← All guides

Launch checklist

Production checklist for AI-built apps

VercelVPSSupabaseDomain

Short answer

A launch checklist you can use before paying for hosting, sharing the app publicly, or handing it to users.

Why this matters

The app looks done, but nobody can answer where secrets live, how backups restore, who owns the server, or what happens when deploy breaks.

Walkthrough

  1. 01

    Lock down ownership

    Before deployment, make sure the important accounts belong to the product owner, not a random builder account.

    • Domain registrar, DNS, GitHub repo, hosting account, database, email, and payment provider must be owned by you.
    • Use a shared password manager or access handover doc, not screenshots in chat.
    • Remove unused collaborators after launch.
  2. 02

    Move secrets out of the app

    AI-built apps often work because secrets were pasted somewhere convenient. That is not production.

    • Keep API keys, database URLs, JWT secrets, and webhook secrets out of git.
    • Use production, preview, and local env vars separately.
    • Rotate secrets if they were ever pasted into chat, logs, public repos, or screenshots.
  3. 03

    Prove the app can recover

    A production app is not production-ready until you know how to recover it.

    • Create database backups and test at least one restore.
    • Write restart, rollback, and deploy commands in plain English.
    • Smoke test signup, login, database writes, file uploads, email, payments, and admin actions.

Where RepoAssistant fits

RepoAssistant turns AI-built apps into production setups with ownership, backups, secrets, and handover covered.