Free tool · runs in your browser

Your AI-built app works. Is it ready for real users?

Lovable, Bolt, Cursor and the rest get you working screens fast. What they don't do unprompted is lock the database, keep keys off the browser, limit abuse and set up backups. Seventeen checks, each with the reason behind it. Answer yes, no or not applicable, then print the result or send it to whoever built the app.

Your answers are saved in this browser only. Nothing is sent to us.

– 0/17 answered
Answer each check to get a score.

Who can see what

Every database table has an access rule (row-level security or the equivalent). · must fix

If the browser talks to the database directly (Supabase, Firebase and similar), the screens are not what keeps data private: the rules are. Test it: sign in as user A and change an ID in the request to load user B's record. If it loads, anyone can.

Admin pages and admin API routes check an admin role on the server. · must fix

Hiding the admin menu is not protection. Call the admin endpoint while signed in as a normal user; it should refuse.

Uploaded files are private unless they're meant to be public. · fix soon

Storage buckets created during a prototype are often public-read. Invoices, ID photos and exports should need a signed, expiring link.

Keys and secrets

No secret key is in the browser code or the repository. · must fix

Search the code and the built JavaScript for payment, email and AI keys. Anything that can spend money or send mail belongs on a server, read from an environment variable.

Any key that was ever committed or pasted into a chat has been rotated. · fix soon

Removing it from the code doesn't remove it from the git history. Treat it as public: make a new one, then delete the old one.

AI and cloud accounts have a spending limit and a billing alert. · fix soon

A leaked key or a loop in your own code can run up a four-figure bill overnight. A limit at the provider is the last line of defence.

The server checks what the screen checks

Every action that changes data is checked on the server: signed in, owns the record, sensible values. · must fix

AI-written code often validates the form and trusts the request. Anyone can send a request without your form.

Error messages shown to users don't include stack traces, SQL or internal paths. · fix soon

Detailed errors are a map for whoever is probing the app. Log the detail; show a plain message.

Limits and abuse

Sign-up, sign-in, password reset and contact forms are rate-limited. · fix soon

Without a limit, a script can send thousands of emails in your name or try stolen passwords against every account.

Features that call an AI model have a per-user limit. · fix soon

Each call costs you money. A free account that can run unlimited requests is an open tab.

Payment webhooks verify the signature and fulfil only the order they belong to. · fix soon

An unverified or replayed webhook can hand out credits or access without a payment. Mark N/A if you don't take payments.

Backups and recovery

Daily backups are on, and you've restored one into a scratch database. · must fix

A backup that has never been restored is a hope. Restoring once tells you it works and how long it takes.

You get an alert when the app is down or errors spike. · good practice

Otherwise the first alert is a customer's email. A free uptime check and error tracking take an hour to set up.

Ownership

The code is in a repository your company controls, and more than one person can deploy it. · fix soon

If the only copy is in one person's builder account, the app leaves when they do.

You know how you'd move if the builder platform changed its price or shut down. · good practice

Export the code and the database once, and check you could run them somewhere else.

Users and the law

A privacy policy and terms that match what the app collects, and a way to delete an account. · fix soon

Required by the app stores and by privacy laws in most markets, and the first thing a careful customer looks for.

Your sending domain has SPF, DKIM and DMARC set up. · good practice

Without them, sign-in codes and receipts land in spam, and support tickets about "I never got the email" follow.

Where this list comes from

Scans of apps built with AI tools keep finding the same gaps: tables anyone can read with the public key, secrets in the browser, no limits on sign-up or reset emails. We went through the research in your AI-built prototype works: check these six things, and about internal tools that teams now build instead of buying in buy, build or prompt.

Shipping a mobile app? The store-ready check covers the links App Store and Google Play reviewers look for, and AppBro sets up the privacy, terms, support and delete-account pages for you.

A checklist, not a security audit. More free tools: biz59.net/tools.