Skip go di main content

Your AI-built app don ready for real users?

Di Plutonapps production-ready check dey score app wey you build with Lovable or any AI builder over 100, inside like three minutes. Answer 19 questions on security, data, releases, monitoring, payments, privacy and ownership, and see di three risks wey you go fix first. E free, and your answers go stay for dis page unless you ask for di full report by email.

Di questions

Security and access

Who fit sign in, and wetin di database allow each of dem read.

1.How people dey sign in to your app?

Sign-in na authentication: to prove who person be.

2.Multi-factor authentication dey on for every account wey fit change production — Supabase, hosting, GitHub, Stripe, your domain?

One password wey dem phish for any of these na way to enter everything.

3.Row-level security dey on for every table wey hold user data, with policies wey you don test as second user?

RLS na wetin dey stop one signed-in user from reading another person rows through your public API.

4.Where your Supabase service-role (secret) key dey?

Di service-role key dey skip row-level security completely.

5.Where you dey keep your other secrets — Stripe secret key, email and AI API keys?

Secret wey enter Git repository go stay for im history even after you delete am.

Data safety

Whether your data go survive bad deploy, bad prompt or bad day.

6.If bad change wipe one table by 3pm, wetin you fit restore?

Daily backups dey lose everything since di last one; point-in-time recovery no dey lose am.

7.You don restore backup inside separate project to prove say e dey work?

Backup wey nobody don restore na hope, no be plan.

8.How database changes dey reach production?

Migration na SQL file wey get version, wey dem dey apply di same way everywhere.

Releases and testing

How we dey check change before your users see am.

9.Staging environment dey, with im own database, where you dey check changes first?

Staging na private copy of production where you dey try each release before e go live.

10.Automated tests dey cover your main flows — sign-up, payment and di main thing wey your app dey do?

Regression tests dey catch di feature wey you no touch wey break because of di one wey you touch.

11.How code dey reach production?

CI/CD dey run di same checks on every change and dey deploy only wetin pass.

Running am live

To know say e don break before your users tell you, and wetin go happen next.

12.If di app break for users right now, how you go take know?

Observability na to know wetin di running system dey do, from im logs, metrics and errors.

13.Sign-up, login and anything wey dey send email or call paid API (like AI model) get rate limit?

Without limit, one script fit run up your bill or lock your users out.

14.If production go down tonight, person wey get name and written plan dey?

Incident response na to decide before e happen who go act and how.

Payments

To collect money without holding card data or trusting di browser.

15.How your app dey collect payments?

Who dey hold di card details dey decide how much compliance work go land on you.

16.You dey check incoming webhooks by signature, and e safe to receive dem two times?

Providers dey retry webhooks, so di same event fit land more than once.

Privacy and compliance

Di GDPR basics and record of who change wetin.

17.You get di GDPR basics: privacy policy wey name your providers, data processing agreement with each one, and way to delete user data when dem ask?

If you get users for EU or UK, these ones na legal duty, no be extra.

18.You fit tell who change wetin for your admin area, and when?

Audit log na record of important actions wey you fit only add to.

Ownership

Whether di app na your own to move, hand over and keep running.

19.Di code dey inside Git repository wey you own, and another team fit deploy am without di person wey build am?

If na only one tool or one person fit ship am, you don lock inside.

0 out of 19 don answer

How di score dey work

Every question get fixed weight, and all di weights add up to 100. Your answer fit earn all, part or none of am; “I no sure” no dey earn anything. Question wey no concern your app, we go leave am out and scale di rest back to 100. Any critical gap go hold di score for 49. Di rules na di same for your browser and for our server, and no AI dey inside am.

Di weight of each area, over 100
AreaQuestionsWeight
Security and access525
Data safety320
Releases and testing315
Running am live315
Payments210
Privacy and compliance210
Ownership15

Bands: 90 and above don ready for production, 75 to 89 e don almost reach, 50 to 74 e still need work, under 50 e never ready. Wetin each term mean dey inside our glossary.

Questions about di check

Wetin di production-ready check dey measure?

19 questions across seven areas wey dey decide whether app safe for real users: security and access, data safety, releases and testing, running am live, payments, privacy and compliance, and ownership. We dey score each answer against fixed weight, and di areas add up to 100.

How dem dey calculate di score?

Every question carry weight, and di weights add up to 100. Your answer fit earn all, part or none of dat weight. "I no sure" no dey earn anything, because if you no fit talk say e don done, di safe thing na to assume say e never done. Question wey no concern your app, like payments when you no dey collect money, we go leave am out and scale di rest back to 100. Critical gap, like service-role key wey dey inside di browser, go hold di score for 49. Di same rules dey run for our server, and no AI dey inside.

Which score mean say app don ready for production?

90 or more don ready for production, 75 to 89 e don almost reach, 50 to 74 e need work before launch, and under 50 e never ready for real users. Any one critical gap go hold app under 50, no matter wetin else dey.

Una dey store my answers?

No, unless you ask for di report by email. Na your browser dey calculate di score. If you ask for di report, we go store your email, di name and app address wey you give, your answers, your score, whether you tick di box for updates, di campaign tags for di link and di page wey send you come (none of di two if your browser dey send Do Not Track or Global Privacy Control), and one-way hash of your IP address, for 24 months. We go send di report once and tell our team. We go only send you anything else if you tick di box. We no dey ever visit or scan your app address.

Na only for apps wey dem build with Lovable?

No. E dey work for any app wey dem build with AI app builder like Lovable, Bolt, v0 or Replit, or wey dem build by hand. Some questions mention Supabase because most AI-built apps dey run on am, but di same checks apply to any app wey get database, sign-in and payments.

Wetin I go fix first?

Start with di three risks wey di check show you. Critical gaps first, then di answers wey lose di most points. Each one get link to simple English definition for our glossary. If you prefer make engineers fix dem, na wetin Plutonapps plan dey do.

You prefer make engineers fix am for you?

You go continue to design for Lovable. Plutonapps engineers go make di real product secure, tested and ready for production, as subscription.

See di plans