Strategy 4 min read
Your AI-built prototype isn't production ready. Here's what to check.
AI app builders produce convincing demos fast. Before real data goes in, check authentication, authorisation, the data model and who owns the code.

AI app builders can turn a description into a working demo in an afternoon. That's genuinely useful — for testing an idea, showing stakeholders, or writing a specification. The trouble starts when the demo quietly becomes the production system.
Generated apps often look complete while missing the parts you can't see. A common example: screens that ask you to log in, sitting on an API that never checks who is asking — so anyone with the URL can read the data.
What to check before real data goes in
- Authentication: is every endpoint protected, or only the screens?
- Authorisation: can a regular user reach admin data by changing a URL or an ID?
- Data model: does it match how your business actually works, or how the generator guessed it does?
- Secrets: are API keys in the code or the browser bundle?
- Ownership: is the code in your repository, on infrastructure you control?
- Specification: does the build match what you asked for, or has it drifted?
Keep the idea, rebuild the foundations
You rarely need to throw everything away. Treat your written specification as the source of truth and the generated code as a draft. Keep the screens that work, rebuild authentication and data access properly, and move it onto infrastructure you own.
Treat the generated code as a draft, and your specification as the source of truth.
Prototypes are cheap now; production systems still aren't. If you have a prototype your team loves but you're not sure it's safe, we can review it and tell you plainly what it would take.

