Launch checklist
Production-ready checklist for AI-built apps
Short answer
A launch checklist you can use before paying for hosting, sharing the app publicly, or handing it to users.
Why this matters
The app looks done, but nobody can answer where secrets live, how backups restore, who owns the server, or what happens when deploy breaks.
Walkthrough
- 01
Lock down ownership
Before deployment, make sure the important accounts belong to the product owner, not a random builder account or the AI tool workspace.
- Domain registrar, DNS, GitHub repo, hosting account, database, email, and payment provider must be owned by you.
- If the app started in Lovable, Bolt, Base44, v0, Replit, or Cursor, export it into a repo and host you control.
- Use a shared password manager or access handover doc, not screenshots in chat.
- Remove unused collaborators after launch.
- 02
Move secrets out of the app
AI-built apps often work because secrets were pasted somewhere convenient. That is not production, especially after moving between builders and hosts.
- Keep API keys, database URLs, JWT secrets, and webhook secrets out of git.
- Use production, preview, and local env vars separately.
- Rotate secrets if they were ever pasted into chat, logs, public repos, or screenshots.
- 03
Prove the app can recover
A production app is not production-ready until you know how to recover it.
- Create database backups and test at least one restore.
- Write restart, rollback, and deploy commands in plain English.
- Smoke test signup, login, database writes, file uploads, email, payments, and admin actions.
Where RepoAssistant fits
RepoAssistant turns AI-built apps into production setups with ownership, backups, secrets, and handover covered.