Skip to main content
Base44 to Production

Base44 to production, without skipping the security scan.

Base44's own documentation makes this plain: the platform provides the tools, but you are responsible for your app's security settings, and you should always run a security scan before publishing. We run that review properly, configure what Base44 hands you correctly, and document what happens if something goes wrong.

See Our Process
Trusted by businesses worldwide
0Hosting choice to make; the backend stays on Base44
SOC 2 & ISO 27001Platform-certified, app-level review still yours
1–2 wksFor a launch readiness review
Residency-ReadyEU, UK or US data location, if your plan needs it
Overview

What does Base44 to production involve?

Base44 to production is different from launching a Lovable or Bolt.new app, because there is no separate host to pick: Base44's backend, database, and hosting stay on its own infrastructure by design. The launch work instead focuses on configuring what Base44 already provides correctly.

That means running the built-in security scan, setting the right app visibility, verifying a custom domain through DNS, and documenting what a real incident would require. Base44's own security page states plainly that the platform provides the tools, but you are responsible for your app's security settings.

Scan before Publish
Base44's own guidance calls this step out explicitly.
Visibility on purpose
Public or Private chosen for a reason, then verified.
Verified, not added
A domain serves traffic only once DNS verification passes.
Restore scope written
Who can recover what, documented before an incident.

Three launch levels, set by who uses the app.

Teams reach production readiness through one of these, and the right one depends on what the app handles.

LevelWhat it coversWhere it falls short
Publish as-isClick Publish, accept default visibility and data rules.Skips the security scan Base44 explicitly recommends running first.
Reviewed launchSecurity scan cleared, visibility set deliberately, domain verified, backups documented.Still runs on standard workspace settings, not residency or compliance controls.
Compliance-grade launchElite or Enterprise data residency, a Data Processing Agreement, and controls mapped to your requirements.Costs more and requires a higher-tier Base44 plan.
The Deep Dive

Platform certification isn't the same as app security.

What Base44's certificates actually cover, and which launch level fits you.

SOC 2 Type II and ISO 27001 cover Base44, not your configuration

Base44 holds both certifications at the platform level, alongside GDPR compliance. That certification covers Base44's own infrastructure, not whether your specific app's visibility, data rules, and roles are configured correctly, which remains the builder's responsibility according to Base44's own documentation.

Reviewed launch, or compliance-grade launch?

Choose a reviewed launch if your app serves general users with no regulatory data residency requirement. Choose a compliance-grade launch if you need data stored in a specific region, a signed Data Processing Agreement, or evidence to hand an enterprise buyer's security team.

The Launch Checklist

The 10 checks every Base44 launch passes.

We test each one against your actual configuration, not just the default.

Security scan run and cleared
Every flagged issue is reviewed and fixed with safe defaults or a manual rule, not dismissed.
App visibility set on purpose
Public or Private is chosen for a reason, not left on whatever Base44 defaulted to.
Public and private areas separated correctly
A mixed app uses 2 linked apps and a subdomain, following Base44’s documented pattern.
Access rules reviewed per data entity
Every entity's rule is checked individually, not accepted as one blanket default.
Custom domain fully verified
The TXT record is published, and the domain's status shows verified, not just added.
Rate limits understood, not fought
Endpoints are rate-limited platform-wide by default, so the app is built to work within that.
Data residency confirmed if required
EU, UK, or US storage is set explicitly on Elite or Enterprise plans where compliance demands it.
Data Processing Agreement in place
A DPA is requested and signed wherever GDPR or similar regulation applies.
Backup and restore scope documented
What is backed up, how long it is kept, and who can start a restore, written down.
Native integrations tested end to end
Stripe, Slack, Sheets, or Twilio connections are exercised for real, not just connected.

Why the scan comes before Publish, not after.

Fixing a visibility or access mistake before launch costs a fraction of fixing it after real data is exposed.

Open data caught early

Misplaced credentials and login gaps found before real users arrive.

No accidental Public

A private app stays private, by a deliberate setting.

The domain actually serves

Verified traffic, not just a record that was added.

Restore scope on paper

Documented before an incident forces the question.

Residency matched

To what your customers or regulators actually require.

Two layers, reviewed apart

Platform certification and your own app-level configuration.

Launch work founders bring us.

We scope the launch around what your app handles and who it serves.

01

Security scan & fix review

The built-in scan run, every finding reviewed, and fixes applied per data entity.

02

Visibility & access configuration

Public or Private set deliberately, with mixed public and private areas structured correctly.

03

Custom domain setup & verification

DNS records published and confirmed verified, not left in a pending state.

04

Data residency & compliance setup

EU, UK, or US data location configured, with a Data Processing Agreement requested where needed.

05

Backup & restore documentation

A written record of what is backed up, retention, and who can initiate recovery.

06

Integration testing & launch review

Stripe, Slack, Sheets, and Twilio flows exercised end to end before real traffic arrives.

Readiness Check

Signs you need Base44 to production help.

Four situations send most founders to us.

  • 01

    You haven't run the security scan yet

    Publish is one click away, and nobody has checked what the scan would find.

  • 02

    You're not sure Public or Private is right

    The app handles real data, and visibility was never a deliberate decision.

  • 03

    A customer asks about data residency

    An enterprise buyer or regulator wants a specific answer you cannot yet give.

  • 04

    Nobody knows the backup and restore plan

    An incident would leave the team guessing what can actually be recovered.

Common launch mistakes we help you avoid.

These five mistakes account for most Base44 launches that go wrong.

01

Publishing without running the security scan

Critical

Base44's own guidance calls this step out explicitly. We run it and review every finding first.

02

Leaving visibility on the default

Critical

Public and Private carry real consequences. We set the value on purpose, then verify it.

03

Treating "domain added" as "domain live"

High

A domain only serves traffic once DNS verification passes. We confirm status, not just setup.

04

Assuming platform certification covers app configuration

Critical

SOC 2 and ISO 27001 cover Base44's infrastructure, not your app's rules. We review both layers separately.

05

Skipping backup documentation

Medium

Assuming backups exist is not the same as knowing retention and restore scope. We write it down.

How we take your Base44 app to production.

Six stages, from review to a documented launch. We keep you informed with full visibility throughout.

01

Readiness review

We review your app, its visibility setting, and its intended users, then recommend a launch level.

3–5 days · Review
02

Security scan & fixes

We run the scan, review every finding, and apply fixes per data entity.

3–7 days · Security
03

Visibility & domain configuration

We set app visibility deliberately and verify your custom domain through DNS.

2–4 days · Configuration
04

Residency & compliance setup

We configure data location and request a Data Processing Agreement where required.

1–2 weeks · Compliance
05

Integration testing

We exercise every native integration end to end, not just confirm the connection.

3–5 days · Testing
06

Launch & documentation handover

We launch with you and hand over written backup, restore, and recovery documentation.

1–2 days · Go-live

Base44 to production cost and timeline.

Three factors drive the price: how much data-entity review your app needs, whether data residency applies, and how many integrations require testing. Base44's own subscription and plan-tier costs are billed separately by Wix.

Launch Readiness ReviewBest for: a small app about to launch
Investment
$2,000–$5,000
Timeline
1–2 weeks
Security
Scan & fix review
Setup
Visibility & domain verified
Recovery
Backup documentation
Production Configuration BuildBest for: apps with real users and real data
Investment
$5,000–$12,000
Timeline
2–4 weeks
Access
Full data-entity review
Integrations
Tested end to end
Structure
Public/private built correctly
Compliance-Grade LaunchBest for: regulated or enterprise-bound apps
Investment
$12,000–$25,000+
Timeline
4–8 weeks
Residency
Data location configured
Legal
Data Processing Agreement
Evidence
Controls mapped for review
Our Stack

The tools and platform features behind your launch.

Base44's own built-in tools, configured properly, backed by review no default setting replaces.

Base44 Native Tools
Security Scan & Security CenterApp Visibility ControlsCustom Domain & DNS Verification
Compliance & Residency
SOC 2 Type IIISO 27001GDPR & Data Processing AgreementEU / UK / US Data Residency
Native Integrations
StripeSlackGoogle SheetsTwilio

Ways to work with us.

Pick the model that fits where your launch stands today. All are fixed-scope with no long-term lock-in.

Launch Readiness Review

A fast pass for apps about to publish for the first time.

Best before first publish

Production Configuration Build

Full access review and integration testing before real users arrive.

Best for real user data

Compliance-Grade Launch

Data residency, DPA, and control mapping for regulated or enterprise apps.

Best for regulated apps

Post-Launch Retainer

Ongoing review support as your Base44 app grows.

Best after go-live
What's Included

Every launch comes complete.

No hidden gaps. Each launch includes everything your team needs to operate the app afterward.

Security review
The scan run and every finding resolved.
Visibility & access
Public, Private, and mixed structures set correctly.
Domain verification
DNS confirmed, not just configured.
Residency setup
EU, UK, or US data location, where required.
DPA request
Handled wherever GDPR or similar rules apply.
Backup documentation
Retention and restore scope written down.
Integration testing
Every connection exercised, not just linked.
Written handover
A record your team can follow after we're gone.

Base44 to production across every kind of app.

The checklist stays the same. The launch level changes with what your app handles.

Non-Technical Founders

First launches that need a safe, deliberate publish.

Internal Tools Teams

Employee-data apps that need visibility set correctly.

Small Business Owners

Customer-facing apps handling real bookings or accounts.

Agencies Shipping Client Apps

Base44 builds that need a professional production handoff.

EU & UK-Bound Products

Apps needing data residency outside the US default.

Growth-Stage Products

Apps facing enterprise security questionnaires for the first time.

Regulated Industries

Teams needing a documented compliance posture before launch.

Multi-App Workspaces

Teams running separate public and private Base44 apps together.

FAQ

Base44 to production questions

The questions founders ask us most before launching.

Base44 to production means correctly configuring the app you already have on Base44's infrastructure, since there is no separate host to choose. The work covers running and clearing the security scan, setting the right visibility, verifying your custom domain, and documenting backup and restore scope before real users arrive.

Yes. Base44's Security page includes a scan that checks for common problems, such as overly open data, credentials left in the wrong place, and login gaps. Base44's own documentation states that you are responsible for your app's security settings and should run this scan before publishing.

A Public app opens for anyone with the link. A Private app opens only for email addresses you explicitly invite. This setting sits in your app’s dashboard under App Visibility, and picking the wrong one either blocks real users or exposes the app to anyone who finds the URL.

Not within a single app. Base44's documented workaround creates a separate public app for the landing page, publishes both apps, links the landing app to the main private app, and assigns your primary domain to the landing page with a subdomain for the private app.

You add the domain in your app's settings, publish a TXT record at your DNS provider to prove ownership, then link the domain so Base44's hosting starts serving it. The domain only counts as ready once its verification status shows verified, not merely added.

Yes. All public endpoints are rate-limited by default, with no configuration available on your part. Rate limits apply per person, so capacity scales with how many people use your app, rather than a single fixed ceiling for the whole app.

Yes, on Elite and Enterprise plans. Workspaces store data in the United States by default, and paid tiers add the option to store your app's data in the EU, UK, or US instead, which matters for regulated or region-bound data.

Yes. Base44 states it holds SOC 2 Type II certification confirmed by independent audit and ISO 27001 certification, alongside GDPR compliance with a Data Processing Agreement available on request. Your own app-level configuration still needs a separate review, since platform certification does not cover how you set up visibility, roles, or data rules.

Base44 to production costs $2,000 to $25,000 or more, depending on scope. A launch readiness review costs $2,000 to $5,000, a production configuration build costs $5,000 to $12,000, and a compliance-grade launch costs $12,000 to $25,000 or more.

A launch readiness review takes 1 to 2 weeks, a production configuration build takes 2 to 4 weeks, and a compliance-grade launch takes 4 to 8 weeks depending on data residency and certification requirements.

Base44 Development builds and extends features. Base44 App Rescue repairs an app that is already broken or leaking credits. Base44 to Production takes the app you have and configures visibility, security, domain, and compliance correctly before real users arrive.

No. Launch work runs as fixed-scope projects. Any ongoing support afterward works month-to-month with no long-term lock-in.