The Go-Live Credential Test

Your client app is live.
But who has the keys?

Most agencies have a launch checklist. Almost none have a credential custody checklist. Answer 10 yes/no questions — we'll score your launch readiness in under 60 seconds.

  1. 1

    Does the client own the production Stripe account?

  2. 2

    Does the client own the production hosting account (Vercel, Netlify, Render, etc.)?

  3. 3

    Does the client own the domain registrar account?

  4. 4

    Does the client control DNS access?

  5. 5

    Are production API keys stored in a real vault — not in Slack, email, Notion, or text messages?

  6. 6

    Have you scanned git history for accidentally-committed secrets?

  7. 7

    Have former freelancers and contractors been removed from production systems?

  8. 8

    Are OpenAI / Anthropic / other AI API keys owned by the client — not a developer's personal account?

  9. 9

    Is there a written handoff record showing who owns each critical credential?

  10. 10

    Has someone reviewed admin access across Stripe, GitHub, hosting, DNS, analytics, and AI tools before launch?

Your score
0/10 answered
0/10Keys need a Sherpa

Answer all 10 to see your final band. Your provisional band is shown above — it'll update as you go.

9–10 · Launch-ready
Clean custody. Nice work.
6–8 · Almost there
A few loose ends before go-live.
3–5 · Normal agency chaos
Common, fixable, and worth cleaning up.
0–2 · Keys need a Sherpa
Your app is live, but so is the treasure map.