AI Dispatch
API & DataSubmit
The wirewireOct 8, 2026

AI app-builder Lovable enforces server-side permissions, but calls SOC 2 and GDPR 'support,' not certification

Lovable's security page describes role-based, server-side-enforced permissions and admin-gated publishing. Its compliance language is a support claim rather than an audit, and the company discloses no insurance or outcome-based payment terms.

Lovable, an AI-assisted app-building platform used by what the company calls "millions of builders," enforces access controls at the server level rather than leaving them to client-side code, according to its own security documentation.

"Permissions are role-based and enforced server-side across viewing, editing, approving, and publishing," the company states. Workspace administrators can also gate releases: "Workspace admins can enable auto-fix to let the agent resolve non-breaking findings during basic scans, and can block publishing on critical findings." Lovable logs who did what: "Production publishing can require explicit approval, and all publishing events are logged with user attribution."

On compliance, the company's language stops short of certification. "Lovable supports SOC 2 and GDPR requirements and provides security documentation and data protection agreements for enterprise review," its security page states — a support claim, not an audit result, with no certificate, auditor or audit scope published.

Billing runs on usage, not outcome. Lovable's changelog states: "Lovable charges each request to the workspace that owns the project, under Run credits" — meaning a workspace pays for each AI action regardless of whether it produces the result the customer wanted.

AI Dispatch's trust-gap rubric, scored against Lovable's published material on Oct. 8, finds the company's governance controls ahead of its disclosure on payment and risk transfer. Runtime governance scores 2 of 3: enforced permissions and an admin publish-block, short of a published spend cap or a ceiling on the agent's own authority. Audit trail scores 1 of 3 — publishing events are logged, but nothing is published about tamper-evidence, retention or customer access to that log. Compliance scores 1 of 3 on the certification-versus-support gap described above. Outcome settlement and insurance-indemnity both score 0: payment is tied to usage rather than result, and a full-text search of Lovable's security page (7,824 characters, fetched Sept. 23) and changelog (200,000 characters, same date) found no occurrence of "insurance," "indemnif," "warranty" or "liabilit[y]."

Entries in this piece 1

Published index entries backed by the same source documents this piece cites.

Sources 8

  1. “Permissions are role-based and enforced server-side across viewing, editing, approving, and publishing.”
    lovable.dev · checked Sep 23, 2026
  2. “Workspace admins can enable auto-fix to let the agent resolve non-breaking findings during basic scans, and can block publishing on critical findings.”
    lovable.dev · checked Sep 23, 2026
  3. “Production publishing can require explicit approval, and all publishing events are logged with user attribution.”
    lovable.dev · checked Sep 23, 2026
  4. “Lovable supports SOC 2 and GDPR requirements and provides security documentation and data protection agreements for enterprise review.”
    lovable.dev · checked Sep 23, 2026
  5. “Lovable charges each request to the workspace that owns the project, under Run credits.”
    lovable.dev · checked Sep 23, 2026
  6. “Millions of builders are already turning ideas into reality”
    lovable.dev · checked Aug 4, 2026
  7. “A full-text search of this capture (7,824 characters, fetched 2026-09-23 from https://lovable.dev/security) found no occurrence of insurance, indemnif, warranty or liabilit.”
    lovable.dev · checked Sep 23, 2026
  8. “A full-text search of this capture (200,000 characters, fetched 2026-09-23 from https://lovable.dev/changelog) found no occurrence of insurance, indemnif, warranty or liabilit.”
    lovable.dev · checked Sep 23, 2026