Security · October 8, 2026 · 3 min read

Is your Lovable app safe to launch? A 12-point security checklist

AI app builders are very good at making things work. They are much less careful about making things safe, because a security hole doesn't show up in the preview. The app looks finished, so it ships.

These are the twelve checks worth running before real users and real data arrive. Most take minutes. None need you to read every line of code.

Keys and secrets

  1. Search the frontend code for secret keys. Anything starting with sk_, a Supabase service_role key, or a private API token must never be in code that runs in the browser. Open your live site, view the page source and the JavaScript bundles, and search for them.
  2. Check environment variables. Variables prefixed NEXT_PUBLIC_, VITE_ or EXPO_PUBLIC_ are bundled into the client. Only values that are safe to publish belong there.
  3. Rotate anything that ever leaked. If a secret was committed to Git, even once, deleting it isn't enough. Generate a new key and revoke the old one.

Database access

  1. Turn on row-level security for every table. In Supabase, a table without RLS can be read and written by anyone holding your public anon key, which is every visitor.
  2. Read every policy. A policy whose condition is simply true lets everyone through. Most tables need a condition like user_id = auth.uid().
  3. Test as a stranger. Sign up as a second user and try to load the first user's records by changing an ID in a request. If it works, so will an attacker's attempt.

Auth and accounts

  1. Check permissions on the server, not the screen. Hiding an admin button isn't protection. Every admin action must be checked by the database or an API, because anyone can call the API directly.
  2. Don't trust editable profile fields for roles. If "role: admin" lives in data the user can update about themselves, they can make themselves an admin.
  3. Turn on email confirmation and rate limits, so one script can't create ten thousand accounts or try ten thousand passwords.

Files, payments and the rest

  1. Make storage buckets private unless the files are meant to be public. Invoices, IDs and avatars uploaded by users usually aren't.
  2. Confirm payments on the server. Unlock paid features from a verified Stripe webhook, never from a redirect to a success page a user could visit by hand.
  3. Turn on backups and try a restore. Point-in-time recovery costs little compared to explaining lost data to customers.

If more than two of these made you unsure, that's normal, and it's exactly what a Tech Check covers. You get every finding rated by severity, in plain language, with a fixed price to fix it.

Keep reading

Want a second pair of eyes on your app?

Book a Tech Check