Security
Probes for exposed secrets, missing RBAC enforcement, row-level security gaps, cross-tenant data leakage, and unauthenticated admin routes. Any critical finding blocks public launch.
Fails closedFlightcheck runs a mandatory pre-launch scan — security, payment integrity, privacy compliance, and store-readiness. Public and paid publish fail closed on any critical finding. You see exactly what blocked the launch, and the fix is free.
Flightcheck is not a linting pass or a checklist you fill out manually. It runs active probes against your live app — testing secrets exposure, cross-tenant data leakage, webhook signature forgery, and store metadata completeness before a single user lands.
Probes for exposed secrets, missing RBAC enforcement, row-level security gaps, cross-tenant data leakage, and unauthenticated admin routes. Any critical finding blocks public launch.
Fails closedConfirms webhook signature verification, idempotency key handling, refund path completeness, and receipt integrity. A payment gate that passes means money actually moves correctly.
Fails closedChecks iOS and Android privacy manifest strings, App Tracking Transparency usage declarations, data deletion support, and PII handling against your spec’s stated data practices.
Store requiredValidates App Store and Play Store metadata completeness — screenshots at required resolutions, content ratings, privacy policy URL, support URL, and minimum OS targeting — before submission.
Blocks submissionVerifies that paid features are actually locked behind an entitlement check, that free-tier users cannot access premium routes, and that upgrade flows unlock the correct access immediately.
Fails closedEvery Flightcheck failure is an AI self-correction task. You pay nothing for the fix. Only new scope you request is billable. Safe-to-charge is a guarantee, not a service tier.
No extra chargePublic and paid publish fail closed on critical security, payment, privacy, or store-readiness issues. You see exactly what blocked the launch — and the fix is free correction, not new scope.
Review the claim evidence registerFlightcheck does not give warnings you can dismiss. Critical security findings, payment integrity failures, and missing privacy declarations are hard blocks. The gate either passes or the product does not publish — no overrides, no “ship it and fix later.”
Flightcheck hits your running app with real HTTP requests, test credentials, and crafted payloads — not just reading source code. Findings are evidence, not guesses.
Public launch and paid launch are separate gates. A security critical will block both. A missing screenshot blocks the store submission gate, not the web launch. Blocking is scoped, not binary.
FlightDeck resolves every Flightcheck finding that originates from its own build output at no charge. You see what changed, why, and the updated Proof run that confirmed the fix.
When every gate in the target launch scope is clear, the publish action becomes available. Not before. The audit log records the full gate history for every version you ship.
Flightcheck runs before every public or paid launch. Findings block it. The fix is free. You ship with a record, not a prayer.