
Know what the prototype cannot do
A convincing screen is not yet a secure product. Review dependencies, embedded secrets, authorisation, input handling and agent permissions.
Review before release
Examine data flows, roles, secrets, failure modes, logs, dependencies and recovery. Automated tests help but do not replace human code and architecture review.
Match controls to risk
An internal demo can remain small. Personal data, payments or critical processes require a documented transition from experiment to operated system.
What to prepare for the first conversation
Use seven release checks: test roles and access to other users’ records; remove secrets from clients and repositories; bound inputs, uploads and outputs; review dependencies and licences; test failures, retries and concurrency; demonstrate export and recovery; assign responsibility for updates and incidents. Describe the use case first. Never send production credentials through an enquiry form.
Discuss a project ↗