GMI Software
Services

Start with the outcome you need to achieve.

Explore all services
Core areas
01AI & AutomationFrom workflow and business case to production02Mobile AppsiOS, Android, React Native03Headless & B2B commerceStores, sales platforms, ERP/PIM integrations
Complementary services
AI-gen developmentAgents, RAG and LLM integrationsE-commerce mobile analyticsFunnel measurement and data-led decisionsProduct Discovery & DesignScope, prototype and delivery planBackend, API & IntegrationsSystems connected to business operationsMaintenance & AuditsStability, performance and continued growthWorkshops & estimationRisks, decisions and fixed-price scope
Not sure where to start?Book a short consultation
Projects

Explore products shaped by clear decisions and measurable outcomes.

All case studies
Delivered productsCase studiesInterfaces, scale and delivery outcomesStarting pointsApp ideas libraryProduct scenarios across 12 industries
Planning a product with similar complexity?Let’s talk
Technologies

We choose the stack around the product, scale and risk.

Explore the full technology stack
MobileReact NativeExplore
CommerceMedusaJS + headlessExplore
Frontend & QA
Next.jsReactTypeScriptPlaywrightMaestro
Backend, DB & cloud
Node.jsNestJSPostgreSQLDockerAWS
AI, 3D & automation
3D configuratorsAI agents & automationRAG & knowledge basesAI-native products
Explore the full technology stack
Tools

Estimate costs and organise decisions before a call.

3 free tools
App cost calculatorEstimate scope and budgetOpen toolE-commerce AI adviserMap decisions, risks and optionsOpen toolE-commerce TCO calculatorCompare SaaS and custom over 5 yearsOpen tool
Discuss your outcome
Company

Meet the people, working model and principles behind GMI.

Get in touch
About usAccountability, history and proofCareersHow we work and open applicationsContactNew projects, support or partnerships
Get in touch
AI Opportunity Sprint
Services
Mobile AppsHeadless & B2B commerceAll services
Projects and results
Technologies
Next.jsNode.jsAWSFull technology stack
Tools
App cost calculatorEstimate scope and budgetE-commerce AI adviserMap decisions, risks and optionsE-commerce TCO calculatorCompare SaaS and custom over 5 years
Meet GMIGet in touch
Back to blog
Mobile apps
Published: September 21, 2026
10 min read

Is your mobile app ready for production?

A practical code, data, testing, release and ownership checklist for React Native and Expo apps.

Mikołaj Lehman, CEO & Founder, GMI Software
Mikołaj Lehman
CEO & Founder, GMI Software

In brief

Production readiness does not depend on whether a team, freelancer or AI tool wrote the code. It requires reproducible builds, safe configuration, tested failure paths, monitoring and explicit ownership.

Production readiness does not depend on whether a team, freelancer or AI tool wrote the code. It requires reproducible builds, safe configuration, tested failure paths, monitoring and explicit ownership.

Secrets, sessions and access

Confirm that secrets are absent from the repository and app bundle, tokens expire correctly and permissions are minimal. Map ownership of the repository, environments, backend and store accounts.

  • Separate development, staging and production configuration.
  • Test logout, session expiry and network loss.
  • Remove unused keys and technical accounts.

Dependencies and architecture

Lock dependency versions, review abandoned libraries and inspect module boundaries. Rapidly generated code can be repetitive without sharing one data and error model.

Data flows and failure paths

Map data from the screen through the API to durable storage. For each critical step, test timeout, retry, duplication, offline behaviour and user feedback.

Tests, performance and crashes

Tests should protect login, payment or the product’s primary transaction. Measure app start, critical-screen responsiveness and behaviour on lower-end devices, then verify crash reporting with a controlled failure.

Monitoring and observability

Before release, decide who sees crashes, API errors and degradation and who responds. Logs must support diagnosis without storing personal data or secrets.

Signing, stores and rollback

A production build should come from a documented process rather than one laptop. Verify certificates, store accounts, privacy labels, phased rollout and the ability to stop or replace a defective release.

  1. Reproduce the build in a clean environment.
  2. Release to internal testers.
  3. Monitor a phased rollout.
  4. Document response and support procedures.

When an independent review helps

An independent review is useful before launch, code handover, investment or major modernisation. It should separate release blockers from improvements, attach evidence and finish with an action plan rather than a loose list of comments.

Definition of Ready before review

A review should not begin by guessing which commit and environment are authoritative. The team identifies the repository, baseline commit, run instructions, expected environment, build access and critical business journeys. If the app cannot be reproduced, that is an audit finding, but the boundary of the attempt must be recorded.

Before work starts, name the decision the review must support: release, take over, remediate or rewrite a selected module. Without this, findings have no useful order. A critical issue is one that affects release, data security, stability of the primary journey or the ability of an accountable team to maintain the product.

Evidence, priorities and recheck

Every material finding should include a code or configuration location, reproduction conditions, impact and recommendation. Priority without evidence can be opinion, while a screenshot without context does not support a decision. The remediation plan should identify task dependencies and the condition for rechecking each finding.

After changes, the team should not close an issue solely because a pull request changed the code. Repeat the scenario, build or measurement that exposed the risk. React Native release checklist can organise the separate publishing stage, but it does not replace evidence specific to the product and its infrastructure.

Define the production-readiness audit scope

If an existing React Native or Expo app is approaching production or a technical handover, start by qualifying the product, available access and the decision the review must support.

Next step

Define the audit scopeSee the SFD mobile app case study

A mobile product example based on verified, publicly available evidence.

Frequently asked questions

Does an AI-built app need a different audit?
No. The criteria concern system behaviour, code quality, release and ownership rather than the tool used to create it.
Does this checklist replace a security audit?
No. It is a production-readiness review, not a pentest, certification or legal opinion.
Does the audit include fixing the code?
The standard audit ends with findings and an action plan. Remediation and retesting require a separately agreed scope.

Content updated: September 21, 2026

Mikołaj Lehman, CEO & Founder, GMI Software
Mikołaj Lehman
CEO & Founder, GMI Software

Mikołaj Lehman is the CEO and founder of GMI Software. On the blog, he covers decisions around mobile apps, ecommerce and digital product delivery.

  • Mobile apps and React Native
  • Headless and B2B ecommerce
  • MedusaJS
  • Digital product delivery

Google Preferred Sources

See GMI more often in Google

Add gmi.software as a preferred source. Google may highlight our new articles more often in Top Stories and supported AI experiences.

Share article:

Related articles

Mobile apps

In-house vs agency for mobile app development

A comparison of building a mobile app in-house or with an agency: hiring cost, start speed, accountability, app store quality, maintenance and knowledge transfer.

→
E-commerce

MedusaJS + Next.js for B2B storefronts: architecture, cost and risks

A practical guide to B2B storefronts: MedusaJS v2 as commerce core, Next.js as the buying portal, customer groups, price lists, sales channels, ERP/PIM and implementation cost.

→
Contact

Let's talk
about the project.

Have an app idea or need technological support? Write to us — we'll prepare a preliminary analysis and estimate within 48h. Projects that go through our DDT process (Discovery, Design & Technology) come with a price guarantee and a fixed-price agreement — a key differentiator for us.

Write to us[email protected]
Visit us
GD
gmi.software Sp. z o.o.ul. Jana Heweliusza 11 / 819
80-890 Gdansk, PolandNearshore product delivery across EU, UK and US time zones.
NIP: 5252816287KRS: 0000830003
gmi.
ServicesOur projectsBlogBrief assistantContact
LIFAINGI
Mobile Trends Awards 2025 nomination - SFD app
© 2026 gmi.software Sp. z o.o.
Privacy PolicyTerms