Skip to content

Security, in plain language

Short write-ups about what actually goes wrong in AI-built apps, and what to do about it.

Security basics

"Row-level security policy for table objects" on upload

"New row violates row-level security policy for table objects" means your upload has no insert rule. Making the bucket public does not add one.

Security basics

Base44 security scan: the one thing only it can see

The Base44 security scan checks seven kinds of problem from inside your app. Here is the half it reads that nothing outside can, and the half it never looks at.

Security basics

Your API key leaked. Here is the order to do things in

An API key leaked and you want to know what to do first. Not every key in your frontend is one, and the order matters more than the speed.

Security basics

"Infinite recursion detected in policy" without disabling RLS

"Infinite recursion detected in policy for relation" means your Supabase policy asked the table it protects. Here is how to break the circle.

Security basics

"No API key found in request" in Supabase, and the wrong fix

"No API key found in request" means your Supabase request arrived without a key. Most answers you find point at your database rules instead.

Security basics

Is Base44 safe? What 5,442 live Base44 apps showed

Is Base44 safe? We ran nine checks on 5,442 live Base44 apps. Almost all scored B for reasons the owner never chose, and one question nobody can answer.

Security basics

Hide an API key: move it to a Supabase Edge Function

Hiding an API key means moving it off the browser, and a Supabase Edge Function is the smallest place to put it. Two steps around the move matter more.

Security basics

Is your .env file exposed? The twelve paths to check

Is your .env file exposed on your own web server? Twelve addresses tell you in a minute, and a hit means everything in the file is already public.

Security basics

v0 security: all 1,790 v0 apps we scanned got an A

v0 security, measured on 1,790 live v0 apps: every one graded A. Only 17 named a database, and that is most of what the A is measuring.

Security basics

Is Bolt safe? What 1,123 live Bolt apps showed

Is Bolt safe? We ran nine checks on 1,123 live Bolt apps. The hosting came back clean. The findings were API keys and open tables inside the apps.

Security basics

Is Supabase down, or is it your app? How to tell

Is Supabase down, or is it your app? A paused project, a full database and a bug of your own all look like an outage. Four checks tell them apart.

Security basics

Does Supabase encrypt my data? Yes. Here is what it stops

Does Supabase encrypt data? Yes: AES-256 at rest, TLS in transit, SOC 2 and ISO 27001 audited. What each one covers, and the leak none of them stops.

Security basics

Supabase free plan limits, and what happens at each one

The Supabase free plan limits you to 500 MB of database and 5 GB of egress, with no backups. What happens as you cross each line, and what $25 changes.

Backups

Test your Supabase backup before the day you need it

How to test your Supabase backup: restore it into a spare project, compare the row counts, sign in, and check for the line a cut-off file is missing.

Backups

Free Supabase backup with a GitHub Action, and the catch

A Supabase backup GitHub Action costs nothing and suits a lot of apps. The workflow, the connection string that works on GitHub, and the egress each run uses.

Everything here is written by a security expert, and aimed at whoever pressed deploy.

Vlad Tkachenko