Coding Agent Cloud How it works Pricing For agencies About us Contact Careers Blog Login Start your coding agent

Guide

The Production Readiness Checklist for Vibe-Coded Apps

A 25 item checklist to take a vibe coded app from "works in the builder" to "real users can rely on it". Pragmatic, tool agnostic, written so a non technical founder can use it on a Lovable, Bolt, Cursor or Claude Code app.

How to use this checklist

Print it. Walk through it before you flip your DNS to production. Each item has a why and a how. If you cannot tick a box, that is the work to do, not a reason to skip it.

Security (10 items)

  1. All secrets in environment variables. Search your code for keys starting with sk_, AIza, eyJ. Move every match to env vars on your hosting platform.
  2. Row Level Security on every table with user data. Supabase: open the Authentication policies, set per table.
  3. Auth check on every server side route. No /api/admin reachable without a session.
  4. Rate limiting on auth and AI endpoints. Cloudflare or platform built in.
  5. Input validation with a library. Zod, Joi, Yup. Never trust user input.
  6. HTTPS only. No mixed content. SSL provisioned and tested.
  7. CSP headers configured. At minimum a default src directive.
  8. Dependencies scanned. Run npm audit or Snyk. Resolve criticals.
  9. Password policy. Minimum length, blocked against breached password lists.
  10. 2FA available. Even if optional. Stripe and many auth providers add this in minutes.

Performance (5 items)

  1. Lighthouse score above 80 on mobile. Free check at PageSpeed Insights.
  2. Bundle size under 300kb gzipped. Bigger means slow phones bounce.
  3. Database indexes on commonly queried columns. Not just primary keys.
  4. Image optimisation. Use WebP or AVIF, lazy load offscreen images.
  5. CDN for static assets. Vercel and Netlify do this default. Roll your own if you self host.

Reliability (5 items)

  1. Automatic database backups. Daily minimum. Test a restore once.
  2. Error monitoring. Sentry, Bugsnag or equivalent. Email alert on new error types.
  3. Uptime monitoring. BetterUptime or UptimeRobot. Alerts you within a minute of downtime.
  4. Rollback path. Can return to previous release within five minutes.
  5. Health check endpoint. /health that returns 200 if app and database are reachable.

Compliance and legal (5 items)

  1. Privacy policy published. Required in most jurisdictions if you collect any user data.
  2. Cookie consent if EU. Otherwise GDPR fine territory.
  3. Terms of service. Liability protection.
  4. Data retention policy. Especially for GDPR right to erasure.
  5. Subprocessor list. Public list of third party services that touch user data.

Cannot tick all 25? That is normal for a first launch. The first 10 (security) are non negotiable. The rest can be added in week one or two of being live. A managed deployment service typically handles 20 of these by default.

Frequently asked questions

Do I need every item before launch?

Security items 1 to 10 yes. The rest can be addressed in the first weeks live. Privacy policy and cookie consent are legally required if you collect any data.

What if I do not understand an item?

Either learn it or hire someone who knows. The checklist is the bare minimum for production, not a nice to have.

Ready to ship your app?

Ployed handles deployment, security and monitoring. A real engineer reviews every release. You keep building in the canvas editor.

Start your project