UNIVERSAL CHECKS
Applies to every AI-built app
These checks apply regardless of which AI tool built your app or which backend you use. Fail any one of these and your users’ data is at risk.
Supabase, Lovable, Bolt.new, Cursor, Claude Code — each tool generates different blind spots. This is the complete checklist before you go live.
Applies to every AI-built app
These checks apply regardless of which AI tool built your app or which backend you use. Fail any one of these and your users’ data is at risk.
The most common backend for AI-built apps
Supabase is the default backend for most AI coding tools. RLS is the single most important security boundary — and the most frequently misconfigured.
18,000+ users exposed in real breaches
Lovable auto-generates Supabase projects for you. The convenience is the risk: RLS policies are often missing by default, and the generated code assumes you’ll add security later. Most people don’t.
Full-stack generation with hidden gaps
Bolt.new generates complete full-stack apps with API routes, database schemas, and deployment configs. The generated code often works perfectly — but auth middleware and environment isolation can have blind spots.
AI-assisted, developer-owned
With Cursor and Claude Code, you have more control — but AI-generated security policies can have subtle edge cases that pass code review at a glance.
Checklists work if you go through every item. But most people skip steps, miss edge cases, or don't know how to test RLS from the outside.
LaunchGuard runs every check on this list automatically — from the outside, the way an attacker would. It takes about 60 seconds and doesn't require signup.
Or skip the checklist entirely
Free. No signup. Tests everything on this checklist from the outside.