AI Dispatch
The wirewireSep 24, 2026

AI coding agent Lovable requires approval for production publishing and logs every publish event; discloses no insurance, liability cap or SLA

Lovable's security page names role-based permissions, an audit trail and SOC 2/GDPR support. Insurance, liability caps and service-level terms are absent.

AI coding agent Lovable, which builds web applications from natural-language prompts, enforces server-side permissions and logs every production publish with the acting user's identity, according to the company's security page reviewed by AI Dispatch. The company discloses no insurance, liability cap, indemnification or service-level terms on the same page.

Lovable's runtime controls give administrators a check on automated changes. "Workspace admins can enable auto-fix to let the agent resolve non-breaking findings during basic scans, and can block publishing on critical findings," the company states. Production changes are not silent: "Production publishing can require explicit approval, and all publishing events are logged with user attribution," according to the page.

Access itself is role-gated rather than left to client-side trust. "Permissions are role-based and enforced server-side across viewing, editing, approving, and publishing," the company says.

Lovable also names two compliance frameworks and describes region-bound data handling. "Lovable supports SOC 2 and GDPR requirements and provides security documentation and data protection agreements for enterprise review," the page states. On where customer data lives: "Customer data is hosted in Lovable Cloud in supported regions including the EU, US, and Asia Pacific. Data residency is region-specific and does not move across regions by default."

What the same review did not find: no insurance product, liability cap, indemnification clause or published service-level agreement appears on Lovable's site. AI Dispatch's index records all four as "no public information."

The pattern is uneven across the trust-gap dimensions the index tracks. Lovable discloses governance controls, an audit trail and named compliance frameworks — three of the five dimensions AI Dispatch scores. It discloses nothing on a fourth, insurance and indemnity, or on the service commitments that would back a runtime guarantee.

AI Dispatch's full index and sourcing are published at aidispatch.news, with a source URL, retrieval timestamp and quote attached to every field.

Sources 5

  1. Workspace admins can enable auto-fix to let the agent resolve non-breaking findings during basic scans, and can block publishing on critical findings.
    lovable.dev · checked Sep 23, 2026
  2. Production publishing can require explicit approval, and all publishing events are logged with user attribution.
    lovable.dev · checked Sep 23, 2026
  3. Permissions are role-based and enforced server-side across viewing, editing, approving, and publishing.
    lovable.dev · checked Sep 23, 2026
  4. Lovable supports SOC 2 and GDPR requirements and provides security documentation and data protection agreements for enterprise review.
    lovable.dev · checked Sep 23, 2026
  5. Customer data is hosted in Lovable Cloud in supported regions including the EU, US, and Asia Pacific. Data residency is region-specific and does not move across regions by default.
    lovable.dev · checked Sep 23, 2026