Security, in plain language
Short write-ups about what actually goes wrong in AI-built apps, and what to do about it.

"Row-level security policy for table objects" on upload
"New row violates row-level security policy for table objects" means your upload has no insert rule. Making the bucket public does not add one.

Base44 security scan: the one thing only it can see
The Base44 security scan checks seven kinds of problem from inside your app. Here is the half it reads that nothing outside can, and the half it never looks at.

Your API key leaked. Here is the order to do things in
An API key leaked and you want to know what to do first. Not every key in your frontend is one, and the order matters more than the speed.

"Infinite recursion detected in policy" without disabling RLS
"Infinite recursion detected in policy for relation" means your Supabase policy asked the table it protects. Here is how to break the circle.

"No API key found in request" in Supabase, and the wrong fix
"No API key found in request" means your Supabase request arrived without a key. Most answers you find point at your database rules instead.

Is Base44 safe? What 5,442 live Base44 apps showed
Is Base44 safe? We ran nine checks on 5,442 live Base44 apps. Almost all scored B for reasons the owner never chose, and one question nobody can answer.

Hide an API key: move it to a Supabase Edge Function
Hiding an API key means moving it off the browser, and a Supabase Edge Function is the smallest place to put it. Two steps around the move matter more.

Is your .env file exposed? The twelve paths to check
Is your .env file exposed on your own web server? Twelve addresses tell you in a minute, and a hit means everything in the file is already public.

v0 security: all 1,790 v0 apps we scanned got an A
v0 security, measured on 1,790 live v0 apps: every one graded A. Only 17 named a database, and that is most of what the A is measuring.

Is Bolt safe? What 1,123 live Bolt apps showed
Is Bolt safe? We ran nine checks on 1,123 live Bolt apps. The hosting came back clean. The findings were API keys and open tables inside the apps.

Is Supabase down, or is it your app? How to tell
Is Supabase down, or is it your app? A paused project, a full database and a bug of your own all look like an outage. Four checks tell them apart.

Does Supabase encrypt my data? Yes. Here is what it stops
Does Supabase encrypt data? Yes: AES-256 at rest, TLS in transit, SOC 2 and ISO 27001 audited. What each one covers, and the leak none of them stops.

Supabase free plan limits, and what happens at each one
The Supabase free plan limits you to 500 MB of database and 5 GB of egress, with no backups. What happens as you cross each line, and what $25 changes.

Test your Supabase backup before the day you need it
How to test your Supabase backup: restore it into a spare project, compare the row counts, sign in, and check for the line a cut-off file is missing.

Free Supabase backup with a GitHub Action, and the catch
A Supabase backup GitHub Action costs nothing and suits a lot of apps. The workflow, the connection string that works on GitHub, and the egress each run uses.
Everything here is written by a security expert, and aimed at whoever pressed deploy.
Vlad Tkachenko