Skip to content

Security, in plain language

Short write-ups about what actually goes wrong in AI-built apps, and what to do about it.

Page 3 of 5

Backups

Supabase project paused? Your data is still there

Supabase paused your project after a week of inactivity. Nothing is deleted, Restore sits beside the project name, and you have a year before that changes.

Security basics

Which AI app builder is safest? We scanned 30,998 apps

Which AI app builder is safest? We scanned 30,998 live apps from Lovable, Base44, Replit, v0 and Bolt. The builder is not what decides your grade.

Security basics

Enable Row Level Security on every Supabase table, then prove it

Enabling Row Level Security in Supabase with no policy locks a table completely. A policy without the setting does nothing. Here is the SQL, and the test.

Security basics

Supabase "RLS disabled in public": what the warning misses

Supabase reports "RLS disabled in public" as an error. It says nothing about the read policy that leaves your table just as open to strangers.

Security basics

How to rotate a leaked Supabase service_role key

Supabase says fix the leak first. Other guides say rotate now. Which is right depends on where your service_role key leaked.

Security basics

Vibe coding security scanners compared, including ours

The best vibe coding security scanner comes down to three questions no feature list answers. Ten tools compared, with prices, and the jobs Reeve does not do.

Security basics

Supabase security checker: run the five checks yourself

A Supabase security checker reads your published app instead of your project settings. Here are the five checks it runs, and how to run each one yourself.

Security basics

Vibe coding security scanner: what a URL scan misses

A vibe coding security scanner reads your live app from outside. Here is what that covers, the four things it cannot see, and how to read the result.

Security basics

Missing security headers: when it actually matters

Missing security headers is the finding our scanner prints most. Here is what it protects against, and when it is the least urgent line on your report.

Security basics

Your OpenAI API key is exposed in your frontend. Rotate it.

An OpenAI API key exposed in your frontend cannot be locked to a domain. Rotate it today, move the call behind your own endpoint, and cap the spend.

Security basics

An API key exposed in your frontend: what 30,998 apps shipped

An API key exposed in your frontend is usually a Google Maps key. We scanned 30,998 live vibe-coded apps and counted which secrets actually leak.

Backups

Supabase backup tools compared, including ours

Four kinds of Supabase backup tool, what each one actually copies, and the case where a free GitHub Action beats paying anyone, us included.

Security basics

How to use secrets in Replit, and what still gets published

How to use secrets in Replit: add one, read it back, and fix the two reasons it comes back undefined. Plus the keys the Secrets tool cannot keep private.

Backups

Supabase free tier backups: how to make one without a terminal

There are no Supabase free tier backups, so the copy has to come from you. How to make one from the dashboard, and what CSV leaves out.

Security basics

Is Supabase secure? Yes. Your project is a separate question

Is Supabase secure? The platform is audited, encrypted and pen-tested. Their own compliance documents say where that stops and your settings begin.

Everything here is written by a security expert, and aimed at whoever pressed deploy.

Vlad Tkachenko