leads (50), then Cursor (46), Bolt (44) and Replit (41).&lt;/p&gt;
&lt;h2 id=&quot;what-they-say-breaks&quot;&gt;What they say breaks&lt;/h2&gt;
&lt;p&gt;We counted which failure classes each firm’s service description names.&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Failure class named in the service description&lt;/th&gt;
&lt;th&gt;Entries (of 90, scanners included)&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Security in general (vulnerabilities, OWASP, hardening)&lt;/td&gt;
&lt;td&gt;48&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Missing or broken tests&lt;/td&gt;
&lt;td&gt;25&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Performance and scalability&lt;/td&gt;
&lt;td&gt;25&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;No deploy pipeline, CI/CD or hosting setup&lt;/td&gt;
&lt;td&gt;23&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Authentication and access control (including Supabase RLS)&lt;/td&gt;
&lt;td&gt;18&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Data model or database problems&lt;/td&gt;
&lt;td&gt;15&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Secrets and API keys in code&lt;/td&gt;
&lt;td&gt;10&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Monitoring and observability&lt;/td&gt;
&lt;td&gt;9&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Documentation&lt;/td&gt;
&lt;td&gt;9&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Payments and Stripe&lt;/td&gt;
&lt;td&gt;8&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Duplicated logic and coupling&lt;/td&gt;
&lt;td&gt;2&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Hallucinated APIs&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Runaway AI API spend&lt;/td&gt;
&lt;td&gt;0&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;Security is the sales pitch. Over half the market names it, and seven of the ten automated scanners are security scanners: Supabase row-level-security probes, leaked-key detection, public buckets. Beesoul, a US-listed audit shop (figures from its directory listing), reports that 10.3% of the Lovable apps it audited had critical RLS vulnerabilities, and that a typical MVP has 8 to 14 findings. Sidekick Interactive’s case study is typical of the genre: exposed API keys, database holes and broken payments in one app.&lt;/p&gt;
&lt;p&gt;Structure is under-sold. Only two of the 90 entries, one of them a scanner, mention duplicated logic or unsafe coupling by name, though that is what makes an AI-generated codebase slow and risky to change. A security patch is usually local; untangling several copies of the same auth check, each slightly different, is where the work goes.&lt;/p&gt;
&lt;p&gt;Nobody sells a spending cap. Not one of the 90 names uncontrolled AI API usage as something they fix; the two that mention “cost” at all mean something else. Yet on r/cursor, a thread about a Cursor bill that spiked within one hour, after a PM asked the agent to tag 87 tasks, reached 228 upvotes. An app that calls a model on every request with no budget, rate limit or per-user cap is a bill waiting to happen.&lt;/p&gt;
&lt;h2 id=&quot;how-they-package-it&quot;&gt;How they package it&lt;/h2&gt;
&lt;p&gt;The 80 human-service firms (the 90 minus the 10 scanners) use four patterns, often more than one at once.&lt;/p&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Packaging pattern&lt;/th&gt;
&lt;th&gt;Firms (of 80)&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Audit, assessment or review named as the first step&lt;/td&gt;
&lt;td&gt;61&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Audit or assessment promised within 48 hours&lt;/td&gt;
&lt;td&gt;10&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Work described in sprints&lt;/td&gt;
&lt;td&gt;9&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Rebuild or re-architecture offered as one option&lt;/td&gt;
&lt;td&gt;9&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Explicitly against rebuilding&lt;/td&gt;
&lt;td&gt;5&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Retainer, maintenance or monitoring mentioned&lt;/td&gt;
&lt;td&gt;16&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;strong&gt;Audit first.&lt;/strong&gt; &lt;a href=&quot;https://vallettasoftware.com/vibe-coding-cleanup&quot;&gt;Valletta Software&lt;/a&gt; (Malta) is the cleanest version: a senior engineer reviews the repository across eight areas, delivers the audit in 48 hours with a debrief call, then scopes the cleanup, typically six to eight weeks. &lt;a href=&quot;https://www.metacto.com/solutions/product-development/vibe-rescue&quot;&gt;MetaCTO&lt;/a&gt; runs a 48-hour code audit, then promises production-ready in 30 days, with weekly demos.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Fixed-scope rescue.&lt;/strong&gt; &lt;a href=&quot;https://axonbuild.com/&quot;&gt;AxonBuild&lt;/a&gt; sells a 10-working-day production-engineering sprint covering auth, secrets, payments, CI/CD and monitoring, ending in a verified handover with two weeks of defect cover and 30 days of async support. &lt;a href=&quot;https://relux.works/en/vibe-code-rescue/&quot;&gt;Relux Works&lt;/a&gt; (Armenia) runs a one-week audit, then a two-to-three-week stabilisation sprint, then what it calls “de-vibe-coding”: moving the app to a production architecture.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Rebuild.&lt;/strong&gt; Usually offered for the broken parts only, and five firms say outright that they avoid it. &lt;a href=&quot;https://bitnoise.pl/services/vibe-code-rescue&quot;&gt;Bitnoise&lt;/a&gt; (Poznań) shows the whole sequence: audit in 3 to 7 business days, stabilisation sprint 2 to 4 weeks, re-architecture 6 to 12 weeks.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Retainer.&lt;/strong&gt; &lt;a href=&quot;https://vibe-audit.com/&quot;&gt;Vibe-Audit&lt;/a&gt; (Barcelona, a one-person shop) runs a pre-launch security sweep delivered in 48 hours, done-for-you fixes, and then ongoing security monitoring.&lt;/p&gt;
&lt;p&gt;Side by side, the market has settled on one sequence: read the code, stabilise what is dangerous, refactor or rebuild what will not hold, then watch it.&lt;/p&gt;
&lt;figure&gt;&lt;p&gt;How cleanup is sold&lt;/p&gt;&lt;ol&gt;&lt;li&gt;Read the code: audit or review first&lt;/li&gt;&lt;li&gt;Stabilise: what is dangerous now&lt;/li&gt;&lt;li&gt;Refactor or rebuild: what will not hold&lt;/li&gt;&lt;li&gt;Watch it: retainer or monitoring&lt;/li&gt;&lt;/ol&gt;&lt;figcaption&gt;The sequence the 80 human-service firms describe, often combining more than one pattern.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;h2 id=&quot;what-a-good-cleanup-engagement-includes&quot;&gt;What a good cleanup engagement includes&lt;/h2&gt;
&lt;p&gt;Use this on anyone you are considering, including us.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;A written review before any commitment, with findings ranked by severity and a verdict: ship, patch, refactor or rewrite. If the verdict is “not worth fixing”, they should say so.&lt;/li&gt;
&lt;li&gt;An experienced engineer who has actually read the code. A scanner finds leaked keys; it does not find the auth check that is bypassed on one route.&lt;/li&gt;
&lt;li&gt;Security tested against the running app, not only the repository: authentication, per-row authorisation, secrets rotated rather than just deleted from git, public storage buckets closed.&lt;/li&gt;
&lt;li&gt;Characterisation tests written before refactoring, so current behaviour is pinned and the cleanup cannot silently change it.&lt;/li&gt;
&lt;li&gt;Duplicated logic collapsed and the data model reviewed, because that decides whether the next feature takes a day or a month.&lt;/li&gt;
&lt;li&gt;A deploy pipeline and monitoring at the end: staging, CI, error tracking, backups. Working on one person’s laptop does not count as done.&lt;/li&gt;
&lt;li&gt;AI API spend bounded: budgets, rate limits, per-user caps and an alert. Nobody in the 90 sells this; ask for it anyway.&lt;/li&gt;
&lt;li&gt;Handover: documentation, and you holding the repository, the cloud accounts and the keys. You own the code from day one.&lt;/li&gt;
&lt;li&gt;A fixed scope with a definition of done and a defect-cover window afterwards.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id=&quot;how-we-do-it&quot;&gt;How we do it&lt;/h2&gt;
&lt;p&gt;Dravin AI is an AI software company. We build AI systems and software, and we clean up &lt;a href=&quot;https://dravin.ai/services/#code-quality&quot;&gt;AI-built apps&lt;/a&gt;. Against the list above, this is what we commit to:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;A written report first.&lt;/strong&gt; Read-only access to one repository, and within 48 hours a written report with findings ranked by severity: the file, the risk and the fix, and what to leave alone. If nothing needs fixing, it says so. There is no obligation to go further.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Secrets.&lt;/strong&gt; A secret we find in your repository is reported the same day, ahead of the report, and rotated within 24 hours.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Auth and data access.&lt;/strong&gt; Every route’s auth check, database access policies included, is traced in the code. Testing the running app is agreed on the call, because it needs access beyond the repository.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Tests before refactoring.&lt;/strong&gt; Tests on the paths that make money, run on every pull request, and structure changed in small, tested steps.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Deploys.&lt;/strong&gt; From the repository, with a rollback that has been tried.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;AI API spend.&lt;/strong&gt; Timeouts, budgets and retry caps on every model call.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Ownership.&lt;/strong&gt; The code is yours from the first commit, we work on branches, never main, and our access is removed within seven days of handover, confirmed in writing.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Defect cover.&lt;/strong&gt; Anything that misses the statement of work, reported in writing within 30 days of handover, is corrected under it.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;An engagement starts with a call about what you built, what it does in production and what worries you. If that is an app that got you to traction, &lt;a href=&quot;https://cal.com/dravin-ai/intro&quot;&gt;book one&lt;/a&gt; or &lt;a href=&quot;https://dravin.ai/review/&quot;&gt;request a code review&lt;/a&gt;.&lt;/p&gt;
&lt;h2 id=&quot;method&quot;&gt;Method&lt;/h2&gt;
&lt;p&gt;Every count comes from the cleanup list in our research workbook: 90 firms, each with a segment, a region, a size band, a description of what it does, its delivery model and its stated turnaround. We read the list on 22 September 2026. The workbook itself is not published; these are the counting rules.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Type, region, size&lt;/strong&gt;: counts of each firm’s segment, region and size band. “Small, micro or one-person” is Small (10 to 49) plus Micro (2 to 9) plus Solo.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Reachability&lt;/strong&gt;: whether we could fetch the firm’s site or know it only from a directory listing, and whether its domain still resolves.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Tool mentions&lt;/strong&gt;: a case-insensitive search of each firm’s description for each builder’s name.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Failure classes&lt;/strong&gt;: a case-insensitive keyword search of the description only. Security: secur, vuln, OWASP, pentest. Tests: test, QA; Sherlock Forensics matches only through “pentest” and is excluded, so 25 rather than the mechanical 26. Performance: perf, scalab, bottleneck. Deploy: CI/CD, CI, deploy, pipeline, hosting, DevOps. Auth: auth, access control, RLS. Data model: data model, database, DB, schema, persistence, RLS. Secrets: secret, key(s), credential. Monitoring: monitor, observab, Sentry. Documentation: doc, docs, document or documentation as whole words. Payments: Stripe, payment. Duplication: duplic, coupling, dead code, untangle. Hallucination: hallucinat. AI spend: cost, spend, token, bill (the two hits, *instinctools’ “cost-benefit” and Vibe Code Rescue’s “perf &amp;amp; cost”, are not API spend). Scanner types: the descriptions of the 10 automated scanners.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Packaging&lt;/strong&gt;: over the 80 firms that are not automated scanners, searching the description, the delivery model and the stated turnaround unless a rule says otherwise. Audit-first: audit, assess, review, scan, diagnos or scorecard. 48 hours: the turnaround promises an audit, assessment, scan or check result in 48 hours or less; fix times and reply times excluded. The ten: MetaCTO, Pfaff Digital, Sonder, VibeAudits, Mitrix Technology, Valletta Software, ShipClarity, Vibe-Audit, VibeCodeBlue and one solo fixer. Sprints: “sprint” anywhere in those three fields. Rebuild offered: rebuild, re-architect, rewrite or full build (11 firms), minus the two of them that also say “without rebuild”, “no rewrites”, “not rebuild”, “diagnosis-over-rebuild” or “without starting from scratch”. Against rebuilding: one of those five phrases in those three fields, the firm’s hero line or the workbook’s notes on how each firm positions itself (5 firms). Retainer: retainer, maintenance, ongoing, monitoring, subscription, defect cover or post-rescue support (16 firms).&lt;/li&gt;
&lt;li&gt;Named offers, turnarounds and claims are quoted from what each firm publishes, unaudited.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Reddit and studies&lt;/strong&gt;: r/ExperiencedDevs (405 upvotes, 102 comments), r/SaaS (65 upvotes, 66 comments) and r/cursor (228 upvotes) from our AI-agency landscape research (48 searches, 2,837 posts, 17 September 2026); r/vibecoding (1,086 upvotes, 125 comments, 24 December 2025) from a separate Reddit sweep for the workbook; Veracode’s 45% from the same landscape research.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This post first appeared on &lt;a href=&quot;https://dravin.ai/blog/who-cleans-up-ai-generated-code/&quot;&gt;Dravin AI&lt;/a&gt;.&lt;/p&gt;</content:encoded><category>Code cleanup</category><category>Vibe coding</category><category>Security review</category><category>Market research</category><author>info@dravin.ai (Dravin AI)</author></item><item><title>What 843 AI agencies actually sell</title><link>https://dravin.ai/blog/what-843-ai-agencies-actually-sell/</link><guid isPermaLink="true">https://dravin.ai/blog/what-843-ai-agencies-actually-sell/</guid><description>We mapped 843 AI agencies across India, the US and Europe: what they sell, where they are, which offers are crowded, which are thin, and what to check.</description><pubDate>Mon, 21 Sep 2026 18:30:00 GMT</pubDate><content:encoded>&lt;p&gt;&lt;strong&gt;TL;DR&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Automation and custom builds account for 457 of the 843 firms we mapped. Only 31 sell audit, security or testing.&lt;/li&gt;&lt;li&gt;The thinnest part of the market is what a system needs once it is live: evaluation, monitoring and someone who answers when it breaks.&lt;/li&gt;&lt;li&gt;Size is unknown for 569 of the 843, so ask who will do the work, what happens after the build and how they will know it works.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Between 17 and 22 September 2026 we built a workbook of every AI agency, consultancy and AI-native delivery firm we could find: 843 firms across India, the US, Europe and a long tail of other regions. We wanted to see the market the way a buyer does. Every count below was computed from that workbook; the method is at the end.&lt;/p&gt;
&lt;p&gt;The short version: most of the market sells the same two things, automation and custom builds, which together account for 457 of the 843 firms. Only 31 sell audit, security or testing. And the work a team needs once something is in production, evaluation, monitoring and someone on the hook when it breaks, is the thinnest part of the map.&lt;/p&gt;
&lt;h2 id=&quot;what-we-counted-and-how&quot;&gt;What we counted and how&lt;/h2&gt;
&lt;p&gt;Eight research passes (Americas and ANZ, India, Europe and the Middle East, design-led studios, consulting and advisory, Asian, vertical and voice agencies, AI-code cleanup, freelancers), directory sweeps (Clutch, GoodFirms, DesignRush, Sortlist, and the n8n, Make and Zapier directories), and 211 firms carried over from our earlier landscape note. Duplicates were merged on domain. Of the 843 sites, 819 loaded and 619 homepages were read on the research date.&lt;/p&gt;
&lt;p&gt;Each firm has a region, one of 35 segments, a size band and a description of what it does. Kept separately, outside the 843: 90 firms that fix &lt;a href=&quot;https://dravin.ai/blog/who-cleans-up-ai-generated-code/&quot;&gt;AI-generated code&lt;/a&gt;, 103 independent consultants, and a 40-row catalogue of every offer type we saw, each rated by how many credible sellers it has.&lt;/p&gt;
&lt;p&gt;One caveat: size is known for only 274 of the 843. Most firms do not say how big they are, which matters later.&lt;/p&gt;
&lt;h2 id=&quot;the-regional-shape&quot;&gt;The regional shape&lt;/h2&gt;
&lt;figure&gt;&lt;p id=&quot;chart-firms-by-region-843-firms&quot;&gt;Firms by region · 843 firms&lt;/p&gt;&lt;ul&gt;&lt;li&gt;India: 209&lt;/li&gt;&lt;li&gt;USA: 162&lt;/li&gt;&lt;li&gt;Europe (as tagged): 146&lt;/li&gt;&lt;li&gt;UK: 55&lt;/li&gt;&lt;li&gt;Australia and NZ: 41&lt;/li&gt;&lt;li&gt;Asia (other): 39&lt;/li&gt;&lt;li&gt;Middle East: 35&lt;/li&gt;&lt;li&gt;Latin America: 32&lt;/li&gt;&lt;li&gt;Canada: 28&lt;/li&gt;&lt;li&gt;Africa: 14&lt;/li&gt;&lt;li&gt;Global, multi-country, other or unknown: 82&lt;/li&gt;&lt;/ul&gt;&lt;figcaption&gt;All 843 firms by the region each is tagged with. Europe is the tag as found and holds some UK-based firms; the Method breaks down the last row.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;p&gt;The regions sell different things. India’s 209 are build shops: 46 dev studios, 27 boutiques, 21 mid-sized IT firms, 29 automation agencies. The US mix is flatter: 21 vertical agencies, 21 automation agencies, 19 dev studios, 11 forward-deployed engineering firms and all 9 big-consultancy AI arms. Europe holds the incumbents: 31 IT majors and consultancies, 15 nearshore firms, 14 data engineering firms. The UK leans to advice: 6 of the 14 governance firms and 5 of the 11 training firms are British.&lt;/p&gt;
&lt;h2 id=&quot;what-firms-sell&quot;&gt;What firms sell&lt;/h2&gt;
&lt;p&gt;The 35 segments group into nine offer families. The grouping is ours; every firm lands in exactly one.&lt;/p&gt;
&lt;figure&gt;&lt;p id=&quot;chart-firms-by-offer-family-843-firms&quot;&gt;Firms by offer family · 843 firms&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Automation and agents as a service: 246&lt;/li&gt;&lt;li&gt;Custom build: 211&lt;/li&gt;&lt;li&gt;Embedded and enterprise delivery: 123&lt;/li&gt;&lt;li&gt;Advice and strategy: 117&lt;/li&gt;&lt;li&gt;Data engineering: 62&lt;/li&gt;&lt;li&gt;Audit, security and QA: 31&lt;/li&gt;&lt;li&gt;Platforms and tooling: 26&lt;/li&gt;&lt;li&gt;Training and community: 18&lt;/li&gt;&lt;li&gt;Other: 9&lt;/li&gt;&lt;/ul&gt;&lt;figcaption&gt;All 843 firms by offer family. Audit, security and QA, the rust bar, is 31 firms; automation and custom build together are 457. The table below lists the segments inside each family.&lt;/figcaption&gt;&lt;/figure&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Offer family&lt;/th&gt;
&lt;th&gt;Firms&lt;/th&gt;
&lt;th&gt;Segments inside&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Automation and agents as a service&lt;/td&gt;
&lt;td&gt;246&lt;/td&gt;
&lt;td&gt;142 SMB automation agencies, 70 vertical agencies, 26 voice-AI agencies, 4 productised services, 4 automation-and-coaching hybrids&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Custom build&lt;/td&gt;
&lt;td&gt;211&lt;/td&gt;
&lt;td&gt;123 dev studios, 27 Indian boutiques, 26 design-led studios, 15 nearshore firms, 11 engineering firms with an AI practice, 9 AI-native delivery firms&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Embedded and enterprise delivery&lt;/td&gt;
&lt;td&gt;123&lt;/td&gt;
&lt;td&gt;35 FDE firms, 31 IT majors based in Europe, 21 Indian mid-sized IT firms, 9 big-consultancy arms, 8 established Indian engineering firms, 7 platform-plus-services firms, 6 IT-major practices, 6 lab and hyperscaler arms&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Advice and strategy&lt;/td&gt;
&lt;td&gt;117&lt;/td&gt;
&lt;td&gt;51 AI consultancies, 19 research and advisory, 17 strategy consultancies, 12 industry consultancies, 12 MSPs, 6 fractional-leadership firms&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Data engineering&lt;/td&gt;
&lt;td&gt;62&lt;/td&gt;
&lt;td&gt;50 data and AI engineering firms, 12 analytics consultancies&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Audit, security and QA&lt;/td&gt;
&lt;td&gt;31&lt;/td&gt;
&lt;td&gt;14 governance and compliance, 10 security and red-teaming, 7 QA and testing&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Platforms and tooling&lt;/td&gt;
&lt;td&gt;26&lt;/td&gt;
&lt;td&gt;15 AI-native startups, 11 developer-productivity and AI-impact platforms&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Training and community&lt;/td&gt;
&lt;td&gt;18&lt;/td&gt;
&lt;td&gt;11 training firms, 7 coaching communities&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Other&lt;/td&gt;
&lt;td&gt;9&lt;/td&gt;
&lt;td&gt;Uncategorised&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;Automation-as-a-service and custom build account for 457 of the 843; audit, security and QA are 31. That ratio is the most useful fact in the workbook. Almost everyone will build the thing. Very few will tell you whether the thing is safe, correct or still working a month later.&lt;/p&gt;
&lt;h2 id=&quot;what-is-crowded-and-what-is-thin&quot;&gt;What is crowded and what is thin&lt;/h2&gt;
&lt;p&gt;The catalogue rates each of the 40 offers by how many credible sellers we found: 22 crowded, 15 moderate, 3 thin.&lt;/p&gt;
&lt;p&gt;Crowded:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Custom builds&lt;/strong&gt; (agents, &lt;a href=&quot;https://dravin.ai/services/#rag&quot;&gt;RAG&lt;/a&gt; systems, &lt;a href=&quot;https://dravin.ai/services/#voice&quot;&gt;voice agents&lt;/a&gt;, internal tools, integrations) are the default offer of nearly every automation agency. The catalogue’s note is that capability is much the same everywhere; firms differ by vertical depth or proof.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Discovery and readiness audits&lt;/strong&gt; take the least capital to start, so almost every new operator leads with one.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Staff augmentation&lt;/strong&gt; is the default Indian services business, with hundreds of Indian shops selling the same thing.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;AI support agents that resolve tickets&lt;/strong&gt; are sold by nine platforms, bundled into the inbox the buyer already owns.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Data plumbing for AI&lt;/strong&gt; (pipelines, warehouses, vector databases) is offered by every data consultancy and is the easiest thing on the list to buy.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thin:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Evaluation harnesses, benchmarking and observability.&lt;/strong&gt; Dozens of funded tool vendors, very few independents doing the implementation, because it takes real ML judgement.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Data-quality and AI-data-readiness audits.&lt;/strong&gt; Crowded as software, thin as a service a person delivers.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Managed agents:&lt;/strong&gt; monitoring, evals and a support SLA for AI systems already in production. Half a dozen vendors sell the dashboard; the human side, someone who answers when the agent breaks at 2am, is thin.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Codebase audit sits next to them, rated moderate: the automated side is crowded and well funded, and the human review is where the catalogue sees the gap. The cleanup list shows that gap starting to fill: 90 firms now sell cleanup of AI-generated code, 48 of them as a service line inside an existing dev agency and 13 as human audit specialists.&lt;/p&gt;
&lt;p&gt;The firm counts say the same thing. 457 firms build. 31 audit, secure or test. 11 are platforms in the developer-productivity and AI-impact segment, measuring what AI is doing to engineering teams. Meanwhile the landscape’s Reddit sweep found an r/ExperiencedDevs thread titled “Getting more calls to fix ai generated codebases than actual new builds lately” at 405 upvotes.&lt;/p&gt;
&lt;h2 id=&quot;what-to-check-before-hiring-anyone&quot;&gt;What to check before hiring anyone&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Ask who will be on the work.&lt;/strong&gt; Size is unknown for 569 of the 843, and a website rarely tells you whether you are talking to a two-person studio or a firm of 7,000. Ask how experienced the engineers are, who checks their code before it merges, and whether any of it is subcontracted.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Ask what happens after the build.&lt;/strong&gt; The market is crowded with builds and thin on evaluation, monitoring and support for systems already in production. Get a written answer on who maintains the thing, how a failure is detected and who answers when it breaks, before you sign for the thing.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Ask how they will know it works.&lt;/strong&gt; An agent or a RAG system without an evaluation harness is a demo. Few firms sell evaluation as a service, so ask to see the test set, the metrics and the regression checks for the system you are buying, and ask what happens when a model version changes underneath it.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;If you already have AI-generated code, get it read before you scale it.&lt;/strong&gt; 457 firms will happily build on top of it; 31 sell audit, security or testing, plus the 90 cleanup firms outside the main list. A careful read finds the auth check missing on one route, the key committed to the repository and the same logic copied into several places. Each is easier to fix before the next feature lands on top of it.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id=&quot;what-we-do&quot;&gt;What we do&lt;/h2&gt;
&lt;p&gt;Dravin AI is an AI software company. We build AI systems and software. Coding agents draft in parallel, each in its own isolated environment, automated checks run on every pull request, and an engineer approves each change before it merges. We also audit code and clean up AI-built apps.&lt;/p&gt;
&lt;p&gt;What we build runs from agents, voice AI, fine-tuned models, classical ML and forecasting systems to web, mobile and desktop apps, and we deploy and run them in the cloud.&lt;/p&gt;
&lt;p&gt;We also work in the thin part of this map: evaluation harnesses, and AI-generated codebases made safe enough for a real team to own. An engagement starts with a call. If any of the above describes where you are, &lt;a href=&quot;https://cal.com/dravin-ai/intro&quot;&gt;book one&lt;/a&gt; and bring the repository.&lt;/p&gt;
&lt;h2 id=&quot;method&quot;&gt;Method&lt;/h2&gt;
&lt;p&gt;Every count comes from our research workbook, built between 17 and 22 September 2026 and counted on 22 September. The workbook itself is not published; these are the counting rules.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;843&lt;/strong&gt;: every firm on the main list; 211 of them came from our earlier landscape note.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Regions&lt;/strong&gt;: the region each firm is tagged with, exact match. The 82 is Global 33, Other 24, Unknown 23, Multi-country or remote 2. Europe is the tag as found; it holds some UK-based firms.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Segments and families&lt;/strong&gt;: each firm’s segment, exact match, filtered by region where one is named. The nine families are our grouping of the 35 segment values; the table is the mapping and it sums to 843. The 11 platforms are the segment “Dev-productivity / AI-impact platform”.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Size&lt;/strong&gt;: each firm’s size band: Solo 17, Micro 60, Small 97, Mid 76, Large 24, Unknown 569; 274 known.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;819 and 619&lt;/strong&gt;: sites that passed a link check, and homepages read on the research date.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;90, 48 and 13&lt;/strong&gt;: the firms on the cleanup list; those whose segment is a dev agency with a cleanup service line; those whose segment is a human audit of AI-generated code.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;103 consultants&lt;/strong&gt;: the firms on the list of independent consultants and freelancers.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;40 offers; 22, 15, 3&lt;/strong&gt;: the offer catalogue’s 40 entries, each rated crowded, moderate or thin by how many credible sellers we found. The crowded and thin notes paraphrase the catalogue’s notes on custom builds, discovery and readiness audits, staff augmentation, support agents, data plumbing, evaluation, data-quality audits, managed agents and codebase audit.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;The r/ExperiencedDevs thread&lt;/strong&gt; (405 upvotes): from the Reddit sweep in our AI-agency landscape note.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This post first appeared on &lt;a href=&quot;https://dravin.ai/blog/what-843-ai-agencies-actually-sell/&quot;&gt;Dravin AI&lt;/a&gt;.&lt;/p&gt;</content:encoded><category>Market research</category><category>AI agencies</category><category>Code cleanup</category><author>info@dravin.ai (Dravin AI)</author></item></channel></rss>