You commented LAUNCH. Here are all thirty, written as prompts you can paste straight into Claude.

One thing the reel couldn't fit: the order matters more than the list. Do the security ten first. It's the only column where a single miss exposes someone else's data. The rest cost you leads or rankings, and those you can fix next week.

The one-paste version

Open Claude Code at the root of your project and paste this.

ROLE: You are auditing my website before it goes live.
TASK: Check the site against the 30 items below and fix everything that fails.
STEPS: For each item answer PASS, FAIL or N/A, and quote the file and line that proves it.
Then fix every FAIL, one commit per item, starting with Security.
RULES: Never mark PASS without evidence. If an item needs a setting outside the code
(DNS, Cloudflare, Supabase dashboard, Google Ads), tell me exactly where to change it
instead of guessing. Do not add llms.txt or FAQ schema.
OUTPUT: A table of all 30 with status and evidence, then the fixes.

SECURITY
1. Row Level Security on every public table, deny by default
2. No private keys in NEXT_PUBLIC_ or VITE_ variables
3. Auth middleware on every admin, dashboard and internal API route
4. Rate limits on login, signup, password reset and forms
5. Cloudflare Turnstile on public forms, verified server-side
6. Content-Security-Policy, Strict-Transport-Security, X-Content-Type-Options
7. npm audit in CI, failing on high severity
8. 301 http to https and to the canonical host
9. Error tracking with alerts
10. Automated daily database backups, with a tested restore

FOUND BY AI
11. sitemap.xml with lastmod set to the real content change date
12. Self-referencing rel=canonical on every indexable page
13. No noindex left in production
14. Organization and LocalBusiness JSON-LD
15. Visible author bylines linked to a bio page
16. Every page reachable from an internal link
17. robots.txt allows OAI-SearchBot, Claude-SearchBot, PerplexityBot
18. INP under 200ms on mobile
19. Skip llms.txt
20. Skip FAQ schema

LEADS AND LEGAL
21. SPF, DKIM and DMARC on the sending domain
22. One-click unsubscribe headers on marketing email
23. Unticked consent checkbox before any phone number field
24. Honour the Global Privacy Control signal
25. No ad or tracking cookies before consent
26. Google Consent Mode v2 for UK and EEA visitors
27. WCAG 2.2 AA: contrast, keyboard navigation, focus states, alt text
28. Meta Conversions API, deduplicated with the pixel
29. Google Ads enhanced conversions
30. UTM parameters captured into hidden form fields

Security: do these ten first

1. Turn on RLS. "Enable Row Level Security on every table in the public schema. Deny by default, then add a policy per table."
Why: without it, a Supabase table can be read through the public API. Tables you created with raw SQL or an ORM don't get it switched on for you, so check each one.

2. Keys server-side. "Move every private key out of NEXT_PUBLIC_ and VITE_ variables."
Why: anything with those prefixes ships inside the browser bundle. The Supabase anon key is meant to be public, but it's only safe with item 1 done.

3. Lock admin routes. "Add deny-by-default auth middleware to every /admin, /dashboard and internal API route."
Why: broken access control is number one on the OWASP Top 10.

4. Rate-limit logins. "Add per-IP and per-account rate limits to login, signup, password reset and every form endpoint."

5. Turnstile on forms. "Add Cloudflare Turnstile to every public form and verify the token on the server."
Note: it's free, with widget and hostname limits that only matter if you run a lot of sites.

6. CSP and HSTS. "Set Content-Security-Policy with frame-ancestors, Strict-Transport-Security and X-Content-Type-Options: nosniff."

7. npm audit. "Run npm audit before every deploy and fail CI on high-severity issues."

8. Force HTTPS. "301 redirect http to https, and the non-canonical host to the canonical one, on the server."

9. Error tracking. "Wire up error tracking so front-end and API errors alert me."

10. Daily backups. "Confirm automated daily database backups are on, and show me how to restore one."
A backup you've never restored is a guess.

Found by AI: eight to do, two to skip

Google's own documentation says there are "no additional requirements to appear in AI Overviews or AI Mode, nor other special optimizations necessary." So this column is mostly the basics done properly, plus two things to stop doing. Google: AI features and your website

11. Honest lastmod. "Generate sitemap.xml with lastmod set to the real last content change, not the build date, and submit it in Search Console."
Why: Google only trusts lastmod when it's consistently accurate. Bump it on every deploy and it gets ignored.

12. Canonical tags. "Add a self-referencing rel=canonical to every indexable page."
Why: Google treats rel=canonical as a strong signal and a sitemap as a weak one. Google on canonicals

13. Kill the staging noindex. "Search the codebase and response headers for noindex and remove it from production."
Why: a noindex tag drops the page from Google Search entirely. Google on noindex

14. LocalBusiness schema. "Add Organization and LocalBusiness JSON-LD with name, address, phone, hours and sameAs links."
Note: this helps normal search features. Google says no special schema is needed for AI Overviews.

15. Author bylines. "Add a visible author byline on every article, linked to a bio page."

16. No orphan pages. "Make every page reachable from at least one internal link, and list any page that isn't."

17. Allow AI search bots. "In robots.txt allow OAI-SearchBot, Claude-SearchBot and PerplexityBot, and check Cloudflare isn't blocking search crawlers."
Note: those are the search bots. The training crawlers (GPTBot, ClaudeBot) are separate, so you can block training and still get found. Blocking Google-Extended doesn't affect Google Search either. Google's crawler list

18. INP under 200ms. "Measure Interaction to Next Paint on mobile and get it under 200ms."
Why: INP replaced FID in Core Web Vitals in March 2024.

19. Skip llms.txt. Google's John Mueller, June 2025: "FWIW no AI system currently uses llms.txt." His post

20. Skip FAQ schema. Since August 2023 Google only shows FAQ rich results for well-known government and health sites. It won't hurt you, but it won't get you the dropdowns or into AI Overviews either.

Leads and legal: the ten that cost you quietly

21. SPF, DKIM, DMARC. "Set up SPF, DKIM and DMARC on the domain that sends your email, including contact form notifications."
Why: Google and Yahoo require all three from bulk senders. Small senders still land in spam without them.

22. One-click unsubscribe. "Add RFC 8058 one-click unsubscribe headers to every marketing email."

23. Phone consent box. "Add an unticked consent checkbox with clear wording before any form collects a phone number."
US note: the FCC's stricter one-to-one consent rule was struck down in January 2025. Plain prior express consent still applies.

24. Honour GPC. "Detect the Global Privacy Control signal and treat it as an opt-out of sale and sharing."
US note: California requires it, and more states do once you pass their thresholds.

25. Consent first. "Don't load advertising or tracking cookies until the visitor opts in."
UK note: the Data (Use and Access) Act 2025 carved out a narrow exception for some analytics cookies. Ad cookies still need consent.

26. Consent Mode v2. "If we use Google Ads or Analytics with UK or EEA visitors, implement Consent Mode v2."

27. WCAG 2.2 AA. "Audit contrast, keyboard navigation, focus states and alt text against WCAG 2.2 AA, and fix every failure."
Why: 3,117 website accessibility lawsuits were filed in US federal court in 2025, according to Seyfarth Shaw's ADA Title III tracker. The European Accessibility Act has applied since June 2025.

28. Meta CAPI. "Add the Meta Conversions API alongside the pixel, deduplicated with a shared event_id."
Skip the event_id and every lead counts twice.

29. Enhanced conversions. "Turn on Google Ads enhanced conversions for the lead form."

30. UTMs into forms. "Capture utm_source, utm_medium and utm_campaign into hidden fields on every form."
Then every lead tells you which ad paid for it.

What this does not fix

  • None of it makes the offer better. A site that passes all thirty and sells the wrong thing still sells nothing.

  • The legal notes are the rules I build my own sites to. They aren't legal advice, and your thresholds depend on where your customers are.

  • Items 9, 10 and 30 need a real test: break something, restore something, submit a form from an ad link. Reading the code won't tell you.

And most importantly, make no mistakes.

Reply and tell me which item your site failed. I'll tell you what I'd fix first.