Do I need a pentest before launch?
If the app will hold personal information, take payments or sell to businesses, yes: have it tested by someone independent before launch. If it has no accounts and stores nothing sensitive, a lighter security review or your own checklist is enough for now. A pre-launch test of a small AI-built app typically costs $2,000 to $12,000 CAD and takes one to three weeks.
How to decide
| App | What to do before launch |
|---|---|
| Landing page, calculator, no accounts | Checklist only |
| Accounts, personal information, consumers | Security review and QA |
| Payments or health, financial or children's data | Security review, QA and a pentest of the running app |
| Selling to businesses who will ask | A pentest with a report or summary letter |
| AI features over customer data or with tools | Add an AI security assessment |
Why before, not after
After launch, a finding is also a possible breach, with notification duties under PIPEDA and Law 25. Before launch it is a bug. The same test costs the same either way; only the consequences differ.
When to book it
Book testing when the features are finished but two to three weeks before the launch date, so there is time to fix and retest. Testing a half-built app wastes days on things that will change.
If budget is tight
Spend in this order. First, the free work: run the pre-launch security checklist, fix what it finds, and run a scanner. Second, a focused security review of authorization, database rules and secrets, which is where most serious findings in AI-built apps are; for a small app that is often one to three tester days. Third, a full penetration test with a shareable report, when a customer or auditor will read it.
Do not launch with personal information or payments on nothing but the AI tool's own assurance. The cheapest independent check is still far cheaper than a breach notification.
Getting it checked
TrazTech offers vibe-coding QA and security review, listed from $2,000 CAD. Get at least one other quote on the same scope; the questions to ask a testing firm help compare them.
Related questions
- How much does it cost to test a vibe coded app?
- How long does a security test take?
- Can I launch without QA?
- Which test do I need
Get a scope for your app
Tell us what you built, what it stores and who is about to use it.
Get matchedCommon questions
Will a customer ask for a pentest report?
Business customers often do, through a security questionnaire. Consumers do not, but they are the ones harmed if the data leaks.
Is a pentest the same as a security review?
Close. A review can include reading code; a pentest attacks the running app. Small apps usually get both in one engagement.