PREFLIGHTX / SECURITY GUIDES
Security guides for AI-built apps
Plain-language, practical guides for founders shipping with Lovable, Bolt, Cursor, v0 and Supabase. What actually leaks, how to check your own app, and how to fix it.
Vibe coding security statistics 2026: what scans found
Published numbers on exposed secrets, open Supabase databases and missing defenses in vibe-coded apps, each with its source, sample size and limits.
Read the guideIs your Supabase database public? Check Row Level Security
Your Supabase public key ships to every browser by design. Row Level Security decides what it can read. Check yours in five minutes and fix it.
Read the guideSecurity headers for AI-built apps: CSP, HSTS and CORS
What each security header prevents, sensible values for a Lovable, Bolt or v0 app, and copy-paste configs for Vercel, Netlify and Cloudflare.
Read the guide.env and .git exposed on your site? How to check and fix
A deployed .env leaks every secret; a deployed .git leaks your whole history. How to check your own site, why SPAs hide it, and how to fix it.
Read the guideExposed API keys in JavaScript: safe to ship or rotate now?
Which API keys are safe in frontend code and which leak money or data, how to find what your app ships, and what to do when a secret is out.
Read the guideSecurity checklist for Lovable, Bolt, Cursor and v0 apps
Twelve checks that catch what AI app builders commonly leave open, ordered to protect the most for the least effort before you launch.
Read the guide
Rather see your own results?
Run a free, read-only scan of your live app. Every finding is shown with a plain-language explanation.
Scan my app — free