Skip to content

Product1 publisher2 min readPublished

Lovable answers its security critics with a free scanner and an admin list of every app

At Dreamforce, Anton Osika said the argument over letting non-engineers ship software is finished. His evidence is automatic vulnerability scanning on every change and connector rules that limit data by who is logged in.

The Product Desk · Product desk

Photograph accompanying Lovable answers its security critics with a free scanner and an admin list of every app
Photo: thenextweb.com

What happened

  • Lovable chief executive Anton Osika told a TIME100 session at Salesforce's Dreamforce that the industry is "way past vibes", answering critics who call AI-built software from non-engineers a security risk.
  • TIME's Ayesha Javed said employees at nearly two-thirds of the Fortune 500 build with Lovable, and that its customers include Adidas and Nvidia.
  • A Nursa leader set out to prototype a nurse-training product and built the whole thing, and the staffing company's leadership then built more than ten apps to replace finance and operations tools, Osika said.
  • Lovable has turned to an insurance policy from Lloyd's to cover AI risk for its enterprise buyers.
  • The 300 McDonald's restaurants in the Nordics run a Lovable-built system for handling incidents and requests on the floor, according to Osika.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

  • decision Security teams at Lovable's enterprise customers choose between blocking a tool colleagues already use and owning the permission review for apps nobody in IT commissioned.
  • exposure A misconfigured connector in an HR app exposes staff records, and the person who set that app up works in HR.
  • contradiction Anyone underwriting the $13.3bn valuation is working from a growth figure the conference room heard and no publisher has since confirmed.
  • precedent Once insurance and admin visibility are part of the pitch, procurement can demand the same paperwork from Cursor and Replit before signing either.

An HR tool should show staff data only to the right managers, Anton Osika said, and he called the question of who can see which data inside an app the harder one [16]. Lovable's connectors, including one for Salesforce, limit what data an app can reach depending on who is logged in [17]. Separately, Lovable scans every change for vulnerabilities automatically and for free, and Osika said AI is getting much better than humans at finding them [14].

Those are two different jobs. A scanner reads code. A connector rule encodes a decision about people, and someone in the business has to make it. Osika said 55% of Lovable's customers and users have more than 11 years of work experience [8]. "People with expertise and close to the problem, they should be the one building software, not people with certain types of certifications," he said [7].

For anyone who has to govern that, the useful part of his account is the inventory. Administrators can see every app built in the company and which ones hold sensitive data, and software engineers can change the code with their own tools [18]. Osika said security teams are starting to see the platform as a way to avoid shadow IT, going from "this last no" to "the first yes" [20].

The evidence for the security claim is a founder on a conference stage. Osika said external penetration testing companies rank Lovable "absolutely in the top", without naming one [15].

The growth figures have the same texture. TIME's Ayesha Javed opened the session with $200m in annual recurring revenue inside a year, tripled in nine months [3]. Triple $200m and the run rate is around $600m [2]. The published trail stops earlier: TechCrunch reported the $200m mark in November 2025, and Bloomberg reported $400m in March 2026 [5]. Lovable raised a $400m Series C at a $13.3bn valuation in August [6].

Osika told buyers to ask who a tool was built for, engineers or everyone else, and said Lovable is built for people without a technical background [22]. A platform lead can add a second question and run it across the apps already live: for each one that touches staff or customer records, name the person who chose the audience. Where that name belongs to the builder rather than to IT, the review sits on the connector settings, not on the scan output. Osika's advice to companies was to run internal hackathons, with employees picking something they are frustrated or passionate about and building a better version [23].

What to watch

  • Whether a named penetration testing firm or a third-party audit of Lovable is published, and what scope it covers.
  • The terms of the Lloyd's policy: which AI risks it covers, the limit, and who is named as the insured.
  • A fresh ARR figure from a publisher, which would settle whether the run rate is nearer $400m or $600m.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories