QuezziesThe Sprint, £3,000

Free · 20-minute self-audit

The Ship-Ready Checklist

AI tools ship prototypes fast, then fail in the same twelve ways when real users arrive. Here's each one, and how to check yours in about twenty minutes. No email required to read it.

  1. 01

    Auth is only on the UI, not the API

    Check it: Log out, then call an API route directly (curl or the network tab's copy-as-fetch). If it returns data, your auth is decoration.

  2. 02

    One user can read another user's data

    Check it: Sign in as user A, open a record, then change the ID in the URL or request to user B's. If B's data loads, you have a tenant leak.

  3. 03

    The Stripe webhook trusts any POST

    Check it: Send a fake POST to your webhook with no signature. If it's processed, an attacker can mark orders paid. Verify the signature server-side.

  4. 04

    Payment succeeds but nothing is provisioned

    Check it: Pay in test mode, then check the account actually got what it bought. Many AI-built apps take the money and never flip the flag.

  5. 05

    A secret key is in the browser bundle

    Check it: Search your built client JS for 'sk_', 'secret', or a provider key prefix. Anything server-only in the browser is already leaked.

  6. 06

    It only runs on your laptop

    Check it: Clone the repo into a fresh folder and run the documented steps. If it won't build and boot clean, your deploy will fail the same way.

  7. 07

    Production secrets are committed or missing

    Check it: Grep the repo for keys and check your host has the real ones set. Committed secrets must be rotated; missing ones break prod silently.

  8. 08

    The AI step assumes perfect model output

    Check it: Force the model to return junk or empty. If the app crashes or shows nothing, add structured outputs and a fallback path.

  9. 09

    Nothing caps runaway AI cost

    Check it: Check for a per-request token or loop limit. Without one, a single bad prompt or agent loop can quietly burn your whole budget.

  10. 10

    Failures hang instead of telling the user

    Check it: Kill your API mid-request. A good app shows an error and recovers; a fragile one spins forever. Users read that as broken.

  11. 11

    There is no backup of the only data copy

    Check it: Ask where the single source of truth lives and when it was last backed up. One unbacked SQLite file is one bad deploy from gone.

  12. 12

    Any endpoint can be hammered for free

    Check it: Loop a script against signup or an AI endpoint. No rate limit means anyone can rack up your bill or fill your database.

Want the next teardown?

I publish short breakdowns of exactly how these fail in real codebases, and how I fix them. Drop your email and I'll send new ones as they land.

Found one that's red? That's a sprint.

I take one of these from broken to working in production in three days, fixed £3,000, pass-or-refund. Book a free 15-minute triage and I'll tell you yes or no on the call.