Production Check · Lovable

You built it on Lovable. Now it has to hold.

You got further than anyone expected. The app works, people like it, and now there are real users, real data and maybe real money on the horizon. The question you can't answer alone: is this safe to ship?

Book a 30-minute call

What we do here.

Lovable apps share a shape: a React front end, a Supabase database, and the security of the whole thing resting on row-level security policies that Lovable does not reliably write. That shape has had three public incidents in thirteen months. In 2025, a scan of 1,645 Lovable apps found 170 exposing their data through missing policies (CVE-2025-48757). In February 2026, a university project leaked 18,697 records the same way. In April 2026, a flaw in the platform itself let any account read other users' source code, database keys and chat history, for every project created before November 2025.

So the check starts where Lovable apps break. Row-level security on every table, verified by trying to read what we shouldn't. Keys: the Supabase service key and any third-party key that ended up in the client. Authentication flows, including the ones Lovable generates for you. Rate limits and abuse, because the first real users include bots. Costs, because edge functions and AI calls can run away on a Sunday. Backups. Error handling that doesn't show users the database. And if your project predates November 2025, we rotate everything the platform breach exposed and check your audit logs for the sixty days around it.

Then we fix the must-fix list, in your codebase, and give you the list of what can wait. If it can't be made to hold, we tell you before you spend more.

What you get.

  • A written assessment in plain words: security, data, reliability, cost, and what happens when it gets popular

  • The must-fix items, fixed by us, in your codebase

  • A prioritised list of what can wait, and what to watch

  • One number: what it would take to go further, if you want to

  • Someone to call. That's the point.

How it runs.

1

Send us access

The repository, the hosting, and a thirty-minute walkthrough of what it does.

2

We check

Ten working days. We read, we run, we try to break it.

3

You get the verdict

A call and a document. Ship, fix first, or stop.

4

We fix

The must-fix list, agreed with you, done in your codebase.

Proof

Primento · handed over, September 2026

Metabooks: built with them, now run by them

Designed and built in two and a half months, then run alongside their team until their own people took it over this month, as planned.

Read the case

Three questions.

Can I keep building on Lovable afterwards?
Yes. The check doesn't move you off it. It makes what's there safe and tells you what to watch as you keep prompting.
Our data is European. Does that matter?
It does. We check where your Supabase project lives and what the app collects, and we tell you what GDPR expects of you in plain words. If personal data was exposed by the April 2026 breach, there's a 72-hour notification clock; we'll tell you if it applies.
I don't understand the code. Will I understand the report?
That's what it's for. Written in plain words, with the technical detail in an annex for whoever builds next.

Price.

Fixed price: €2,900 excl. VAT, prepaid. Includes the check, the verdict within ten working days of access, and up to two days of must-fix work in your codebase. Further fixes at €900 per day, agreed before we start. If our verdict is "stop", the unused fix days are refunded.

Not for.

  • An idea without code yet.
  • A product nobody will use.
  • Anyone who wants to be told it's fine.
  • Two tools that don't talk. That's the Integration mission.

Tell us about Lovable.

Lean builders. We deliver.