Every page about Lovable security is written by Lovable, a scanner vendor, or an agency with a rebuild to sell. This one separates the three incidents behind the headlines, says what a green scan does and does not prove, and walks the leaked-key hour, so you fix the right thing once.

A headline said Lovable apps leak. Or your publish dialog came back with a critical finding you do not understand. Or a user emailed to say they can see someone else's account. Three different things just happened to three different people, and every page that answers 'is Lovable secure' treats them as one question. They are not.

Here is the short version. There are three separate Lovable security stories. Two of them were user apps with the database policies left off, which is a thing you can check in twenty minutes and fix in an afternoon. One of them, the April 2026 incident, was Lovable's own platform, and it is the only one a certificate or a trust page has anything to say about. A green scan is a floor, not a verdict, and Lovable's own documentation says so in plain words. The key that everyone panics about, the anon key sitting in your bundle, is meant to be there. The one that is an incident is a different key. And almost nothing on this page is a reason to rebuild.