VibeCoded

Pre-launch security checklist for AI-built apps

Forty checks, grouped the way an attacker would approach your app. Tick them in your browser as you go; nothing is sent anywhere. Everything left unticked is your test scope.

Last reviewed 2026-09-30Written by Jacob Masse, TrazTech Inc.

Before an AI-built app takes real users, check seven areas: accounts, access control, database rules, secrets, payments, AI features and privacy. Most serious findings in vibe coded apps come from the second, third and fourth. Work through the list below with two test accounts open side by side. If you cannot tick an item or do not know how to check it, that item belongs in a professional security test.

1. Accounts and login

0 of 0 done ·

Getting this section right

Evidence that passes. A test account that cannot log in without verifying email, a password reset flow that expires its links, and a session that ends on logout on every device.

Typical timing. Hours, if the auth provider handles it. Custom login code written by an AI tool can take a few days to make safe.

Common mistakes. Login built by hand instead of using the provider; reset links that never expire; sessions that survive logout.

In Canada. If you serve Quebec users, Law 25 expects privacy-protective defaults, so do not switch on tracking or public profiles by default.

2. Access control

The most common serious finding. Log in as user A in one browser and user B in another, and try to reach B's data from A's session by changing IDs in URLs and requests. See IDOR.

0 of 0 done ·

Getting this section right

Evidence that passes. Two test accounts, where user A tries to read and change user B's records through the API directly, not just through the interface. Both attempts should fail.

Typical timing. A day to test properly. Fixing missing checks across every route can take a week in an app that skipped them.

Common mistakes. Checking permissions in the front end only; trusting a user ID sent from the browser; admin routes protected by a hidden URL.

In Canada. A breach caused by one user reading another's data is reportable to the Privacy Commissioner of Canada if it creates a real risk of significant harm.

Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.

3. Database and storage rules

0 of 0 done ·

Getting this section right

Evidence that passes. Row level security switched on for every table, storage buckets private unless they must be public, and a test showing an anonymous key cannot read other users' rows.

Typical timing. An afternoon to review policies; longer if tables were created without them.

Common mistakes. Row level security turned off to make a feature work; storage buckets left public; policies that allow any signed-in user to read every row.

In Canada. Personal information in Canada must be protected by safeguards appropriate to its sensitivity. A public table of user data fails that test outright.

4. Secrets

0 of 0 done ·

How to search for them is on exposed API keys.

Getting this section right

Evidence that passes. A search of the built front end and the repository history showing no secret keys, with keys rotated if one ever appeared.

Typical timing. An hour to search, an hour to rotate. Cleaning keys out of git history takes longer but matters less than rotating them.

Common mistakes. A service key in the client bundle; API keys committed early in development and still valid; one key shared between test and production.

In Canada. Keys to services holding Canadian customer data are part of the safeguards PIPEDA expects. Rotate any key you cannot account for.

5. Payments

0 of 0 done ·

Getting this section right

Evidence that passes. Prices and amounts set on the server, webhook signatures verified, and a test showing a changed price in the browser does not change what is charged.

Typical timing. A day to verify with test payments.

Common mistakes. Trusting the amount sent from the browser; webhooks accepted without checking the signature; refunds exposed on an unprotected route.

In Canada. Canadian card payments fall under PCI DSS through your processor. Using a hosted checkout keeps most card data out of your app entirely.

6. AI features

0 of 0 done ·

Each risk is explained on the OWASP LLM Top 10.

Getting this section right

Evidence that passes. A record of what the model can read and do, rate limits and spending caps on model calls, and test prompts showing it refuses to reveal other users' data or its instructions.

Typical timing. A day for a basic review; an LLM red team engagement takes one to two weeks.

Common mistakes. Giving the model access to every user's data through retrieval; no spending cap on model calls; treating model output as trusted input to other systems.

In Canada. Sending personal information to a model provider outside Canada is a transfer you should disclose in your privacy policy, and in Quebec it needs a privacy impact assessment first.

7. Privacy and operations

0 of 0 done ·

What PIPEDA and Law 25 require of an AI app is on privacy law for AI apps in Canada.

Getting this section right

Evidence that passes. A published privacy policy that matches what the app collects, a way to delete an account and its data, and error monitoring that does not record passwords or full payment details.

Typical timing. A day to write the policy and wire up deletion if the data model allows it.

Common mistakes. A copied privacy policy that does not match the app; no way to delete an account; logs full of personal information.

In Canada. PIPEDA requires a privacy contact and a way to access and correct personal information. Quebec's Law 25 adds a named person in charge of privacy.

After the checklist

Everything left unticked goes in the scope of a test, and a tester will also check the items you ticked, because "I checked" and "it holds up against an attacker" are different things. Use the launch readiness check for a score, or the cost estimator to price the test. TrazTech's vibe-coding QA and security review covers this list and the QA side together.

Have the list checked by someone who breaks apps

Send the unticked items with a description of the app.

Get matched

Common questions

Is ticking every item enough to launch?

It is a strong start for a low-risk app. For an app holding personal information or taking payments, have the list verified by a tester, because the checks that feel done are the ones worth confirming.

Does the checklist save my progress?

Yes, in your own browser only. Nothing is sent to us.