Go-Live Check

A security check for apps built with Lovable, Bolt, Replit or Claude Code.

Before real customers trust your app with their data and their money, I go through it the way a home inspector goes through a house — and give you a plain-English list of what to fix first.

  • You run a business, and the app you built with AI now handles real customers.
  • You’re about to launch, or about to start taking payments.
  • You’re not a developer, and you want a straight answer — not a 60-page PDF.

The checklist

What I check, room by room.

These are the problems I see most often in apps built with AI tools. Each one is checked by hand, not just by a scanner.

1

Customer data

“files out the window”

Can one customer see another’s details — or can a stranger see everyone’s?

  • Database access rules (Supabase RLS) on every tableThe most common leak in Lovable and Bolt apps.
  • Firebase security rules, if your app uses Firebase
  • File storage: are uploaded photos and documents public?
  • What your app’s API returns to someone who isn’t logged in
2

Logins & admin pages

“the back door is unlocked”

Are the private parts of your app really private?

  • Admin and staff pages checked on the server, not just hidden in the menu
  • Roles: can a normal user give themselves admin rights?
  • Sign-up, password reset and email links
3

Secret keys

“keys under the doormat”

Keys that anyone visiting your site can copy.

  • Supabase service_role key or other admin keys in the browser code
  • OpenAI, Stripe or email-service keys that can run up bills
  • Keys committed to GitHub history
4

Payments

“nobody checked the safe”

Does “paid” really mean paid?

  • Stripe webhooks verified, so payments can’t be faked
  • “Paid” status set by your server, never by the browser
  • Refunds, failed payments and cancelled subscriptions
5

Backups

“boxes in the basement”

If something gets deleted, can you get it back — today?

  • Backups switched on, and how far back they go
  • One real restore test on a copy of your data
6

When something breaks

“smoke alarm, no batteries”

Do you find out before your customers tell you?

  • Error alerts that reach you by email
  • A simple uptime check for your site
  • Basic security headers and HTTPS settings
+

Ease of use (UX)

“a front door that sticks”

A safe app can still frustrate people. Where do your customers get confused, annoyed or give up?

  • Can people book or buy before being forced to create an account?
  • Forms that work on a phone: the right keyboard, a show‑password button, clear error messages
  • Pages that load quickly on a phone
  • The first screen says clearly what you offer and what to do next
  • Anything else that gets in your customers’ way

What you get

A report you can actually read.

The report

Every finding: what’s wrong, why it matters to your business, how urgent it is.

The video

About 10 minutes, walking you through the findings on your own screens.

The fix list

Ranked and estimated, so you or any developer can start right away.

One follow-up

Questions by email for 14 days after the report.

See a sample report

What I need from you

  • Lovable / BoltInvite me to the project as a collaborator
  • GitHubRead access to the code, if there is a repo
  • Supabase / FirebaseA read-only or developer role
  • StripeA view-only team seat, if you take payments
  • A test loginOne normal user and, if you have one, one admin

Never your passwords. I only test apps you own, with your written go-ahead, and I don’t download your customers’ data. Remove my access the moment we’re done.

What this isn’t

  • Not a certified penetration test or a compliance audit (SOC 2, HIPAA, GDPR)
  • Not new features or a redesign
  • Not a review of native iOS or Android code
  • Bubble and Base44 apps: I can inspect and report, but fixes are limited

Bigger than ~20 screens? Tell me what you have and I’ll quote a fixed price before you pay anything.

How it works

Three business days. No calls.

1
Day 0

Order and invite

Pay the fixed price, fill in a short form about your app, and invite me as a collaborator.

2
Days 1–3

I inspect it

If I find something urgent — like customer data open to anyone — I tell you within 24 hours.

3
Day 3

Report and video

Fix it yourself, hand it to your developer, or upgrade to Check + Fix and I’ll do it.

How to order

Send me your app. That’s it.

Email me the link to your app and the tool you built it with. Within one business day I reply with a fixed quote, a secure payment link, and what to invite me to.

Email me your app

Reply within 1 business day · Pay only after you see the quote

Questions

Before you order.

Is my Lovable app secure by default?

Not always. Lovable and similar tools build working apps fast, but the database access rules (Supabase “RLS”) are often missing or too open. That means one customer — or a stranger — may be able to read other people’s data. Even a safe first version can break later: in my own test app, adding a “cleaner” role let a customer pose as a cleaner and see door codes.

How much of my time does this take?

About 15 minutes: a short form and a few invitations. Everything after that is written, and you get a video instead of a meeting.

What if you find something serious halfway through?

You hear about it within 24 hours, with a short note on how to close it quickly — you don’t have to wait for the full report.

Will you keep my app and data confidential?

Yes. I’m happy to sign a standard mutual NDA, and confidentiality is part of my terms anyway. I work on your project only through the access you give me, I don’t copy customer data, and I delete my notes on request after the job.

Can’t I just ask ChatGPT or Claude to check my app?

You can, and it’s worth trying. But the AI that wrote the problem is usually the one checking it — and it often answers “this looks secure” when it isn’t. I test your app from the outside, the way an attacker would, and I put my name under the result.

Can you fix the problems too?

Yes. Check + Fix (from $990, with a fixed quote once I’ve seen your app) includes fixing every critical and serious issue, re-testing, and setting up backups and error alerts. If you start with the $290 check, it’s credited in full when you upgrade within 14 days.

Find the holes
before your customers do.

$290 fixed. Report in three business days.

Start a Go-Live Check