---
title: From Replit to production | Contember Fabrika
description: Built an app on Replit that your company now relies on? We move it via Git into your own cloud with company sign-in, no public URL and reviewed changes.
url: "https://www.contember.com/from/replit"
type: static
generatedAt: "2026-09-28T14:08:32.937Z"
---

# You built it on Replit. Here's how it runs for your company.

We take the code from your Replit project into your company's Git, make small changes and deploy it into a cloud account registered to your company, on Cloudflare or Zerops, or AWS by arrangement. Colleagues sign in with their company account, the app has no public replit.app address, and we review every change before it goes live.

This page is for whoever built the app on Replit, and for the IT person who was handed it and asked to put it into production.

Updated 28 September 2026
  [Show us your app →](https://cal.com/contember/demo) [How the move works ↓](#steps)    ![](/illustrations/machine-warehouse.webp)       From  Your GitHub
Pushed from Replit's Git pane, or a ZIP download of the project.
    To  Your cloud account
Cloudflare or Zerops, or AWS by arrangement. Registered to your company, not to us.
    Data  Comes along
Replit's database is PostgreSQL. It moves with the standard pg_dump and pg_restore.

## What people ask when a Replit app *becomes a company app*

Word for word from Replit's community forum. Each one gets a short answer from us here; the details are further down the page.


> “Is there a way to protect the myapp.replit.app url? When I connect it to my domain (...) the app is still available through myapp.replit.app”

*[Replit forum, March 2025 ↗](https://replit.discourse.group/t/how-can-i-secure-waf-replit-app/3980)*
     On Fabrika
The app has no public address at all. The only way in is the platform's sign-in, and the replit.app copy gets unpublished.


> “I simply want user to be able to access my app only without having to create a replit account, is that possible?”

*[Replit forum, November 2025 ↗](https://replit.discourse.group/t/user-app-access-requires-replit-account-creation/7899)*
     On Fabrika
Colleagues sign in with their company Google, Microsoft or Okta account, outside people with a password. Nobody needs a Replit account.


> “Could really use a one-button deploy to push a Replit app to an enterprise stack behind a firewall.”

*[Replit forum, December 2025 ↗](https://replit.discourse.group/t/enterprise-deployments/8027)*
     On Fabrika
Not a button, and not your own servers. We deploy into your company's own cloud account, where the app is reachable only through sign-in.


> “my monthly replit bill has been consistently hovering around $500–$1000 (...) it's almost entirely driven by constant agent usage top-ups and keeping a few key deployments running.”

*[Replit forum, August 2026 ↗](https://replit.discourse.group/t/anyone-else-dropping-500-1000-mo-on-agent-credits/13303)*
     On Fabrika
The servers are paid to the cloud provider by usage, and the AI your people build with runs on your company's own AI plan.


> “Is Replit really reliable for production use? (...) A platform error occurs. The rollback fails. The last stable version is gone. No usable backup is available.”

*[Replit forum, January 2026 ↗](https://replit.discourse.group/t/is-replit-really-reliable-for-production-use/8491)*
     On Fabrika
The code lives in your company's Git, so the last version doesn't vanish with a tool. Backups and restore we set up with you, to the extent you need.


> “(...) was able to design some internal tools using coding languages that are outside of the technical specialties of the current IT department (...) I'm beginning to encouter some problems since starting more ambitious projects.”

*[Replit forum, November 2025 ↗](https://replit.discourse.group/t/next-steps-as-non-tech-vibe-coder/7868)*
     On Fabrika
That's the situation Fabrika is built for: people outside IT build, the platform holds the rules and we review every change.

## What changes when the app *leaves Replit?*

Less than people expect. It stays the same app: same screens, same logic, same data. What changes is who handles sign-in, keys and deployment, and where it runs.
   ![](/illustrations/machine-parts.webp)
### Comes along as it is

 - The code and its commit history, pushed from the Git pane to a private GitHub repository, ideally in your company's organisation.
- Screens, logic and the way people use the app. We don't rewrite what works.
- The data in Replit's database. It's PostgreSQL, and Replit's own guide moves it with `pg_dump` and `pg_restore`.

### Has to be set up again

 - Secrets. Replit's docs say secret values never leave the project, so keys are copied by hand or issued again, and they go into the cloud, not the code.
- Sign-in. Replit Auth signs users in with a Replit account. The platform takes over sign-in: a company account for colleagues, a password for outside people.
- Files in App Storage. Buckets don't move; the files are downloaded and uploaded to storage in your account.
- Connectors to other services, and your custom domain, which gets pointed at the new app.
- Agent history and checkpoints stay on Replit. Commits made at checkpoints come along in the Git history.
     Checked 28 September 2026 [Replit docs: copying a project by hand ↗](https://docs.replit.com/teams/identity-and-access-management/manually-copy-projects)[Replit docs: Auth ↗](https://docs.replit.com/learn/projects-and-artifacts/auth)    ~380,000
publicly reachable apps built with Lovable, Replit, Base44 and Netlify were found by the security firm RedAccess. Around 5,000 of them held sensitive company or personal data, often with no sign-in at all.
  [Security Boulevard, 2026 ↗](https://securityboulevard.com/2026/05/thousands-of-vibe-coded-apps-exposing-corporate-personal-data-redaccess/)
### Try it yourself

Open your app's replit.app address in a private browser window. Whatever you can see without signing in, anyone can see.

## How does an app get from Replit *into production?*

The Replit app keeps running until the new home is ready and tried out. How long it takes depends mostly on the data and on what the app uses from Replit; the offer says exactly.

 1. 01
### Scoping call

You show us the app and tell us who uses it. We check what it relies on from Replit: the database, Replit Auth or Clerk, App Storage, connectors. Within a few days you get an offer with the scope, the timeline and the price.
 free · 30 min
1. 02
### Code to your GitHub

In Replit's Git pane you connect a private GitHub repository, ideally in your company's organisation, and push. If you don't use Git, download the project as a ZIP and we'll put it into Git. We need access to the repository, not to your Replit account.
 you, in a few clicks
1. 03
### We go through the code

Keys pasted into the code or committed by accident, sign-in, database queries, what runs on the server and where the app sends data. We go through what we find with you.
 part of the takeover
1. 04
### Small changes

The platform takes over sign-in from Replit Auth. Keys move into the cloud. Replit's run and publish settings are replaced by a deployment into your account. Screens and logic stay as they are.
 part of the takeover
1. 05
### A test copy of the data

We copy the database first as a test, so the new version can be tried with real data while the Replit app keeps running.
 part of the takeover
1. 06
### Deployment into your account

We set up Fabrika in a cloud account registered to your company, on Cloudflare or Zerops, or AWS by arrangement, and deploy the app. It has no public address; the only way in leads through the platform. Test and production are separate.
 one-off
1. 07
### Switch-over and unpublishing

On an agreed day you unpublish the app on Replit, we make the final copy of the data and point your domain at the new app. From then on every change goes live only after our review, and each version comes with a report of what we checked.
 from go-live · monthly

### What we look at in the repository
    `.replit` How Replit runs and publishes the app. Replaced by the deployment into your account.  `replit.nix` System packages, if the app has any. We carry over what it needs.  `.gitignore` Keeps secrets, database dumps and Replit's .cache folder out of the repository.  `DATABASE_URL` Where the app connects to its database. Pointed at the database in your account.  `package.json` Or requirements.txt. Dependencies, and whether they install cleanly outside Replit.  `the rest of the code` Screens and logic. Stay as they are, apart from sign-in.    The exact list depends on the app and its language. This is where we start.
## When is Replit Pro *or Enterprise enough?*

Replit answers some of these questions itself, and it's worth knowing how before you call us. The former Teams plan has been replaced by Replit Pro.

### What Replit offers

 - **Pro and Enterprise**: access controls on a published app, so it doesn't have to be open to everyone.
- **Enterprise**: SAML single sign-on and SCIM provisioning from your identity provider, with roles mapped to your groups.
- **Enterprise**: admins can require private deployments or ban public apps, require security scans before publishing, and require every change to be pushed to Git first.
- **Enterprise**: audit logs streamed to your SIEM, and a choice of deployment geography including the EU. Otherwise published apps run on Google Cloud in the US.
- **Enterprise** is bought as an annual credit commitment or pay-as-you-go.
   Checked in Replit's docs on 28 September 2026. [Publishing ↗](https://docs.replit.com/learn/projects-and-artifacts/replit-deployments)[Replit Enterprise ↗](https://docs.replit.com/billing/plans/replit-enterprise)[Privacy and deployment settings ↗](https://docs.replit.com/teams/privacy-and-deployment-settings)[Source control settings ↗](https://docs.replit.com/teams/enterprise-privacy-settings)[Pro replaced Teams ↗](https://docs.replit.com/billing/teams-billing/overview)
### Replit is the better fit when

 - your people build and run everything inside Replit and want to keep it that way;
- your company signs in through SAML and IT wants to manage builders from its identity provider;
- automated scans and publishing policies are enough, without a person reviewing each change.

### Fabrika is the better fit when

 - the app should run in a cloud account registered to your company, outside the tool it was built in;
- you want a person to review every change before it goes live, and someone who answers for running it;
- apps come from different places (Claude Code, Cursor, Lovable, a developer or an agency) and you want one place where they all run by the same rules.

## When isn't Fabrika for you?

We'd rather say it up front than at the end of a call.

 - The app is a public service for thousands of customers, with payments and sign-up open to anyone on the internet. Fabrika is built for company apps used by your people and a few outsiders.
- A handful of people use the app, nothing important depends on it, and restricting access to the published app on Replit Pro is enough.
- You want to keep building and publishing only inside Replit. Then Replit Enterprise is the more natural fit.
- Your IT requires Azure, Google Cloud or your own servers behind a firewall, or SAML-only sign-in. Fabrika runs on Cloudflare or Zerops, or AWS by arrangement, and connects company accounts through OIDC (Google, Microsoft, Okta).
- You only want the code checked once and will run the app yourselves. Then a one-off audit is the cheaper route.

## Can we keep building on Replit afterwards?

Honestly: it isn't a standard route yet. Replit can push to and pull from a GitHub repository, so technically the road is there. But the Replit preview runs at Replit, outside the platform, and sign-in no longer goes through Replit. Ask us and we'll look at your app.

### What works for certain today

You carry on in Claude Code, Cursor or Codex, or we keep developing the app for you. Wherever a change is made, it goes live only through our review.

## What people ask about Replit apps
 ![](/illustrations/spot-gatehouse.webp)
### Is there a way to protect the myapp.replit.app url?

On Replit, the Pro and Enterprise plans can restrict access to a published app, and Enterprise can require private deployments. On Fabrika the app has no public address at all; the only way in is the platform's sign-in. Once the move is done, you unpublish the replit.app copy so nothing keeps running outside review.

### How do I export my entire Replit app outside Replit?

The code through the Git pane into a GitHub repository, or as a ZIP (Download as zip in the file tree). The database with `pg_dump`. Secrets don't leave Replit, so they're copied or issued again by hand, and files in App Storage are downloaded separately. Replit describes all of this in [its own guide](https://docs.replit.com/teams/identity-and-access-management/manually-copy-projects); we do it with you.

### Can you deploy it behind our firewall?

Not onto your own servers. We deploy into your company's own cloud account on Cloudflare or Zerops, or AWS by arrangement, and the app is reachable only through sign-in with your company account. If your security team needs the app on your own hardware, we're not the right fit.

### Do our users need a Replit account?

No. Colleagues sign in with their company Google, Microsoft or Okta account, and multi-factor sign-in follows your company's settings for that account. Outside people, such as suppliers or clients, sign in with a password. Roles are set per app in one place.

### Our data is in Replit's database. Does it come with us?

Yes. It's PostgreSQL, so it moves with the standard tools. We make a test copy first, so the new version can be tried with real data, and the final copy on switch-over day, once nobody writes to the Replit app any more.

### Does the Replit app keep running while you work on it?

Yes, until switch-over day. Unpublishing on Replit doesn't delete the project, so if something went wrong on that day, the old app could be published again as it was.

### Where will the data live?

Replit publishes apps on Google Cloud in the US; Enterprise customers can choose another region, including the EU. On Fabrika the data sits in a cloud account registered to your company, so we are your only supplier. If you need the data in the Czech Republic, Zerops is a Czech company with a data centre in Prague.

### What will running it cost, compared to our Replit bill?

Three parts. You pay the cloud provider directly for the servers, by actual usage. The takeover is a one-off. Then there's a monthly fee for operations and review, based on the number of apps, never per user or per hour. The AI your people build with runs on your company's own AI plan. You get the figures in the offer after the scoping call.

### Who looks after the app when the person who built it leaves?

The repository is in your company, not on their account, and we handle operations and change review. A colleague, a developer or we can carry on with it. Access goes with the company account: once it's closed, that person can't sign in through the platform.

### A colleague brought us the app and IT is supposed to deploy it. Where do we start?

With the scoping call, ideally with both of you on it. For IT we've written up what the platform handles, how a change gets into production and the answers to a typical security questionnaire: [Security](/security).
          ![](/illustrations/cta-crane.webp)
## Show us your *Replit app*.

Half an hour and a link to the app or the repository is enough. We'll tell you what the move involves, what happens to the database and sign-in, and whether it makes sense for you at all. If it doesn't, we'll say so plainly.
  [Book a 30-min call →](https://cal.com/contember/demo) [Taking over AI-built apps in general →](/already-building)