Is my Replit app secure?
Replit builds, hosts and publishes in one place, and its agent can change code and data while you work. Before customers arrive, check what the agent can touch, where the keys live, and how you would restore.
What Replit handles.
- ✓Hosting for published apps, served over HTTPS
- ✓A Secrets tool that encrypts keys and hands them to the app as environment variables
- ✓A Security Center that scans dependencies and code, and reviews the files the agent changes for hardcoded secrets
- ✓A scan before publishing, with a setting that can block publishing on critical findings
From the platform’s own documentation: Replit docs: Project Security Center · Replit docs: Secrets
What stays yours.
- →Which database the agent can write to while you build, and keeping production out of reach
- →A backup you have restored at least once
- →Authorization on every route: the server checks who is asking
- →Keys in Secrets, rotated if one ever reached the code
- →Security headers on the published app
Documented.
Public reports that involve Replit or apps built on it, dated and linked. Each line says what its source says, and nothing more.
- July 21, 2025An AI agent deleted a production database
The Register reports that Replit’s agent deleted the production database of SaaStr founder Jason Lemkin despite instructions not to make changes without permission, and ignored a code freeze instruction. Replit first told him a rollback was impossible; the rollback later worked.
Source: The Register, July 21, 2025 - June 2, 2026A scan of 1,072 Supabase-backed apps
Symbiotic Security scanned 1,072 apps built with Lovable, v0, Bolt.new, Replit and Windsurf that use Supabase. It reports that 98% had at least one vulnerability, 308 exposed the anon key in JavaScript, 172 allowed data to be changed or deleted without signing in, and 197 had a CORS misconfiguration on the Supabase API.
Source: Symbiotic Security, June 2, 2026 - May 7, 2026About 380,000 public assets built with AI coding tools
eWeek reports that Red Access found about 380,000 publicly accessible assets created with AI coding tools, on platforms including Lovable, Replit, Netlify and Base44, and that around 5,000 of them exposed potentially sensitive information such as medical and financial records.
Source: eWeek, May 7, 2026
A five minute check.
In your own Replit dashboard, in this order.
- Run the Security CenterIn the Tools pane, open Security Center and run a scan. Read critical and high findings first.
- Turn on publish blockingIn the publishing security settings, set Block publishing of critical vulnerabilities, so a critical finding stops the release.
- Find every keyOpen Secrets and list what is there. Then search the code for sk_, key= and token. Anything found in code moves to Secrets and gets rotated.
- Separate building from productionConfirm which database the agent writes to during a session. Production data should not be the one it experiments on.
- Test a restoreFind your latest backup or restore point and restore it to a copy. A backup you have never restored is a guess.
Questions.
Can the Replit agent change my live data?
It works with whatever access the project gives it. The Register reported a case in July 2025 where it deleted a production database despite instructions not to make changes. Keep production credentials out of the workspace the agent edits.
Is the Security Center enough?
It covers dependencies and common insecure patterns well. It does not decide which of your users should see which records; that is your authorization logic, and it is what an audit reads line by line.
Do I need to move off Replit?
No. Most fixes are configuration and a few server-side checks. The app can stay where it is.
Check the public side now.
Ten seconds. We read only what any visitor’s browser already sees, and store nothing.
Opens the app security check on this site with your address filled in.
How it works, in four steps.
Scan
Check the protections any visitor’s browser can see, then run the deeper scan on an app you prove is yours.
Run the scan → 2 · AuditAI-Build Audit
A signed report within 48 hours: what is exposed, what you own, and the order to fix it in.
Ask for the audit → 3 · FixFix
The report’s list, fixed for a set price by a set date. If we miss the target, the next week is on me.
Ask about the fix → 4 · GuardGuard
A weekly automated scan, dependency and model updates, a monthly senior review, and one named person who answers.
Ask about Guard →