Is my Bolt app secure?
Bolt builds and publishes from the browser, with a database and sign-in available in the same project. Its own audit and database security page are the place to start; the rules they flag are yours to settle.
What Bolt handles.
- ✓Publishing and hosting for the app
- ✓A built-in database, or a Supabase project you connect
- ✓A security audit from the Publish menu on paid plans, covering data access, authentication, input handling and secrets
- ✓A database Security page that flags missing row level security policies and permissions that are too open
From the platform’s own documentation: Bolt docs: Check your project’s security · Bolt docs: Database security settings
What stays yours.
- →A row level security policy on every table, written for how your users relate to each other
- →Keys for paid services kept out of the code sent to visitors
- →Sign-up and sign-in settings that match who the app is for
- →Storage settings for uploaded files
- →Security headers on the published app
Documented.
Public reports that involve Bolt or apps built on it, dated and linked. Each line says what its source says, and nothing more.
- June 2, 2026A scan of 1,072 Supabase-backed apps
Symbiotic Security scanned 1,072 apps built with Lovable, v0, Bolt.new, Replit and Windsurf that use Supabase. It reports that 98% had at least one vulnerability, 308 exposed the anon key in JavaScript, 172 allowed data to be changed or deleted without signing in, and 197 had a CORS misconfiguration on the Supabase API.
Source: Symbiotic Security, June 2, 2026 - May 8, 2026A scan of 5,600 live apps built with AI tools
VentureBeat reports that Escape.tech scanned 5,600 publicly available apps built with AI tools in October 2025 and found more than 2,000 high-impact vulnerabilities, over 400 exposed secrets and 175 instances of exposed personal data. The report does not break the results down by platform.
Source: VentureBeat, May 8, 2026
A five minute check.
In your own Bolt dashboard, in this order.
- Run the security auditClick Publish, then Run security audit. Read data access and secrets findings first.
- Open database securityClick the database icon at the top of the project, then Security. Every missing RLS policy listed there is a table to settle before launch.
- Read the policiesFor tables that hold one person’s data, the policy should compare the signed-in user to an owner column, not allow everyone.
- Search the published app for keysOpen the live app’s developer tools and search the loaded scripts for service_role, sk_live and secret.
- Check authentication settingsIn the database’s authentication settings, confirm who can sign up and how they confirm their email.
Questions.
Does Bolt’s audit cost tokens?
Bolt’s docs say neither the audit nor its fixes use your tokens. It is available on paid plans.
The audit said to ask Bolt to fix it. Is that enough?
Often it is for the issues it lists. Check the result: open the policy it wrote and confirm it says what you meant, because a policy can be valid and still too open.
What if I connected my own Supabase project?
Then the same checks run in the Supabase dashboard: RLS on every table, policies per user, storage buckets, and keys.
Check the public side now.
Ten seconds. We read only what any visitor’s browser already sees, and store nothing.
Opens the app security check on this site with your address filled in.
How it works, in four steps.
Scan
Check the protections any visitor’s browser can see, then run the deeper scan on an app you prove is yours.
Run the scan → 2 · AuditAI-Build Audit
A signed report within 48 hours: what is exposed, what you own, and the order to fix it in.
Ask for the audit → 3 · FixFix
The report’s list, fixed for a set price by a set date. If we miss the target, the next week is on me.
Ask about the fix → 4 · GuardGuard
A weekly automated scan, dependency and model updates, a monthly senior review, and one named person who answers.
Ask about Guard →