Skip to content

The Lovable Feature AtlasIndependent community catalog

Atlas
Security

Security View (Per-Project)

GASecurityReleased Jun 2025All plansSource: docs.lovable.dev

Security View (Per-Project) is Lovable's Security feature: Per-project security review with RLS, code, and dependency scans.

Security View runs RLS analysis, database security checks, code security review, and npm dependency audits per project. Scans trigger automatically on file changes and before publishing, and can be run on-demand.

Example workflows

Starting points built from this record, not transcripts of a run. Each prompt is written the way it should be sent, as one paragraph, and each is worth editing before you send it.

  1. Stand it up from scratch

    You have read the record and want Security View (Per-Project) working in a real project rather than a sandbox.

    Set up Security View (Per-Project) in this project — per-project security review with RLS, code, and dependency scans. Walk it end to end, tell me exactly what you changed, and flag anything I have to switch on myself before it works.

    Expected outcome

    A working setup, a plain list of what changed, and a short list of anything left for you to switch on. Check that list before assuming it is done.

  2. Pre-launch hardening

    The record lists this as one of the jobs Security View (Per-Project) is meant for, so it is a fair first test of whether it fits your app.

    In this project, use Security View (Per-Project) for pre-launch hardening. Build the smallest version that a real user could complete end to end, keep the change scoped to that path, and tell me how to test it myself.

    Expected outcome

    One complete path a user can walk, the files and settings that changed, and the steps to test it. Walk it yourself before you ship it.

  3. Review it before you publish

    Security View (Per-Project) is wired in and you are about to put it in front of people. This is the pass that catches the half-configured version.

    Review how this project uses Security View (Per-Project) before I publish. Check RLS analysis and code security review, list anything that is missing, misconfigured, or only half wired, fix what is safe to fix, and tell me what you left alone and why.

    Expected outcome

    A findings list split into what was fixed and what was left, with a reason for each. Anything left alone is yours to decide on.

  4. Catching RLS misconfigurations

    A second job the record lists for Security View (Per-Project), useful once the first path works.

    Extend this project so Security View (Per-Project) also covers catching RLS misconfigurations. Reuse what is already wired rather than adding a parallel setup, and tell me what you reused and what is new.

    Expected outcome

    A second path built on the same setup, plus a note on what was shared and what was added.

Capabilities

  • RLS analysis
  • Code security review
  • npm dependency audit
  • Pre-publish blocking

Use cases

  • Pre-launch hardening
  • Catching RLS misconfigurations

The link to lovable.dev uses a referral code. The atlas is otherwise unsponsored.

Frequently asked

  • What is Security View (Per-Project)?

    Security View (Per-Project) is Lovable's Security feature: Per-project security review with RLS, code, and dependency scans. Security View runs RLS analysis, database security checks, code security review, and npm dependency audits per project.

  • Is Security View (Per-Project) GA or in beta?

    Security View (Per-Project) is generally available (GA) on Lovable.

  • What Lovable plan includes Security View (Per-Project)?

    Security View (Per-Project) is available on all Lovable plans.

  • When did Security View (Per-Project) launch?

    Security View (Per-Project) launched on Jun 4, 2025.

Related in Security

See all →
Post on XLinkedIn

What Lovable Shipped

One email a week. Every new feature. Nothing else.

A curated Monday roundup of every Lovable feature added or promoted to GA in the past week — pulled straight from the atlas.

No spam. Unsubscribe anytime. Independent, not affiliated with Lovable AB.