Lovable ships a working app fast, and the parts it does not ask you about are the parts that break in production. Most of what we find sits in the Supabase project behind it.
Leave your app URL for a free first check — we run it and email you the result — or read the 41-point checklist we run against every app.
Lovable wires the client straight to Supabase, so a table without a working policy is readable by any signed-in visitor. The most common variant is not a missing policy but one that says USING (true) — which reads as protected and behaves as open.
A fix applied by hand and then overwritten by the next generation is not a fix. An Audit ($690) writes every fix so that it holds when you keep building in Lovable; Production Readiness ($2,450) is the package where we apply them for you, written the same way. Either way the point is that the fix survives the next prompt.
The anon key belongs in the client. The service role key does not, and it appears in bundles more often than anyone admits. If we find one, it is treated as compromised and has to be rotated, not just removed.
Yes. An Audit gives you the fixes as instructions, written so that applying them survives your next prompt; on Production Readiness we apply them ourselves, the same way. That's the point.
For the free first check, no — just the URL. For an audit, read-only access to the Supabase project behind it. We sign an NDA before anything.
A free first check, an audit at $690, and a checklist you can compare with anyone else's.
SEE PRICING