The production readiness checklist we use.
The same twelve domains we score in an audit. Run it on your own app before you talk to anyone, including us. Three questions per domain; a "no" is a finding.
Show this list in
Architecture
- Could someone sketch how the whole app fits together on a single sheet of paper?
- Is it clear which part shows the screens, which part does the work and which part stores the information?
- Is the same rule, such as how a price is worked out, written in more than one place, so fixing one copy leaves the others wrong?
Authentication
- Do people get logged out after a while, and can you log someone out remotely if their account is at risk?
- Is login handled by a well-known service rather than something written from scratch for your app?
- Can someone who forgot their password get back in on their own, without that route letting a stranger in?
Authorisation
- Could one customer see or change another customer's information by changing a number in the address bar?
- Does the server check who is asking every time data is read or changed, not only the screen?
- Are the powerful admin controls locked away from ordinary users?
Data
- When the structure of your database changes, is each change recorded so it can be repeated or undone?
- Are copies of your data made automatically, and has anyone actually restored one in the last three months?
- Does the server reject bad or malicious information, even if someone bypasses the form?
Security
- Are your passwords and keys kept out of the code that visitors download and out of the code you store?
- Are the outside building blocks your app uses fixed to known versions and checked for known security problems?
- Is there a limit on how fast someone can try passwords or trigger things that cost you money?
Reliability
- If a service you depend on, such as payments or email, is slow or down, does the rest of the app keep working?
- If the app tries something twice after a failure, can it be sure it will not charge or send twice?
- If two people buy the last item or book the same slot at the same moment, does the app handle it correctly?
Testing
- Would something warn you automatically if paying or signing up stopped working?
- Do those checks run by themselves every time the code changes?
- Are the checks focused on the parts where money changes hands or customer data is handled?
Performance
- Has anyone looked at the slowest things your app asks the database to do?
- Has anyone checked that pages do not ask the database hundreds of small questions where one would do?
- If ten times as many people used it tomorrow, would it slow down a little or stop working?
AI features
- Is there a set of test questions with known good answers that the AI's output is checked against?
- Is there a plan for when the AI gives a wrong answer or stops responding?
- Does a person approve anything the AI does that cannot be taken back?
Observability
- When something goes wrong for a user, is it recorded and does someone get told?
- Do you know how long each AI request takes and what it costs?
- If a customer complained about a problem at a specific time, could you find out what happened within five minutes?
Deployment
- If an update breaks something, can you go back to the previous version with one action?
- Is there a separate test copy of the app, with its own keys, so experiments never touch real customers?
- Does every update go through the same automatic checks before it reaches customers?
Cost
- Do you know what each customer costs you each month in hosting and AI?
- Will you be warned, or will spending stop, before a bill gets out of hand?
- If something went wrong overnight and repeated itself, would it cost you $50 or $50,000?
Production Readiness Audit
Sample audit, illustrative. Not a client.
App: SaaS built with Lovable, Next.js and Supabase
| Domain | Score | Finding |
|---|---|---|
| ArchitectureBoundaries clear; business logic duplicated in three routes | 6/10, warning | Boundaries clear; business logic duplicated in three routes |
| AuthenticationProvider-managed sessions; no revocation on password change | 7/10, pass | Provider-managed sessions; no revocation on password change |
| AuthorisationRow-level security disabled on 3 of 9 tables | 2/10, fail | Row-level security disabled on 3 of 9 tables |
| DataNo migrations; backups never restored | 4/10, warning | No migrations; backups never restored |
| SecurityService-role key present in client bundle | 3/10, fail | Service-role key present in client bundle |
| ReliabilityThird-party timeouts unhandled; retries not idempotent | 5/10, warning | Third-party timeouts unhandled; retries not idempotent |
| TestingNo automated tests; checkout untested | 1/10, fail | No automated tests; checkout untested |
| PerformanceTwo N+1 queries on the dashboard | 6/10, warning | Two N+1 queries on the dashboard |
| AI featuresNo evaluation set; no fallback when the model fails | 4/10, warning | No evaluation set; no fallback when the model fails |
| ObservabilityErrors not captured; AI cost not tracked | 2/10, fail | Errors not captured; AI cost not tracked |
| DeploymentManual deploys; no rollback | 5/10, warning | Manual deploys; no rollback |
| CostNo spend caps on model API | 5/10, warning | No spend caps on model API |
42 / 100. Not production-ready. Nine findings blocking launch, three advisory.
Want us to run it?
A Production Readiness Audit scores all twelve domains, ranks every finding and comes with a fixed-price plan to fix them. $1,500, five working days, half credited if you proceed.