Ship It Safely is the plain-language security, debugging and launch kit for people who built something real with an AI app builder or coding assistant, and now want to share it without a bad Tuesday.
Ship It Safely · Bodhih Pro Kits · 39 by Bodhih Training, trainers to 2,000+ companies since 2008.
Check eight layers in order: spec, data, access rules, login, secrets, deploy, test and backup. Switch on database access rules for every table, keep secret keys on the server, test with two accounts and a logged-out window, and prove you can restore a backup. The Ship It Safely kit from Bodhih Training gives you the checklist and tracker.
Want the full free guide first? Read How to Secure an AI-Built App Before Launch: A Checklist.
The app does everything you asked. What you can't tell is whether a stranger could read your users' records by editing a web address. Nobody showed you how to check, and the assistant says everything is fine.
To get it working at midnight you pasted an API key into a chat. It worked. Now you're not sure where that key lives, who can see it, or what it could cost you.
You report a bug, the assistant apologises and changes something, and now two things are broken. Twenty prompts later you can't remember what the working version looked like.
Names, emails, phone numbers, maybe payments. You know there are privacy rules, and you have a form that collects a date of birth because the assistant suggested it.
If something leaked or a bill exploded this weekend, what would you do in the first hour? Where is the off switch? Is there a backup, and have you ever restored it?
Imagine the evening before you share your app. Instead of hoping, you open the Launch Readiness Tracker and look at one number and one line of text. The readiness score says 91%. The verdict says Nearly: close High items. You know exactly which three checks are left, and you know why each one matters.
Now picture the two-account test. You log in as user B, paste the address of user A's booking, and watch the app refuse. Then you open a private window, paste the link of an uploaded file, and it does not open. That quiet refusal is what safe looks like, and you can see it with your own eyes rather than taking anyone's word for it.
A week later something breaks, as things do. You don't type 'it's broken'. You fill in the Bug Report Sheet, send four clear lines, and ask for the cause before the fix. As you save a named checkpoint and watch one small change solve one small problem, you notice that debugging has become a method instead of a mood.
And if a bad day ever comes, there's a single page taped inside a cupboard with the off switch, the backups and the five steps written down. When you fill in that page this week, you'll probably never need it. That is exactly the point.
The e-book shows you how. The tools make it happen. Here is exactly what you download.
The guide: methods, worked examples, scripts and exercises
The 50-point checklist with a weighted readiness score and launch verdict, a risk register, 40 mischief tests, a bug log with fix-loop alerts, a secrets and services inventory, backup log, cost monitor and three live dashboards.
The full checklist as a fillable, printable PDF: nine sections, severity marked on every item, chapter references and a sign-off box.
Decide who can read, create, update and delete every table and storage bucket, then hand the grid to your assistant and verify it with two accounts.
Fill in the top half today; follow the five boxes on the bad day: contain, assess, tell, fix, learn.
One page that turns 'it's broken' into a report an assistant or developer can act on: reproduce, isolate, describe, then verify.
45 copy-and-paste prompts for security review, access rules, secrets, privacy, test cases, explaining errors, escaping fix loops and launch.
A data map plus plain-language outlines for a privacy notice and terms of use, with [CHECK] markers for a professional. Not legal advice.
An editable test plan with a field-by-field input table, happy, sad and mischief path cases, a regression list and a release sign-off.
The five-step debugging method as a follow-the-arrows flow, with a what-the-error-means table and a bug report script.
One page on public versus secret keys, where each may live, the five rules and the leaked-key drill.
The three-strikes drill for when the assistant keeps fixing one thing and breaking another, with the fresh-start brief.
What checkpoints, versions, commits, branches and backups are, the checkpoint habit, and a simple backup schedule.
A dated one-page guide to the kinds of tools AI builders use and which safety settings to look for in each. Examples, not recommendations.
A seven-day launch plan, two post-launch reviews and twelve monthly maintenance reminders (with quarterly restore drills) for Google, Outlook or Apple Calendar.
Each chapter opens with a real situation, gives you a method and ends with something to do today, using the tools in your kit.
Why AI-built apps work before they are safe, and how to use the kit.
Pick your stakes level, learn the eight stable layers and rank risks before fixing anything.
Decide who can read, create, update and delete every table, and make the rules live in the database.
Use the platform's login, keep secret keys on the server, and inventory, cap and rotate them.
Validate every input on the server, keep card details with a trusted provider and write kind error messages.
Privacy basics for small apps: collect less, explain more, delete on schedule (educational, not legal advice).
The difference between checkpoints and backups, the checkpoint habit and the restore drill.
Happy, sad and mischief paths, the two-account test and forty hands-on tests for your own app.
The five-step debugging method: reproduce, isolate, describe, one small fix, verify.
The three-strikes drill for when the assistant keeps fixing one thing and breaking another.
A staged launch, the weekly watch, the incident plan and when to pay for a professional review.
Why tools change and judgment lasts.
A dated guide to tool types and the settings to look for in each.
The words you'll meet, translated.
Every outcome is practised with a worked example and a tool, not just described.
People who measure before and after improve faster and can show it. AssessAll, our sister assessment platform, has AI-graded assessments that pair with this kit. Take one now, work through the kit, then re-take it.
Here is the single most useful sentence in this book. Anything that happens in the user's browser can be seen and changed by the user. Hidden buttons, greyed-out fields and "admin only" pages that are merely not linked are decorations. A curious teenager with the browser's built-in developer tools can read the requests your app sends and send their own. So the real rules have to live where users cannot reach: on the server, or in the database itself. Many AI builders pair your app with a hosted database that the browser talks to directly. That design is fine, but only if the database has access rules switched on for every table. One popular provider's documentation says it bluntly: enable row level security on every table in an exposed schema. Without that, a table can be readable and writable by anyone who has the app's public key, and the public key is, by design, public.
| Free templates and typical advice | This kit | |
|---|---|---|
| Method | A blank checklist with no explanation of why each item matters | Ten chapters teaching eight stable layers, with a worked example in each |
| Who it's for | Written for developers, in developer language | Written for non-coders, with every term translated and a glossary |
| Readiness | Tick boxes and a feeling | A weighted readiness score, blocker flags and a plain launch verdict |
| Testing | 'Test your app thoroughly' | The two-account test, the private-window test and 40 mischief tests with safe results |
| Debugging | 'Ask the AI to fix it' | A five-step method, a bug report sheet and a three-strikes drill for fix loops |
| Tool advice | Tied to one tool and out of date in three months | Tool-agnostic principles, with specifics kept to a dated tool sheet |
| After launch | Nothing | Cost monitor, backup log, incident one-pager and twelve months of maintenance reminders |
Bodhih Training has designed and delivered corporate programmes since 2008. Bodhih Pro Kits package what works in those workshops into a guide plus the exact tools we use, so you can apply it the same day without a facilitator in the room.
Name, email and country. UPI, card or netbanking in India; international cards everywhere else. No account to create.
Your download page opens at once, with every file and a one-click ZIP. A permanent link lands in your inbox too.
Start with the quick-start chapter, then the main spreadsheet or planner. Most buyers use something from the kit the same day.
When you download Ship It Safely, start with the one check that matters most for your app. Whether you run the two-account test tonight or open the Launch Readiness Tracker tomorrow morning, you'll know more about your own app within the hour than you did after weeks of building it.
Personal licence for the buyer's own use (and use with your own team or clients where the kit says so). Please don't share or resell the files. Team and company licences: solutions@bodhih.com.
Role-based Applied AI certifications from Bodhih.
Prompts, workflows and guardrails for every professional.
250+ AI-graded assessments to measure skills and earn verified credentials.
Individual development plans that start from evidence and stay yours.
Run this topic as a live workshop for your team, in person or online.
Book a vetted coach for career, leadership or communication. Pay per session.
Certification pathways in Applied AI, Workplace English and management.
No, it is written for non-coders. But we won't pretend you never need to understand anything: you will read some settings screens, learn a few words such as access rules and secrets, and run tests by hand. The e-book translates every term and the prompts make your assistant do the technical reading.
No kit can promise that, and you should be wary of anything that does. It helps you find and fix the most common and most serious problems in AI-built apps, and it tells you plainly when to pay for a professional review, such as when you handle payments, health, finance, ID documents or children's data.
Create two test accounts, A and B. As A, create a record and copy its web address. Log in as B in another browser and paste the address, then try changing the number at the end. Finally paste it into a logged-out private window. If B or the visitor can see A's record, your access rules need fixing in the database or server.
Treat it as leaked. Create a new key at the provider, put it in your platform's secrets settings, redeploy and test, then revoke the old key and check your usage and billing. Deleting the message is not enough. The Secrets and keys cheat sheet has the drill on one page.
It is written to be tool-agnostic, because it teaches the layer underneath: spec, data, access rules, login, secrets, deploy, test and backup. Tools are named only as examples in a dated appendix and tool sheet marked correct at October 2026, and the kit is independent: not affiliated with or endorsed by any vendor. Names, menus and plans change, so check the vendor's current documentation.
No. The whole kit is educational. The privacy notice and terms starter is an outline to help you think and to brief a qualified professional, with [CHECK] markers where the law differs by country. Rules such as the GDPR and India's DPDP Act vary in detail, so check your local law or a qualified professional.
If you'd like an objective baseline, AssessAll offers the Debugging Judgment Assessment with a Mid-Task Requirement Change, the Personal Data Judgment assessment and the Workplace Cybersecurity Awareness Assessment. They are separate from this kit and useful before and after you work through it.
Pick the two layers where your checklist score was weakest and set a goal for each. Jobulary's individual development plan can turn what you learn here into a measured development plan, which is handy if building with AI is becoming part of your job.
No. Start with Chapter 2 and Chapter 3 tonight: run the two-account test, the private-window test and the view-source test, and set spending caps. Then work through the rest of the checklist in the tracker over a week.
Digital kits are non-refundable once downloaded, except for corrupted files we can't fix within 3 working days, duplicate charges or failed delivery. The sales page shows exactly what is inside so you can decide before you buy.
₹999 including 18% GST for buyers in India, or $29 for buyers outside India. One-time payment, no subscription, with an automatic invoice.
Instantly. Your download page opens the moment payment succeeds, and a permanent download link is emailed to you. Download each file separately or everything in one ZIP.
Any of the usual tools: Excel or Google Sheets for spreadsheets, Word or Google Docs for templates, Adobe Acrobat Reader, Preview, Xodo or GoodNotes for the fillable PDFs, and Google, Outlook or Apple Calendar for the calendar plan.
Yes. Team and company licences, and workshops on this topic run by Bodhih Training, are available. Write to solutions@bodhih.com or call +91 99000 11601.