Lovable
18 fields evidenced · 37 with no public information. Every value below links to the document it came from and the date we checked it.
Also appears in
Trust gap
How this is scoredAre scope, spend, and authority enforced while the agent runs?
Permissions are role-based and enforced server-side across viewing, editing, approving and publishing, and workspace admins can block publishing on critical security-scan findings. That is authority enforced at run time, stated on the vendor's own /security page. Not 3: no spend cap, no limit on the agent's own action scope, and no customer-configurable authority ceiling is published.
Counts Permission scopes and Runtime governance, each cited below.
Is there a tamper-evident record of what it actually did?
All publishing events are logged with user attribution, so a record of consequential actions exists. Not 2 or 3: nothing is published about tamper-evidence, hash-chaining, retention, or customer review or export of that log. Scored 1 and therefore a trust gap.
Counts Audit trail, each cited below.
How this gap gets closed →Are compliance obligations attached per engagement?
The /security page states Lovable "supports SOC 2 and GDPR requirements" and provides security documentation and data protection agreements for enterprise review. That is a support claim, not a certification: no certificate, auditor, report date or audit scope is published. Scored 1 and deliberately not read as certified - the hedge in the vendor's own wording is the finding.
Counts Compliance certifications, each cited below.
How this gap gets closed →Does payment depend on a verified result?
An evidenced zero rather than an absence: the changelog states each request is charged to the workspace that owns the project under Run credits, so payment is per usage regardless of result, which is rubric 0 as written. No escrow, milestone release or clawback on failure is published.
Rests on Settlement mechanism and Outcome-based pricing, recorded as undisclosed and cited below. For a 0 that absence is the finding. What a score rests on
How this gap gets closed →Can the deployment be insured, and is the customer indemnified?
No public evidence found. insurance_available, insurance_carriers, coverage_limits and indemnification are all recorded no_public_information against the captured pages. Reported as a finding, not as a gap in our checking.
Rests on Indemnification, Insurance carriers, Coverage limits and Insurance available, recorded as undisclosed and cited below. For a 0 that absence is the finding. What a score rests on
How this gap gets closed →Assurance
- Insurance available
- no public informationlovable.dev · checked Aug 4, 2026 · source did not state this
- Insurance carriers
- no public informationlovable.dev · checked Aug 4, 2026 · source did not state this
- Coverage limits
- no public informationlovable.dev · checked Aug 4, 2026 · source did not state this
- Indemnification
- no public informationlovable.dev · checked Aug 4, 2026 · source did not state this
- Liability cap
- no public informationlovable.dev · checked Aug 4, 2026 · source did not state this
- Audit trail
- All publishing events are logged with user attribution
“Production publishing can require explicit approval, and all publishing events are logged with user attribution.”
lovable.dev · checked Sep 23, 2026 - Tamper-evident log
- no public informationlovable.dev · checked Aug 4, 2026 · source did not state this
- Explainability
- no public informationlovable.dev · checked Aug 4, 2026 · source did not state this
- Runtime governance
- Workspace admins can block publishing on critical security-scan findings.
“Workspace admins can enable auto-fix to let the agent resolve non-breaking findings during basic scans, and can block publishing on critical findings.”
lovable.dev · checked Sep 23, 2026 - Permission scopes
- Role-based, server-side-enforced permissions across viewing, editing, approving, and publishing
“Permissions are role-based and enforced server-side across viewing, editing, approving, and publishing.”
lovable.dev · checked Sep 23, 2026 - Compliance certifications
- Supports SOC 2 and GDPR requirements; provides security documentation and data protection agreements for enterprise review
“Lovable supports SOC 2 and GDPR requirements and provides security documentation and data protection agreements for enterprise review.”
lovable.dev · checked Sep 23, 2026 - Regulatory alignment
- no public informationlovable.dev · checked Aug 4, 2026 · source did not state this
- Outcome-based pricing
- no public informationlovable.dev · checked Aug 4, 2026 · source did not state this
- Settlement mechanism
- no public informationlovable.dev · checked Aug 4, 2026 · source did not state this
- Dispute process
- no public informationlovable.dev · checked Aug 4, 2026 · source did not state this
- SLA terms
- no public informationlovable.dev · checked Aug 4, 2026 · source did not state this
- Evaluation coverage
- no public informationlovable.dev · checked Aug 4, 2026 · source did not state this
Agency
- Autonomy level
- An AI agent can automatically resolve non-breaking security scan findings when auto-fix is enabled by workspace admins
“Workspace admins can enable auto-fix to let the agent resolve non-breaking findings during basic scans”
lovable.dev · checked Sep 23, 2026 - Human oversight
- no public informationlovable.dev · checked Aug 4, 2026 · source did not state this
- Goal complexity
- no public informationlovable.dev · checked Aug 4, 2026 · source did not state this
- Action space
- no public informationlovable.dev · checked Aug 4, 2026 · source did not state this
- Operating environment
- no public informationlovable.dev · checked Aug 4, 2026 · source did not state this
- Initiative
- no public informationlovable.dev · checked Aug 4, 2026 · source did not state this
Safety
- Safety evaluations
- no public informationlovable.dev · checked Aug 4, 2026 · source did not state this
- Red teaming
- no public informationlovable.dev · checked Aug 4, 2026 · source did not state this
- Safety policy
- no public informationlovable.dev · checked Aug 4, 2026 · source did not state this
- Usage restrictions
- no public informationlovable.dev · checked Aug 4, 2026 · source did not state this
- Model or system card
- no public informationlovable.dev · checked Aug 4, 2026 · source did not state this
- Incident reporting
- no public informationlovable.dev · checked Aug 4, 2026 · source did not state this
- Third-party evaluations
- no public informationlovable.dev · checked Aug 4, 2026 · source did not state this
- Data handling
- Customer data resides in the region selected (EU, US, or Asia Pacific) and does not move across regions by default
“Customer data is hosted in Lovable Cloud in supported regions including the EU, US, and Asia Pacific. Data residency is region-specific and does not move across regions by default.”
lovable.dev · checked Sep 23, 2026
Practicality
- Pricing model
- Charged per request against the owning workspace's Run credits.
“Lovable charges each request to the workspace that owns the project, under Run credits.”
lovable.dev · checked Sep 23, 2026 - Price point
- no public informationlovable.dev · checked Aug 4, 2026 · source did not state this
- Availability
- no public informationlovable.dev · checked Aug 4, 2026 · source did not state this
- Deployment options
- no public informationlovable.dev · checked Aug 4, 2026 · source did not state this
- Integrations
- Connects to Slack, Notion and HubSpot, reachable from Lovable in Telegram.
“Lovable in Telegram can now work in your connected tools, such as Slack, Notion, or HubSpot”
lovable.dev · checked Sep 23, 2026 - Supported regions
- Regional data hosting available in the EU, US, and Asia Pacific
“Lovable Cloud supports regional data hosting in the EU, US, and Asia Pacific.”
lovable.dev · checked Sep 23, 2026 - Support model
- no public informationlovable.dev · checked Aug 4, 2026 · source did not state this
Foundation models
- Base models
- App AI features default to Gemini 3.7 Flash
“Gemini 3.7 Flash is now the default model”
lovable.dev · checked Sep 23, 2026 - Model provider
- Google is a model provider (Gemini) for app AI features
“Gemini 3.7 Flash is now the default model”
lovable.dev · checked Sep 23, 2026 - Model swappable
- Apps can specify their own model instead of the Lovable default
“Apps that already specify a model are unaffected”
lovable.dev · checked Sep 23, 2026 - Open weights
- Replicate connector gives apps access to thousands of open-source AI models
“Replicate lets apps run thousands of open-source AI models”
lovable.dev · checked Sep 23, 2026 - Fine-tuning
- Apps can run the customer's own fine-tuned models.
“apps powered by your own fine-tuned models”
lovable.dev · checked Sep 23, 2026 - Context window
- no public informationlovable.dev · checked Aug 4, 2026 · source did not state this
Ecosystem
- Protocols supported
- Runs an MCP server that works with locally-run MCP clients supporting OAuth.
“The Lovable MCP server now works with any MCP client that runs on your computer and supports OAuth.”
lovable.dev · checked Sep 23, 2026 - Tool use
- no public informationlovable.dev · checked Aug 4, 2026 · source did not state this
- Multi-agent
- no public informationlovable.dev · checked Aug 4, 2026 · source did not state this
- API access
- A Lovable API collection is published in the Postman API Network.
“The Lovable API collection is now in the Postman API Network.”
lovable.dev · checked Sep 23, 2026 - Open source
- no public informationlovable.dev · checked Aug 4, 2026 · source did not state this
- Marketplace presence
- Listed on the Slack App Marketplace
“installs Lovable from the Slack Marketplace”
lovable.dev · checked Sep 23, 2026
Impact
- User base
- Millions of builders
“Millions of builders are already turning ideas into reality”
lovable.dev · checked Aug 4, 2026 - Deployment scale
- no public informationlovable.dev · checked Aug 4, 2026 · source did not state this
- Target sectors
- no public informationlovable.dev · checked Aug 4, 2026 · source did not state this
- High-risk domains
- no public informationlovable.dev · checked Aug 4, 2026 · source did not state this
- Documented incidents
- no public informationlovable.dev · checked Aug 4, 2026 · source did not state this
In the wire
Reporting backed by the same source documents as Lovable’s own evidenced fields.
Frequently asked
- What is Lovable?
- Integrates: Connects to Slack, Notion and HubSpot, reachable from Lovable in Telegram.
- How much does AI Dispatch know about Lovable, and how is it verified?
- 18 fields are evidenced, each with a cited source document and retrieval date. 37 are recorded as no public information — meaning the cited source does not state it, not a gap AI Dispatch has left unchecked.
- Does Lovable have a published trust gap?
- Yes — 4 of 5 scored dimensions (Audit trail, Compliance, Outcome settlement, Insurance & indemnity) is rated 0 or 1 out of 3 by a human reviewer against AI Dispatch's published trust-gap rubric.
- What are the alternatives to Lovable?
- 30 other published ai coding agents entries are in the same category as Lovable in the AI Dispatch index, each with its own cited fields.