Your AI-built app works. Is it ready for real users?
Lovable, Bolt, Cursor and the rest get you working screens fast. What they don't do unprompted is lock the database, keep keys off the browser, limit abuse and set up backups. Seventeen checks, each with the reason behind it. Answer yes, no or not applicable, then print the result or send it to whoever built the app.
Your answers are saved in this browser only. Nothing is sent to us.
Launch checklist from biz59.net/tools/launch-checklist · 2026-10-09
Who can see what
If the browser talks to the database directly (Supabase, Firebase and similar), the screens are not what keeps data private: the rules are. Test it: sign in as user A and change an ID in the request to load user B's record. If it loads, anyone can.
Hiding the admin menu is not protection. Call the admin endpoint while signed in as a normal user; it should refuse.
Storage buckets created during a prototype are often public-read. Invoices, ID photos and exports should need a signed, expiring link.
Keys and secrets
Search the code and the built JavaScript for payment, email and AI keys. Anything that can spend money or send mail belongs on a server, read from an environment variable.
Removing it from the code doesn't remove it from the git history. Treat it as public: make a new one, then delete the old one.
A leaked key or a loop in your own code can run up a four-figure bill overnight. A limit at the provider is the last line of defence.
The server checks what the screen checks
AI-written code often validates the form and trusts the request. Anyone can send a request without your form.
Detailed errors are a map for whoever is probing the app. Log the detail; show a plain message.
Limits and abuse
Without a limit, a script can send thousands of emails in your name or try stolen passwords against every account.
Each call costs you money. A free account that can run unlimited requests is an open tab.
An unverified or replayed webhook can hand out credits or access without a payment. Mark N/A if you don't take payments.
Backups and recovery
A backup that has never been restored is a hope. Restoring once tells you it works and how long it takes.
Otherwise the first alert is a customer's email. A free uptime check and error tracking take an hour to set up.
Ownership
If the only copy is in one person's builder account, the app leaves when they do.
Export the code and the database once, and check you could run them somewhere else.
Users and the law
Required by the app stores and by privacy laws in most markets, and the first thing a careful customer looks for.
Without them, sign-in codes and receipts land in spam, and support tickets about "I never got the email" follow.
Where this list comes from
Scans of apps built with AI tools keep finding the same gaps: tables anyone can read with the public key, secrets in the browser, no limits on sign-up or reset emails. We went through the research in your AI-built prototype works: check these six things, and about internal tools that teams now build instead of buying in buy, build or prompt.
Shipping a mobile app? The store-ready check covers the links App Store and Google Play reviewers look for, and AppBro sets up the privacy, terms, support and delete-account pages for you.
A checklist, not a security audit. More free tools: biz59.net/tools.