Your AI built it
Your AI built it. I make it safe, yours, and connected.
Lovable, Replit, Bolt or your own prompts got you a working app. Before customers, payments or real data touch it, a senior engineer checks what is exposed, makes sure every account and key is in your name, and connects it to the systems the business runs on.
Tell me what you are buildingIt is right when.
- An app your AI tool built is about to meet real customers or real data
- Keys, tokens or a database sit somewhere you cannot see
- You are not sure who owns the code, the hosting or the domain
- It works on its own but has to talk to Shopify, QuickBooks, a CRM or payments
- Every change the AI makes breaks something else
If the app is a prototype for your own use, with no customer data and no payments, keep iterating with the AI. The audit is for the moment it goes live.
Why it matters now.
of code samples written by AI models introduced a top-10 web security flaw, with no improvement from 2025 to early 2026.
Veracode, 100+ models →high-impact vulnerabilities and 400 exposed secrets in a scan of 5,600 publicly deployed apps built with AI tools.
SecurityWeek, 2026 →of professional developers say the top reason they still ask a person is when they do not trust the AI’s answer.
Stack Overflow Developer Survey 2025 →What the audit checks.
The method, in the order it runs. Nothing on this list needs your AI tool to change how it works.
Secrets and keys
- No API key, database key or token shipped to the browser
- Every exposed key rotated, with the old one revoked
- Secrets live in the host’s environment, not in the repository
Who can see what
- Database rules (Supabase row-level security, Firebase rules) checked table by table
- Every page and API route checks who is asking, on the server
- Admin screens behind a real role, not a hidden link
What you own
- Repository, hosting, domain, database and AI keys in the company’s name
- A second admin on every account, so one person leaving cannot lock you out
- An export of your data you have actually opened
When it fails
- Backups that run on their own, and one restore tested
- Errors that alert a person instead of failing silently
- Payment and webhook flows that survive retries and duplicates
Connected to the business
- Which systems it must talk to, and the one source of truth for each record
- What breaks if the AI tool or its pricing changes
- Tests on the paths that move money or customer data, so the next AI change cannot break them unnoticed
AI-Build Audit
A signed report: what is exposed, what you own and what you do not, and the order to fix it in. Then a fixed quote to fix it, or the list to do it yourselves.
Ask for the audit → Monthly, fixedAccountable Maintainer
Monitoring, security updates, and a review of every change the AI or your team makes before it ships. One named person answers when it breaks.
Ask about the retainer →“The AI can write the code. Someone still has to answer for it.”
How it works.
- DiscoveryWe map the problem and the one outcome that matters most.
- Fixed-scope first phaseOne outcome, one price, agreed up front.
- Demos at every stepYou see working software, not status reports.
- You own everythingYour repository, your keys, your data.
- Decide at each milestoneContinue, pause or stop, and keep what you paid for.
Proof, not promises.
The audit method is the list above, published check by check, and the same standards run through the Field Kits. 7IT publishes its own work in the open: original research, and a live tool server AI assistants use.
Browse the Field Kits →Read before you decide.
In-depth guides, each with a working Field Kit.
Custom Software for US Businesses: Build vs Buy, Real Costs, and Timelines
A practical, no-hype guide for US small and mid-size businesses deciding whether to build custom software, what it really costs, how long it takes, and how to d…
Includes the Cost and Scope Scorecard → GuideHow to Secure an Admin Panel: Google Auth, 2FA, and Sessions on Vercel
A technical guide to locking down an admin panel when both your client app and admin run on Vercel. Google sign-in with an allowlist, real 2FA, why httpOnly coo…
Includes the Admin Security Checklist → GuideFrom Idea to MVP: Scoping a First Phase That Pays for Itself
A practical guide to turning a software idea into a first phase that ships and pays for itself. Finding the one workflow worth building first, cutting scope to …
Includes the MVP Scoping Worksheet → GuideEscaping No-Code Lock-In: Moving From Bolt or Lovable to Code You Own
A technical guide to graduating from no-code AI builders to software you own. Why builders are great until they are not, the signs you have outgrown one, what o…
Includes the No-Code Exit Checklist → GuideDatabase Design for Non-DBAs: A Practical Technical Guide
A practical guide to designing a database you will not regret. Modeling real entities and relationships, choosing keys and types, letting the database enforce i…
Includes the Schema Design Checklist → GuideDon't Lose Your Data: Backups and Disaster Recovery for Small Businesses
A technical guide to backups and disaster recovery that actually work. Why an untested backup is not a backup, what to back up, the 3-2-1 rule, point-in-time re…
Includes the Backup and Recovery Checklist →Questions.
Which AI tools do you work with?
Whatever built it: Lovable, Replit, Bolt, v0, Base44, Cursor, Claude Code, or code pasted from a chat. The audit reads the result, not the tool.
Will you rewrite the whole thing?
Only what has to change. Most AI-built apps keep most of their code. The report separates what must be fixed before launch from what can wait.
Can we keep building with our AI after?
Yes. The point is to make that safe: tests on the critical paths and a review step, so the AI keeps moving fast without breaking what matters.
Do we need you after the audit?
No. You get the list and can fix it yourselves. The Accountable Maintainer retainer is there if you want one named person answering for it every month.