Skip to content

Not verified

Database row rules

Whether the row rules behind the app actually stop one signed in account reading another's rows.

Last updated September 20, 2026

Needs a signed-in account

Why a check from outside cannot see it

A check can see that a table answers the public key. Whether the rule on it is the right rule requires reading the policy, and policies are not published.

How to check it yourself

  1. 1Sign in as one account and note the id of a record it owns.
  2. 2Sign in as a second account and request the first account's record by id through the API.
  3. 3Repeat for every table that holds customer data, not just the one on the page you remembered.

Sign in as one account and request another account's record by id through the API.

What a Launch Review does instead

Launch Review, $199

A reviewer reads the policies, then asks for another account's record by id and confirms the database refuses.

See what a Launch Review covers

Incidents that involved this

  • Not verified

    First-quarter 2026 assessment of 200 apps

    183 of 200 vibe-coded apps, 91.5 percent, contained at least one vulnerability traceable to AI hallucination or missing security context.

  • Observed

    Moltbook records exposure

    An app exposed 4.75 million records, including 1.5 million API tokens and 35,000 email addresses.

  • Not verified

    Tea app, first breach

    An unprotected storage instance exposed tens of thousands of user images, including identity documents.

  • Not verified

    Tea app, second breach

    Three days after the first breach, over a million private messages were exposed through an API endpoint with no access control.

  • Observed

    Lovable-built apps, CVE-2025-48757

    Broken access control reported across 170 production applications built with Lovable.

See all nine items

ShipReady is not a penetration test or a security certification. No automated check can prove an application is secure.

Last updated September 20, 2026