VibeCoded

How do I monitor an AI-built app?

Last reviewed 2026-09-30Written by Jacob Masse, TrazTech Inc.

Log sign-ins, failed logins, permission denials, admin actions, payment events, errors and AI tool calls, without logging passwords, tokens, full card numbers or unnecessary personal information. Set alerts for error spikes, repeated failed logins, unusual data exports and AI spending. AI-built apps often ship with no logging beyond the host's defaults, so a breach goes unnoticed.

What to log

  • Authentication events and failures.
  • Permission denials, which show someone probing.
  • Admin and role changes.
  • Payment and subscription changes.
  • AI requests: user, tokens, tools called.
  • Errors with request IDs.

Alerts worth having

  • Error rate above normal.
  • Many failed logins or permission denials from one source.
  • Large exports or unusual query volume.
  • AI spend above a daily threshold.

What never to log

Logs are a second copy of your data, and they are often less protected than the database. Never log passwords, session tokens, API keys, full payment card numbers, or the contents of password reset links. Avoid logging full request bodies on routes that handle personal information, and redact email addresses and phone numbers where you do not need them. For AI features, decide deliberately whether to keep full prompts and responses: they are useful for spotting injection attempts and debugging, and they also hold whatever users typed, which under PIPEDA and Law 25 is personal information you must protect and eventually delete.

Limit who can read production logs, set a retention period that matches your privacy policy, and make sure your logging provider is listed among your service providers. A breach of a log store is still a breach.

Getting it checked

TrazTech offers vibe-coding QA and security review, listed from $2,000 CAD. Get at least one other quote on the same scope; the questions to ask a testing firm help compare them.

Get a scope for your app

Tell us what you built, what it stores and who is about to use it.

Get matched

Common questions

How long should I keep logs?

Long enough to investigate an incident, commonly 90 days to a year, and no longer than your privacy policy says.

Is my host's logging enough?

It covers requests and errors. Application events like permission denials need your own logging.