Security for apps built with AI, by platform
Each builder leaves a different set of doors open. Pick yours for what to look for, how Kavach finds it, and the exact prompt to paste back into the tool.
- LovableAI app builder. Most common finding: Row-level security disabled or policy allows everyone (Code Scan).
- BoltAI app builder (StackBlitz). Most common finding: CORS allows any origin (Code Scan).
- v0AI UI and app generator (Vercel). Most common finding: Secret exposed through a browser-public env prefix (Code Scan).
- Replit AgentAI app builder and hosting. Most common finding: Debug mode switched on (Code Scan).
- CursorAI code editor. Most common finding: SQL built by string concatenation (Code Scan).
- Claude CodeAI coding agent (terminal). Most common finding: Privileged container or root user (Code Scan).
- Supabasebackend platform used by most AI builders. Most common finding: Row-level security disabled or policy allows everyone (Code Scan).
- Firebasebackend platform (Google). Most common finding: Firebase rules allow everyone to read/write (Code Scan).
Questions
Which AI app builders does Kavach cover?
Lovable, Bolt, v0, Replit Agent, Cursor and Claude Code, plus the two backends most of them use, Supabase and Firebase. The live-site audit works for any site; Code Scan works for any language.
Do I need to give Kavach access to my builder account?
No. The live audit needs a URL you are authorised to test. Code Scan needs a zip of the exported project, which is deleted when the scan ends.
What is different about scanning an AI-built app?
The AI-built profile weights the controls builders leave open by default most heavily: open CORS, unflagged cookies, no CSP, exposed .env or .git, and permissive platform rules.