From AI prototype to production
Is your AI-built app ready for real users?
If an app handles accounts, personal data, payments or a critical business process, a successful demo is not enough. Before launch it needs verified permissions, data handling, secret management, failure states, backups, monitoring and infrastructure ownership.
1. Accounts and permissions
Testing a successful sign-in is insufficient. Try changing an address, identifier or API request to see whether one user can reach another user’s data.
Every role needs explicit permission. Administrative actions must not rely on a hidden interface button for protection.
2. Data, secrets and privacy
API secrets must not ship to the browser. You need to know where backups are made, who can access them and how the system is restored.
For personal data, document why it is stored, where it lives and how it can be exported or deleted.
3. Payments and external services
Payments can arrive twice, webhooks can be late or never arrive. Production logic must not fulfil the same order repeatedly.
Every integration needs a timeout, a failure path and traceability. A perfect demonstration is different from resilient operation.
4. Tests, monitoring and recovery
Critical journeys must be repeatable: registration, purchase, core data storage and restoration. Test the failures with the highest cost first.
Monitoring should reveal what failed, who was affected and when it began. A backup only becomes evidence after a successful restoration.
5. Ownership
The product owner should control the domain, repository, database, hosting and third-party accounts. A supplier may have access but must not be the only person capable of opening the system.
Handover includes access, deployment steps, essential documentation and the list of services requiring payment or renewal.
Frequently asked questions
Is AI-generated code automatically insecure?
No. Risk comes from missing review, architectural understanding and testing, not from AI use alone.
Must the whole prototype be rebuilt?
Not always. The interface and some functions may stay while permissions, the data layer or payments are replaced. An audit should decide.
When is an audit necessary?
Before using personal data, payments, private business data or serving many users, and before investor or developer handover.