Free self-check
Is your prototype ready for real users?
Ten questions for anyone who built an app with AI tools, a no-code platform or a quick MVP. One minute. You get a score, the gaps that matter most, and what to do about each one.
- A scoreOut of 100, with what it means for you.
- Your checklistWhat is in place, what is partly there, what is missing.
- What to doA fix for each gap, with steps to check it yourself.
- A report to shareBy email if you want it, ready to forward to your team.
Your result
0/100
Ready for real users
The basics that keep an app safe and running are in place. The next step is keeping them true as the app grows: tests on every change, alerts that reach a person, and limits that grow with use.
Close, with risky gaps
It works, but some of the basics are missing. Each gap below is a way real users, real data or a real bill can hurt you. Fix them in order: the first ones protect your users’ data and your money.
Still a prototype
Several basics are missing, so the app can lose data, leak it or fail without anyone noticing. Start with the first item below. Most of these fixes don’t need a rewrite.
Where to start
- Does every user have to log in, and can each one see only their own data?
Check access on the server for every page and every request, not just by hiding buttons. Then try it: log in as one user and open another user’s record. If it opens, fix that before anything else.
Read: One system, many customers: proving their data stays apart
- Are your passwords and API keys kept out of the code, each with only the access it needs?
Move every key into your hosting platform’s secret settings, replace any key that was ever in the code, and give each key only the permissions it needs.
- Is your data backed up automatically, and have you ever restored a backup to check it works?
Turn on automatic daily backups of your database and uploaded files, keep a copy somewhere separate, and practice a restore into a test copy. Write the steps down.
Read: Limit the blast radius: decide what a failure is allowed to break
- Do you know what personal data you store, who can see it and where it goes, including to AI tools?
List the personal data you keep and why, delete what you don’t need, keep it out of your logs, and send an AI provider only what the task really needs.
- When something fails, like a payment, an email or an outside service, does the app tell the user and keep their work?
Decide what each important action does when it fails: show a clear message, keep what the user typed, retry where it’s safe, and record the error so someone can look at it.
Read: Production: what a prototype skips and a real system can’t
- Are there spending limits and alerts on your AI provider, hosting and other paid services?
Set a monthly budget and an alert on every paid service, add per-user limits on AI features, and know what one typical use of your app costs you.
Read: The cost of an AI feature: tokens, caching and the right model per task
- Do automated tests check your most important paths before every release?
Write automated tests for the few paths your users depend on most, run them on every change, and block a release when one fails.
- If the app breaks at 2 a.m., will someone know before your users tell you?
Add error tracking, an uptime check that alerts a named person, and logs that let you follow what happened to a given user or request.
Read: Observability for AI features: what to log, trace and watch
- Could another developer understand and safely change your app without the person who built it?
Write a one-page guide: how to run it, test it and deploy it, where the important parts are, and why the key decisions were made. Then clean up the parts nobody understands.
- Are the code, the domain, the hosting and the AI accounts in your company’s name, with you as an owner?
Move every account into your company’s name with at least two owners, and keep one list of what exists and who has access.
No gaps on this list. Your app is in good shape for real users.
Want an engineer to look at it?
Send your result to an engineer and get a reply with what we would check first in your app. Free, with no obligation.
Built from real projects
Every question comes from what we have seen go right, and wrong, on real work. See it in practice:
SuperEscuela: A Free School Built and Written with AI →Questions
- Is it really free?
- Yes. The result appears on the page, and nothing is asked of you to see it.
- What happens to my answers?
- They are scored in your browser. We only receive them if you choose to send them to an engineer or ask for the report by email. See our privacy policy.
- Will you add me to a newsletter?
- No. If you ask for the report, we send that one email. We only write again if you reply.
- Who is behind it?
- EVDevs: experienced engineers working with AI on revenue, data and AI systems. About us.