Your client app is live.
But who has the keys?
Most agencies have a launch checklist. Almost none have a credential custody checklist. Answer 10 yes/no questions — we'll score your launch readiness in under 60 seconds.
- 1
Does the client own the production Stripe account?
- 2
Does the client own the production hosting account (Vercel, Netlify, Render, etc.)?
- 3
Does the client own the domain registrar account?
- 4
Does the client control DNS access?
- 5
Are production API keys stored in a real vault — not in Slack, email, Notion, or text messages?
- 6
Have you scanned git history for accidentally-committed secrets?
- 7
Have former freelancers and contractors been removed from production systems?
- 8
Are OpenAI / Anthropic / other AI API keys owned by the client — not a developer's personal account?
- 9
Is there a written handoff record showing who owns each critical credential?
- 10
Has someone reviewed admin access across Stripe, GitHub, hosting, DNS, analytics, and AI tools before launch?
Answer all 10 to see your final band. Your provisional band is shown above — it'll update as you go.