Playbooks & production notes

Security

Security guidance for AI-built apps: authentication, authorization, tenant isolation, secrets, storage, and public endpoints.

The trust boundaries AI coding tools quietly skip: auth, row-level security, secrets, storage rules, and endpoints that never check who is calling. Written for founders shipping from Lovable, Base44, Cursor, or Claude Code. Start with "Vibe Coding Security: The Real Risk Ranking From 26 Audits", then "Is Lovable Safe?".

Security

Code Audit Service: How to Choose One and What to Ask For

7 min read
Security

Do I Need a Pen Test? What SOC 2 and Customers Actually Require

12 min read
Security

Vibe Coding Security Scanner: 5 Tools Compared

10 min read
Security

API Security Checklist for AI-Built Apps

22 min read
Security

Are Vibe Coded Apps Safe? The Security Risks and How to Check

15 min read
Security

OWASP LLM Top 10 2026: The Risks Explained

28 min read
Security

Vibe-Coded App Hacked? Signs, Real Cases, and What to Do Now

21 min read
Security

How to Secure Vibe-Coded Apps When You Can’t Read the Code

18 min read
Security

Vibe Coding Security Checklist: 12 Checks, Each With a Test (2026)

17 min read
Security

GitHub Copilot Security Risks: What Each Plan Does and Does Not Cover

20 min read
Security

Firebase Security Rules: Examples, Patterns and Tests

20 min read
Security

Is Cursor Safe? Security, Privacy, and Agent Risks

21 min read
Security

Is Firebase Secure? What Google Protects and You Configure

23 min read
Security

Is Bolt.new Safe? What Its Security Audit Can and Cannot Prove

21 min read
Security

Lovable App Security Checklist: Five Tests to Run

14 min read
Security

Is Replit Safe in 2026? Platform Controls, Secrets, Forking, and Agent Code

21 min read
Security

How to Test Supabase RLS: Database and API Tests

19 min read
Security

Supabase Row Level Security: What a Policy Decides, and What It Cannot

19 min read