How to use this checklist
Print it. Walk through it before you flip your DNS to production. Each item has a why and a how. If you cannot tick a box, that is the work to do, not a reason to skip it.
Security (10 items)
- All secrets in environment variables. Search your code for keys starting with
sk_,AIza,eyJ. Move every match to env vars on your hosting platform. - Row Level Security on every table with user data. Supabase: open the Authentication policies, set per table.
- Auth check on every server side route. No
/api/adminreachable without a session. - Rate limiting on auth and AI endpoints. Cloudflare or platform built in.
- Input validation with a library. Zod, Joi, Yup. Never trust user input.
- HTTPS only. No mixed content. SSL provisioned and tested.
- CSP headers configured. At minimum a default src directive.
- Dependencies scanned. Run
npm auditor Snyk. Resolve criticals. - Password policy. Minimum length, blocked against breached password lists.
- 2FA available. Even if optional. Stripe and many auth providers add this in minutes.
Performance (5 items)
- Lighthouse score above 80 on mobile. Free check at PageSpeed Insights.
- Bundle size under 300kb gzipped. Bigger means slow phones bounce.
- Database indexes on commonly queried columns. Not just primary keys.
- Image optimisation. Use WebP or AVIF, lazy load offscreen images.
- CDN for static assets. Vercel and Netlify do this default. Roll your own if you self host.
Reliability (5 items)
- Automatic database backups. Daily minimum. Test a restore once.
- Error monitoring. Sentry, Bugsnag or equivalent. Email alert on new error types.
- Uptime monitoring. BetterUptime or UptimeRobot. Alerts you within a minute of downtime.
- Rollback path. Can return to previous release within five minutes.
- Health check endpoint.
/healththat returns 200 if app and database are reachable.
Compliance and legal (5 items)
- Privacy policy published. Required in most jurisdictions if you collect any user data.
- Cookie consent if EU. Otherwise GDPR fine territory.
- Terms of service. Liability protection.
- Data retention policy. Especially for GDPR right to erasure.
- Subprocessor list. Public list of third party services that touch user data.
Cannot tick all 25? That is normal for a first launch. The first 10 (security) are non negotiable. The rest can be added in week one or two of being live. A managed deployment service typically handles 20 of these by default.