Testing and the Due Diligence Audit
You have tested by clicking around. That catches the obvious. It does not catch the thing you never thought to try — and "things nobody thought to try" is where most launch disasters live.
What you want is a fixed list, applied the same way every time, by something that does not get bored or attached to your work.
What a standard actually is
A standard is a written list of what "ready" means, agreed before you look at any particular app. That last part is what makes it useful — you cannot quietly lower the bar for your own project if the bar was written first.
The one built into Vibe Coder Playground is called the Vibe Coder Standard. Right now it runs to 5 pillars, 34 checks, grouped like this:
- Locked down — secrets, permissions, the security list from the last stage.
- Actually works — does the main thing work, including with empty and strange input.
- Fast & usable — speed, phones, and whether people with disabilities can use it.
- Legit — privacy, licensing, and the legal pages you need once real people show up.
- Ship-ready — no leftover placeholder text, no broken dependencies, and it works as installed rather than only on your machine.
That number grows as new risks appear — it has grown several times — which is why it is read live here rather than typed into this page.
A chat reads the code
The audit sends the payload
Refused, and the refusal is on the record. Confirmed, not read.
What a good audit does that a chat does not
- Same list every time. Not "whatever seemed interesting today".
- One verdict. Pass, caution, or fail — not a wall of maybes.
- A phased plan. What to fix first, second, third, in plain language.
- Honest about its limits. A good audit tells you what it could not check.
That last point deserves emphasis. An audit that never says "I don't know" is not being thorough; it is guessing and hiding it.
Reading your first verdict without taking it personally
Your first audit will probably say caution or fail. That is normal and it is not a judgment of you.
- Critical — fix before anyone uses it. Usually security or data loss.
- Major — fix before you tell people about it.
- Minor — real, but it can wait.
Work top-down and re-run it. Watching the list shrink is genuinely the most satisfying part of building.
A caution about auto-fix
Some tools, the Playground included, offer to fix findings for you. That is a real time-saver — and you should still look at what changed and run your app afterwards. An automatic fix is a suggestion applied quickly, not a guarantee.
Go deeper
For doing this by hand, see How to Test AI-Generated Code and the 15-Minute Pre-Launch Review.
Video deep dives for this stage
Official showcase
Community picks
No videos for this stage yet.