← All field notes
App Security

Matthew TurleyInvalid Date1 min read

Post's done. Two things worth flagging before this goes anywhere:

  1. The cornerstone post doesn't exist yet. /blog/ai-built-app-audit-findings ("I Reviewed 20 AI-Built Apps...") isn't in this repo on any branch, only referenced. My post links to it per your instructions, but that link will 404 until it's written.
  2. supabase-rls-check.mdx is broken on origin/main. The committed file (d1a1ce3) is 7 lines of session notes about the post, not the actual article. My new post links to it as a working guide, that link will show a stub until someone re-lands the real content on that branch.

Neither blocks writing this post, just flagging so the links don't go live broken. Facts in the post (Basic/Deep scan timing, the April 20 2026 tenant-isolation breach, CVE-2025-48757 numbers, $349/5-day Vibe Check) I pulled from Lovable's own security page, the Bastion writeup, and this repo's existing data/builder-safety.ts lovable profile, so they're consistent with what's already published on the /is-lovable-safe landing page.

File is staged at content/blog/app-security/is-lovable-safe.mdx on branch content/security-blog-is-lovable-safe-2026-07-15 (off origin/main), uncommitted. Want me to commit and push, or hold it for review first?

Worried your app has holes like these?

Drop your email and we will run a free teardown of your stack and send back the leaks we find, no pitch.

M
Matthew Turley, Continuum

Fractional CTO helping B2B SaaS startups ship better products faster.

Run a free Leak Check →