AI Dispatch
API & DataSubmit
agent · ai-coding-agents

Lovable

lovable.devevidence retrieved Aug 4, 2026 – Sep 23, 2026view as JSONall ai-coding-agents entries30 alternatives
Reviewed12 or more fields evidenced, and scored by a human against the published rubric

18 fields evidenced · 37 with no public information. Every value below links to the document it came from and the date we checked it.

Runtime governance
2/3

Are scope, spend, and authority enforced while the agent runs?

Permissions are role-based and enforced server-side across viewing, editing, approving and publishing, and workspace admins can block publishing on critical security-scan findings. That is authority enforced at run time, stated on the vendor's own /security page. Not 3: no spend cap, no limit on the agent's own action scope, and no customer-configurable authority ceiling is published.

Counts Permission scopes and Runtime governance, each cited below.

Audit trail
1/3

Is there a tamper-evident record of what it actually did?

All publishing events are logged with user attribution, so a record of consequential actions exists. Not 2 or 3: nothing is published about tamper-evidence, hash-chaining, retention, or customer review or export of that log. Scored 1 and therefore a trust gap.

Counts Audit trail, each cited below.

How this gap gets closed →
Compliance
1/3

Are compliance obligations attached per engagement?

The /security page states Lovable "supports SOC 2 and GDPR requirements" and provides security documentation and data protection agreements for enterprise review. That is a support claim, not a certification: no certificate, auditor, report date or audit scope is published. Scored 1 and deliberately not read as certified - the hedge in the vendor's own wording is the finding.

Counts Compliance certifications, each cited below.

How this gap gets closed →
Outcome settlement
0/3

Does payment depend on a verified result?

An evidenced zero rather than an absence: the changelog states each request is charged to the workspace that owns the project under Run credits, so payment is per usage regardless of result, which is rubric 0 as written. No escrow, milestone release or clawback on failure is published.

Rests on Settlement mechanism and Outcome-based pricing, recorded as undisclosed and cited below. For a 0 that absence is the finding. What a score rests on

How this gap gets closed →
Insurance & indemnity
0/3

Can the deployment be insured, and is the customer indemnified?

No public evidence found. insurance_available, insurance_carriers, coverage_limits and indemnification are all recorded no_public_information against the captured pages. Reported as a finding, not as a gap in our checking.

Rests on Indemnification, Insurance carriers, Coverage limits and Insurance available, recorded as undisclosed and cited below. For a 0 that absence is the finding. What a score rests on

How this gap gets closed →

Assurance

Insurance available
no public information
lovable.dev · checked Aug 4, 2026 · source did not state this
Insurance carriers
no public information
lovable.dev · checked Aug 4, 2026 · source did not state this
Coverage limits
no public information
lovable.dev · checked Aug 4, 2026 · source did not state this
Indemnification
no public information
lovable.dev · checked Aug 4, 2026 · source did not state this
Liability cap
no public information
lovable.dev · checked Aug 4, 2026 · source did not state this
Audit trail
All publishing events are logged with user attribution
“Production publishing can require explicit approval, and all publishing events are logged with user attribution.”
lovable.dev · checked Sep 23, 2026
Tamper-evident log
no public information
lovable.dev · checked Aug 4, 2026 · source did not state this
Explainability
no public information
lovable.dev · checked Aug 4, 2026 · source did not state this
Runtime governance
Workspace admins can block publishing on critical security-scan findings.
“Workspace admins can enable auto-fix to let the agent resolve non-breaking findings during basic scans, and can block publishing on critical findings.”
lovable.dev · checked Sep 23, 2026
Permission scopes
Role-based, server-side-enforced permissions across viewing, editing, approving, and publishing
“Permissions are role-based and enforced server-side across viewing, editing, approving, and publishing.”
lovable.dev · checked Sep 23, 2026
Compliance certifications
Supports SOC 2 and GDPR requirements; provides security documentation and data protection agreements for enterprise review
“Lovable supports SOC 2 and GDPR requirements and provides security documentation and data protection agreements for enterprise review.”
lovable.dev · checked Sep 23, 2026
Regulatory alignment
no public information
lovable.dev · checked Aug 4, 2026 · source did not state this
Outcome-based pricing
no public information
lovable.dev · checked Aug 4, 2026 · source did not state this
Settlement mechanism
no public information
lovable.dev · checked Aug 4, 2026 · source did not state this
Dispute process
no public information
lovable.dev · checked Aug 4, 2026 · source did not state this
SLA terms
no public information
lovable.dev · checked Aug 4, 2026 · source did not state this
Evaluation coverage
no public information
lovable.dev · checked Aug 4, 2026 · source did not state this

Agency

Autonomy level
An AI agent can automatically resolve non-breaking security scan findings when auto-fix is enabled by workspace admins
“Workspace admins can enable auto-fix to let the agent resolve non-breaking findings during basic scans”
lovable.dev · checked Sep 23, 2026
Human oversight
no public information
lovable.dev · checked Aug 4, 2026 · source did not state this
Goal complexity
no public information
lovable.dev · checked Aug 4, 2026 · source did not state this
Action space
no public information
lovable.dev · checked Aug 4, 2026 · source did not state this
Operating environment
no public information
lovable.dev · checked Aug 4, 2026 · source did not state this
Initiative
no public information
lovable.dev · checked Aug 4, 2026 · source did not state this

Safety

Safety evaluations
no public information
lovable.dev · checked Aug 4, 2026 · source did not state this
Red teaming
no public information
lovable.dev · checked Aug 4, 2026 · source did not state this
Safety policy
no public information
lovable.dev · checked Aug 4, 2026 · source did not state this
Usage restrictions
no public information
lovable.dev · checked Aug 4, 2026 · source did not state this
Model or system card
no public information
lovable.dev · checked Aug 4, 2026 · source did not state this
Incident reporting
no public information
lovable.dev · checked Aug 4, 2026 · source did not state this
Third-party evaluations
no public information
lovable.dev · checked Aug 4, 2026 · source did not state this
Data handling
Customer data resides in the region selected (EU, US, or Asia Pacific) and does not move across regions by default
“Customer data is hosted in Lovable Cloud in supported regions including the EU, US, and Asia Pacific. Data residency is region-specific and does not move across regions by default.”
lovable.dev · checked Sep 23, 2026

Practicality

Pricing model
Charged per request against the owning workspace's Run credits.
“Lovable charges each request to the workspace that owns the project, under Run credits.”
lovable.dev · checked Sep 23, 2026
Price point
no public information
lovable.dev · checked Aug 4, 2026 · source did not state this
Availability
no public information
lovable.dev · checked Aug 4, 2026 · source did not state this
Deployment options
no public information
lovable.dev · checked Aug 4, 2026 · source did not state this
Integrations
Connects to Slack, Notion and HubSpot, reachable from Lovable in Telegram.
“Lovable in Telegram can now work in your connected tools, such as Slack, Notion, or HubSpot”
lovable.dev · checked Sep 23, 2026
Supported regions
Regional data hosting available in the EU, US, and Asia Pacific
“Lovable Cloud supports regional data hosting in the EU, US, and Asia Pacific.”
lovable.dev · checked Sep 23, 2026
Support model
no public information
lovable.dev · checked Aug 4, 2026 · source did not state this

Foundation models

Base models
App AI features default to Gemini 3.7 Flash
“Gemini 3.7 Flash is now the default model”
lovable.dev · checked Sep 23, 2026
Model provider
Google is a model provider (Gemini) for app AI features
“Gemini 3.7 Flash is now the default model”
lovable.dev · checked Sep 23, 2026
Model swappable
Apps can specify their own model instead of the Lovable default
“Apps that already specify a model are unaffected”
lovable.dev · checked Sep 23, 2026
Open weights
Replicate connector gives apps access to thousands of open-source AI models
“Replicate lets apps run thousands of open-source AI models”
lovable.dev · checked Sep 23, 2026
Fine-tuning
Apps can run the customer's own fine-tuned models.
“apps powered by your own fine-tuned models”
lovable.dev · checked Sep 23, 2026
Context window
no public information
lovable.dev · checked Aug 4, 2026 · source did not state this

Ecosystem

Protocols supported
Runs an MCP server that works with locally-run MCP clients supporting OAuth.
“The Lovable MCP server now works with any MCP client that runs on your computer and supports OAuth.”
lovable.dev · checked Sep 23, 2026
Tool use
no public information
lovable.dev · checked Aug 4, 2026 · source did not state this
Multi-agent
no public information
lovable.dev · checked Aug 4, 2026 · source did not state this
API access
A Lovable API collection is published in the Postman API Network.
“The Lovable API collection is now in the Postman API Network.”
lovable.dev · checked Sep 23, 2026
Open source
no public information
lovable.dev · checked Aug 4, 2026 · source did not state this
Marketplace presence
Listed on the Slack App Marketplace
“installs Lovable from the Slack Marketplace”
lovable.dev · checked Sep 23, 2026

Impact

User base
Millions of builders
“Millions of builders are already turning ideas into reality”
lovable.dev · checked Aug 4, 2026
Deployment scale
no public information
lovable.dev · checked Aug 4, 2026 · source did not state this
Target sectors
no public information
lovable.dev · checked Aug 4, 2026 · source did not state this
High-risk domains
no public information
lovable.dev · checked Aug 4, 2026 · source did not state this
Documented incidents
no public information
lovable.dev · checked Aug 4, 2026 · source did not state this

In the wire

Reporting backed by the same source documents as Lovable’s own evidenced fields.

Frequently asked

What is Lovable?
Integrates: Connects to Slack, Notion and HubSpot, reachable from Lovable in Telegram.
How much does AI Dispatch know about Lovable, and how is it verified?
18 fields are evidenced, each with a cited source document and retrieval date. 37 are recorded as no public information — meaning the cited source does not state it, not a gap AI Dispatch has left unchecked.
Does Lovable have a published trust gap?
Yes — 4 of 5 scored dimensions (Audit trail, Compliance, Outcome settlement, Insurance & indemnity) is rated 0 or 1 out of 3 by a human reviewer against AI Dispatch's published trust-gap rubric.
What are the alternatives to Lovable?
30 other published ai coding agents entries are in the same category as Lovable in the AI Dispatch index, each with its own cited fields.