Security guides for AI-built apps.
What each AI dev tool secures by default, and what it quietly leaves to you. Pick your stack to see the real risks, fixes, and a free 30-second audit.
AI dev tools ship working apps astonishingly fast — and they all make security trade-offs on your behalf. Some are sensible defaults. Others quietly leave your database readable by anyone with the anon key, your API routes unauthenticated, or your secrets in the client bundle. The risk profile is different for every stack: what Bolt.new leaves exposed is not what Firebase leaves exposed.
Each guide below covers one stack: what it secures by default, the specific misconfigurations we find most often in real scans, how to fix each one (with copy-paste prompts for your AI editor), and the checks CheckVibe runs automatically against that stack. If you’d rather skip the reading, every guide ends with the same shortcut — paste your URL and get the audit in about 30 seconds.
Is Bolt.new secure?
Bolt.new ships fast. Here's what it doesn't check.
Is Lovable.dev secure?
Lovable builds it pretty. Did it build it locked?
Is v0 by Vercel secure?
v0 generates beautiful UI. The security is your problem.
Is Cursor + Claude Code secure?
Your AI editor ships your code. Did it ship your secrets?
Is Supabase secure?
Supabase is incredible. Without RLS, it's also a public read.
Is Firebase secure?
Firebase Security Rules are powerful — and silently wrong.
Is Replit Agent secure?
Replit Agent ships in minutes. Production security takes hours.
Is Windsurf secure?
Cascade builds whole features autonomously. Audit what it shipped.
Not sure what your stack leaks?
Paste your URL for a free 30-second audit — every finding ships with an AI-ready fix prompt.