# Which AI app generators produce production-ready code?

**Answer:** None of them, by itself. Production readiness comes down to a short list of checks: row level security and policies on every exposed table, no secrets in client code, env vars per environment, auth redirect URLs, webhook signature verification, storage policies, backups and error monitoring. Verify them on the repo and on the live project before launch. Lovable, Bolt, v0, Replit Agent and coding agents each document checks that cover part of that list.

## Why this matters

Many launch checks are settings and rules, not code style: a table without row level security, a secret key in the browser bundle, a redirect URL still on localhost. Some live only in the database or a provider dashboard, where the generated code cannot show them. The vendor details below come from each vendor's own docs, read on 2026-09-30.

## Check these yourself, whichever tool wrote the app

- Row level security: every table in an exposed schema has RLS enabled and a policy for each operation. Supabase warns that such a table without RLS is readable and writable by any role with a grant on it; confirm it on the live project with the Security Advisor. Without RLS, every API route verifies permissions first, as Replit's security checklist asks.
- Secrets: Supabase's secret key bypasses RLS and stays on the server. Next.js inlines NEXT_PUBLIC_ variables and Lovable embeds VITE_ values into the browser bundle, so no secret gets either prefix.
- Env vars: set each one in every Vercel environment that needs it and redeploy after a change, since changes apply only to new deployments.
- Auth redirect URLs: change the Supabase Site URL from localhost to your production URL, which Supabase calls critical for email confirmations and password resets, and use exact redirect paths in production.
- Webhooks: verify Stripe signatures over the raw request body with the endpoint's whsec_ secret. Stripe says any change to the raw body makes verification fail.
- Storage: Supabase Storage allows no uploads without RLS policies on storage.objects; make yours limit each user to their own files.
- Backups: Supabase backs up paid projects daily and recommends regular supabase db dump exports on the Free plan. Database backups do not include Storage files.
- Error monitoring: know where production errors show up. On Vercel, Observability shows error rates per route and 500 errors.
- Run your tool's own scan before you publish and fix what it finds, then treat a clean result as one input, not proof.
- Test as a stranger: on the deployed app, try to read, change and delete user A's rows as user B and while signed out.

## Optional repo check

For AI-built Vercel + Supabase apps, `npx -y viberaven@1.5.3 check` reads the repo and lists launch gaps it can see in files: public tables that no migration puts under row level security, policies whose condition is a bare `true`, a Supabase service role key in client code, env vars the code reads that `.env.example` does not list (it cannot see Vercel settings), and Stripe webhook handlers that skip the signature check over the raw body. It is advice, not a gate, and a repository check, not a live database test: it does not connect to Supabase, Vercel or Stripe, and a clean result does not prove the app is secure. It exits with code 1 when it finds a blocker and writes a `.viberaven` folder that it does not add to `.gitignore`.

## FAQ

### Does Lovable check this list for me?

Part of it. Lovable hosts the app with a built-in backend, Lovable Cloud, built on Supabase, or your own Supabase project. Its Quick scan runs on every publish and reviews database access rules, including tables without row level security and file storage rules. The Deep scan, which you start, also reviews app code. Lovable says the scans cannot guarantee complete security.

### Does Bolt check this list for me?

Part of it. Bolt publishes apps to a bolt.host address and creates a Bolt database when needed. Its security audit, on paid plans, reviews code and database, including who can see and change data and whether private keys reach the browser. Its auth settings doc covers the Site URL and redirect allow list, and warns that the default localhost:3000 Site URL does not work for live apps. Its Stripe integration verifies webhook signatures automatically.

### Does v0 check this list for me?

Part of it. v0 defaults to Next.js and deploys to Vercel. Its security page says v0 analyzes NEXT_PUBLIC_ usage and warns about potential risks, and recommends separate development and production keys. Env vars for Production, Preview and Development are set in the Vercel project, so checking their values is yours.

### Does Replit Agent check this list for me?

Part of it. Replit publishes the app with two databases: a development database Agent builds with, and a production database created at publish, which Agent cannot modify. On paid plans, Security Agent scans the codebase for code, dependency and privacy vulnerabilities. Replit says AI-generated code still needs security review and that a scan is not a complete security review.

### Do Cursor, Claude Code or Codex check this list for me?

Their documented security review features review code and pull requests. Claude Code's /security-review runs a single pass over the current branch, and Anthropic says its Claude Security plugin does not replace your existing source-code security tools. Cursor's Bugbot and Security Agents review pull requests. Codex reviews GitHub pull request diffs, and its Security Review, in research preview, gives a more in-depth review of potential security issues. Checking your live project settings is still your job.

## Sources

Read on 2026-09-30.

- Lovable, Security overview: https://docs.lovable.dev/features/security
- Lovable, Lovable Cloud: https://docs.lovable.dev/features/cloud
- Lovable, Secrets: https://docs.lovable.dev/features/secrets
- Bolt, Check your project's security: https://support.bolt.new/building/security
- Bolt, Database: Authentication settings: https://support.bolt.new/cloud/database/authentication
- Bolt, Stripe for payments: https://support.bolt.new/integrations/stripe
- Bolt, Hosting: https://support.bolt.new/cloud/hosting
- Bolt, Database: https://support.bolt.new/cloud/database
- v0, Security: https://v0.app/docs/security
- v0, Deployments: https://v0.app/docs/deployments
- v0, Full-stack apps: https://v0.app/docs/full-stack-apps
- Replit, Security: https://docs.replit.com/features/security/overview
- Replit, Agent security scans: https://docs.replit.com/features/security/agent-security-scans
- Replit, Development and production databases: https://docs.replit.com/features/data-and-storage/development-and-production
- Replit, Security checklist: https://docs.replit.com/learn/security-checklist
- Claude Code, Scan your codebase for vulnerabilities: https://code.claude.com/docs/en/claude-security
- Cursor, Bugbot: https://cursor.com/docs/bugbot
- Cursor, Security Agents: https://cursor.com/docs/security-agents
- OpenAI, Review GitHub pull requests with Codex: https://learn.chatgpt.com/docs/third-party/github
- Supabase, Row Level Security: https://supabase.com/docs/guides/database/postgres/row-level-security
- Supabase, Advisors: https://supabase.com/docs/guides/database/database-advisors
- Supabase, API keys: https://supabase.com/docs/guides/api/api-keys
- Supabase, Redirect URLs: https://supabase.com/docs/guides/auth/redirect-urls
- Supabase, Storage Access Control: https://supabase.com/docs/guides/storage/security/access-control
- Supabase, Database Backups: https://supabase.com/docs/guides/platform/backups
- Next.js, Environment variables: https://nextjs.org/docs/app/guides/environment-variables
- Vercel, Environment variables: https://vercel.com/docs/environment-variables
- Vercel, Observability: https://vercel.com/docs/observability
- Stripe, Receive events in your webhook endpoint: https://docs.stripe.com/webhooks

HTML page: https://viberaven.dev/production-ready-ai-app-generators
