Skip to content

Is your AI-built app ready for real users?

The Plutonapps production-readiness check scores an app built with Lovable or any AI builder out of 100, in about three minutes. Answer 19 questions on security, data, releases, monitoring, payments, privacy and ownership, and see the three risks to fix first. It is free, and your answers stay in this page unless you ask for the full report by email.

The questions

Security and access

Who can sign in, and what the database lets each of them read.

1.How do people sign in to your app?

Sign-in is authentication: proving who someone is.

2.Is multi-factor authentication on for every account that can change production — Supabase, hosting, GitHub, Stripe, your domain?

One phished password on any of these is a way into everything.

3.Is row-level security on for every table that holds user data, with policies you have tested as a second user?

RLS is what stops one signed-in user reading another's rows through your public API.

4.Where does your Supabase service-role (secret) key live?

The service-role key skips row-level security entirely.

5.Where are your other secrets kept — Stripe secret key, email and AI API keys?

A secret in a Git repository stays in its history even after you delete it.

Data safety

Whether your data survives a bad deploy, a bad prompt or a bad day.

6.If a bad change wiped a table at 3pm, what could you restore?

Daily backups lose everything since the last one; point-in-time recovery does not.

7.Have you restored a backup into a separate project to prove it works?

A backup nobody has restored is a hope, not a plan.

8.How do database changes reach production?

A migration is a versioned SQL file, applied the same way everywhere.

Releases and testing

How a change is checked before your users see it.

9.Is there a staging environment, with its own database, where changes are checked first?

Staging is a private copy of production where each release is tried before it is live.

10.Do automated tests cover your core flows — sign-up, payment and the main thing your app does?

Regression tests catch the feature you did not touch breaking because of one you did.

11.How does code get to production?

CI/CD runs the same checks on every change and deploys only what passes.

Running it live

Knowing it broke before your users tell you, and what happens next.

12.If the app broke for users right now, how would you find out?

Observability is knowing what the running system is doing, from its logs, metrics and errors.

13.Are sign-up, login and anything that sends email or calls a paid API (such as an AI model) rate-limited?

Without a limit, one script can run up your bill or lock out your users.

14.If production went down tonight, is there a named person and a written plan?

Incident response is deciding before it happens who acts and how.

Payments

Taking money without holding card data or trusting the browser.

15.How does your app take payments?

Who holds the card details decides how much compliance work lands on you.

16.Are incoming webhooks checked by signature, and safe to receive twice?

Providers retry webhooks, so the same event can arrive more than once.

Privacy and compliance

The GDPR basics and a record of who changed what.

17.Do you have the GDPR basics: a privacy policy naming your providers, a data processing agreement with each, and a way to delete a user's data on request?

If you have users in the EU or UK, these are legal duties, not extras.

18.Can you tell who changed what in your admin area, and when?

An audit log is an append-only record of significant actions.

Ownership

Whether the app is yours to move, hand over and keep running.

19.Is the code in a Git repository you own, and could another team deploy it without the person who built it?

If only one tool or one person can ship it, you are locked in.

0 of 19 answered

How the score works

Every question has a fixed weight, and the weights add up to 100. Your answer earns all, part or none of it; “Not sure” earns nothing. A question that does not apply to your app is left out and the rest are scaled back to 100. Any critical gap caps the score at 49. The rules are the same in your browser and on our server, and there is no AI in the loop.

Weight of each area, out of 100
AreaQuestionsWeight
Security and access525
Data safety320
Releases and testing315
Running it live315
Payments210
Privacy and compliance210
Ownership15

Bands: 90 and above is production-ready, 75 to 89 nearly there, 50 to 74 needs work, below 50 not ready. What each term means is in our glossary.

Questions about the check

What does the production-readiness check measure?

19 questions across seven areas that decide whether an app is safe for real users: security and access, data safety, releases and testing, running it live, payments, privacy and compliance, and ownership. Each answer is scored against a fixed weight, and the areas add up to 100.

How is the score calculated?

Every question carries a weight, and the weights add up to 100. Your answer earns all, part or none of that weight. "Not sure" earns nothing, because if you cannot say it is done the safe assumption is that it is not. A question that does not apply to your app, such as payments when you take none, is left out and the rest are scaled back to 100. A critical gap, such as a service-role key in the browser, caps the score at 49. The same rules run on our server, with no AI involved.

What score counts as production-ready?

90 or more is production-ready, 75 to 89 is nearly there, 50 to 74 needs work before launch, and below 50 is not ready for real users. Any single critical gap holds an app below 50, whatever else is in place.

Do you store my answers?

Not unless you ask for the emailed report. The score is worked out in your browser. If you ask for the report, we store your email, the name and app address you give, your answers and your score for 24 months, send the report once and tell our team. We only send you anything else if you tick the box. We never visit or scan your app's address.

Is it only for apps built with Lovable?

No. It works for any app built with an AI app builder such as Lovable, Bolt, v0 or Replit, or built by hand. Some questions name Supabase because most AI-built apps run on it, but the same checks apply to any app with a database, sign-in and payments.

What should I fix first?

Start with the three risks the check shows you. Critical gaps come first, then the answers that lost the most points. Each one links to a plain-English definition in our glossary. If you would rather have engineers fix them, that is what a Plutonapps plan does.

Rather have engineers fix it for you?

You keep designing in Lovable. Plutonapps engineers make the real product secure, tested and ready for production, on a subscription.

See the plans