nommiopen nommi

← back to resources

vibe-coder

Is my AI-built app safe to launch? A ten-minute check

the short answer

Before you launch an app built with AI (artificial intelligence), you can catch several common launch mistakes in about ten minutes. Check six things. Secret keys are hidden from visitors, login works, and users cannot see each other's data. You have a backup, a test payment works, and you have a privacy policy. This is a starting check, not a security audit. If you hold sensitive data, get an expert review.

In short

  • Answer: Run six quick checks before launch; they catch common mistakes but do not replace a security audit.
  • Check these three things: no secret keys in browser code; one user cannot see another's data; you have a backup you can restore.
  • Watch out: health, money or children's data needs a proper review by a security expert, not just this list.
  • Do this next: make two test accounts and try to open one account's data while logged in as the other.
  • Last reviewed: 6 October 2026.

Why check at all if the builder made it?

Because a builder makes what you asked for, and you may not have asked for security. An app can look finished and still let one user see another user's data.

The first-ranked web app risk in the OWASP Top 10:2025, a standard awareness list from the Open Worldwide Application Security Project, is broken access control. That means people can reach data or actions they should not have permission for (OWASP Top 10:2025, A01 Broken Access Control, checked 6 October 2026). Check 3 below is aimed at exactly that.

Check 1: are my secret keys hidden? (2 minutes)

An API (application programming interface) key is a secret password that lets your app use another service, such as payments or an AI service. Anyone who copies it can use that service as you, and you may pay for it.

  • Keys belong in settings stored on your hosting, often called environment variables, not in the code that loads in a visitor's browser.
  • Ask your builder: is any key visible in the code that runs in the browser?
  • If a key was ever visible, replace it with a new one in that service's settings. Hiding it later is not enough.

Check 2: does login work properly? (2 minutes)

Authentication is how your app checks who someone is. On the live app, not your laptop:

  • Sign up with a fresh email address, log out, then log back in.
  • Reset the password and make sure the email arrives.
  • Log out, then paste a private page's address into the browser. You should be sent to the login page.

Check 3: can users see each other's data? (3 minutes)

This is the most important check. Make two test accounts, A and B.

  • In account A, create something private, such as a note or an order.
  • Copy the address of that page.
  • Log in as B in a private browser window and open that address. If B can see A's data, stop and fix it before launch.

If your app's addresses include a number, such as an order number, try changing it by one while logged in as B. In our reading, that is a common way private data leaks.

Check 4: do I have a backup? (1 minute)

Find out whether your database makes backups and how to restore one. A backup you have never restored is a hope, not a backup. If your service offers automatic backups, turn them on.

Check 5: does a test payment work? (1 minute)

If you take money, use your payment service's test mode to make one test purchase. Check that the user gets access only after the payment succeeds. Then cancel or refund it, and check that access ends if it should.

Check 6: do I have a privacy policy? (1 minute)

If you collect emails or any personal data, you need to tell people what you collect and why. Depending on where you and your users are, privacy laws may require it. Write a plain privacy policy page and link it from your sign-up form. This is educational, not legal advice.

What does this check not cover?

A lot. It does not test for attacks a skilled person would try, the code libraries your app depends on, or how your app behaves under heavy use. That is what a security audit by an expert is for.

The strongest case against launching after only this check: if you hold health records, financial details or children's data, a leak can seriously harm people. The missing fact is what data you hold. If it is sensitive, pay for an expert review before launch.

What else should I check before I launch?

Make sure the app actually works live, not just on your laptop: why your app works on your laptop but not for friends. For everything beyond safety, what you might be forgetting before launch covers the rest.

Your next move this week

Block ten minutes and run the six checks on your live app, in order. Write down every check that fails. Fix check 3 first if it failed, then check 1, before you invite anyone new.