Built your app with Lovable, Cursor, Bolt, Replit or similar? Answer 20 yes/no questions to see how ready it is for real users, real data and real payments. It takes about three minutes.

The questions come from the problems we fix most often when AI-built apps reach production: data visible to the wrong user, unverified payment webhooks, secrets in the browser and no way to roll back.

0 / 20 answered

Accounts and access

I tested with two separate accounts and confirmed neither can see the other’s data.Critical

Access rules are enforced on the server or in the database (for example Supabase row-level security), not only by hiding buttons in the interface.Critical

Admin and internal pages require a verified admin role checked on the server.Critical

Password reset, email verification and session expiry have been tested end to end.

Data and privacy

I know exactly which personal data the app stores and where it is hosted.

Users can export or delete their data, and deleting an account really removes it.

Backups exist and I have tested restoring one.Critical

Uploaded files are private unless they are meant to be public.Critical

Payments and subscriptions

Payment webhooks verify the provider’s signature.Critical

Paid access is granted from subscription events, not from the thank-you page.Critical

Webhook handlers are safe to run twice, so retries never double-grant or double-charge.

Failed payments, cancellations and refunds change the user’s access correctly.

Secrets and integrations

No API keys or secrets are in the front-end code or in a public repository.Critical

Test and live keys are separate, and live keys exist only on the server.Critical

Rate limits or spending caps protect paid services such as AI models, email and SMS.

Deployment and operations

Staging and production are separate environments.

Errors and downtime are monitored and someone is alerted.

I can roll back a bad release within minutes.

Dependencies are kept up to date and known vulnerabilities are checked.

A named person owns the app after launch (fixes, updates and incidents).

Your answers stay in your browser. Nothing is sent to us or stored.

How to read your score

The score weights critical items more heavily, because one open access hole matters more than a missing monitoring alert. Treat it as a to-do list, not a verdict.

Frequently asked questions

What does the AI App Health Check cover?

It covers the five areas where AI-built apps most often fail after launch: accounts and access, data and privacy, payments and subscriptions, secrets and integrations, and deployment and operations. Each question is a yes or no check you can verify yourself.

Is my data sent anywhere?

No. Your answers stay in your browser and are not sent to us or stored. We only record, anonymously, that a check was completed and the score band.

Does a high score mean my app is secure?

No. It is a self-assessment, so it shows what you believe is in place, not what is actually true. A high score means the basics are covered on paper; an independent technical audit is the way to confirm it before real customers and payments are involved.

AI app technical audit · AI app repair and launch · Production readiness checklist