Loading page…
Loading page…
Blog
Practical security tips for apps built with Lovable, Bolt, Cursor and Supabase. No jargon, with prompts you can paste into your coding agent.
· 6 min read
Vibe coding security checklist: 10 checks before real users sign up, from leaked secrets and database rules to headers and cookies, each easy to verify.
Read the post· 5 min read
Why secret API keys end up in front-end JavaScript built with AI, how to find them with your browser's developer tools, and what to do if one leaked.
Read the post· 5 min read
The Supabase anon key is safe to expose; the service_role key never is. What each key can do, why Row Level Security matters, and how to check your app.
Read the post· 6 min read
Content-Security-Policy, HSTS, frame-ancestors and three more security headers: what each does, a safe starting value and how to check yours.
Read the postChecklists and fix prompts for the tool your app is built with.