Risk self-check

Is your AI app just a demo, or already ready for customers?

Your AI app runs. But is it also ready for real users, customer data or customer questions?

The short self-check assesses product status, stack, data, auth, data access, infrastructure and technical responsibility, and shows you a first risk rating, typical blind spots and a sensible next step.

  • 2 minutes
  • 8 questions
  • No repo access needed
  • No email needed
  • Result visible immediately

Who is the check for?

For founders, product teams and agencies who built software with Lovable, Cursor, Bolt, Base44, Claude Code, Replit, v0 or their own AI-assisted code and want to know whether there are technical blind spots before real users, customer data, customer questions, a security questionnaire or due diligence.

The check is especially useful when a demo flow slowly turns into a real product, internal tool or customer system.

What gets checked?

Product status & business risk

Just internal testing, or already a customer, launch, security questionnaire or due diligence?

AI builder & stack

Was it built with Lovable, Base44, Cursor, Bolt, Claude Code, Replit, v0 or your own AI-assisted code?

Users, data & tenants

Just test data, or customer data, documents, payments, teams or tenants?

Auth, roles & data access

Are login, roles, admin functions and data access really checked server-side?

Infrastructure, backups & operations

Are there backups, restore tests, monitoring, rollback, clear environments and an operations mindset?

Know-how & technical responsibility

Is there someone who can assess risks regularly, or just hope?

What do you get as a result?

At the end you get a rough risk rating:

Green

Currently rather low acute risk. Still re-check before real users.

Yellow

Some points should be assessed before customer use, launch or technical questions.

Red

Several signals suggest a demo flow is no longer enough as a technical assessment.

Plus typical blind spots and a recommended next step: re-check later, Baseline or a fit check.

Question 1 of 80% complete

What's coming up next?

What the check is not

The check does not replace a technical review, a penetration test or a security guarantee. It is a quick self-assessment. A real technical assessment requires repository, stack and infrastructure context.

If the check shows yellow or red, it does not automatically mean the app is bad. It only means: before customer data, customer questions or launch, someone should take a closer look.

Frequently asked questions

Is this a security assessment?

No. The check is not a technical security assessment or a guarantee. It only helps surface typical risk areas. A real assessment requires repo, stack and infrastructure context.

Do I need repo access or technical knowledge?

No. The short check works without repo access. You should roughly know what the app was built with, whether it processes real data and whether users, roles or customer areas exist.

Do I have to provide my email?

No. Result visible immediately, email only optional if you want to save it or have me assess it with you.

What happens to my answers?

The answers are used to compute a rough risk rating and typical blind spots. If you don't provide contact details, no request is created from it.

What comes after the check?

If green, you can re-check later. If yellow or red, a Baseline or a 15-minute fit check can help to assess the risks concretely.

Why only 8 questions?

The short check is meant for a first assessment. For concrete projects there is a more detailed readiness intake after the fit check.

Want it more precise?

For concrete projects there is a more detailed technical readiness intake after the fit check.