Is my Bolt app secure?
An app built with Bolt runs whatever code it generated, front end and back end. The risk is in the checks it did or did not write around your data, keys and payments.
A Bolt app is secure only if the code it generated checks permissions on the server, keeps secrets off the client, and validates payments server-side. Bolt builds full-stack projects quickly in the browser and can wire in a hosted database, often Supabase. Before launch, confirm every API route checks who is calling and what they may touch, that no secret key ships to the browser, and that nothing important is decided in front-end code.
Where the risk sits in a Bolt app
Bolt produces a full-stack JavaScript project and deploys it. Depending on the prompt, data goes to a Supabase database, a serverless API, or both. Each path has its own place for a missing check: RLS for direct database access, and handler code for the API routes. The generated routes often check that a user is logged in and stop there.
| Finding | How to check it yourself |
|---|---|
| API routes check login but not ownership | Call an endpoint with another user's record ID while logged in as yourself |
| Database rules open | If Supabase is used, check RLS on every table |
| Secrets in environment variables exposed to the client | Search the built bundle for key prefixes; variables marked public are shipped to the browser |
| Payment success trusted from the browser | Check that access is granted by a verified webhook, not a redirect page |
| No rate limits | Submit the login form fifty times quickly and see if anything stops you |
| Verbose errors | Trigger an error and check whether stack traces or queries appear |
Checks to run before launch
0 of 0 done ยท
The full list, tool by tool, is the pre-launch security checklist. For the flows rather than the security, use the launch checklist.
The tool is not the problem
Bolt produces working software quickly and it is a reasonable way to build a first version. Its output is a first draft. Nothing in the tool checks that every record is protected from every user who should not see it, because that depends on rules only you know. Ask it to add the checks, then have someone who did not write the prompts verify them. That is what a security test is.
Getting it tested
A security and QA test of a small Bolt app typically costs $2,000 to $12,000 CAD, depending on roles, payments and any AI features. Testers work from the running app and, if you share it, the exported code. See what to give the testers. TrazTech offers this as vibe-coding QA and security review; get a second quote on the same scope.
Common questions
Is Bolt safe for a production app?
It can produce one. Treat the generated code as a first draft, check the items on this page, and have it tested before real users and real data.
Where does Bolt put secrets?
In environment variables. Anything given a public prefix is compiled into the browser code and is readable by anyone, so only non-secret configuration belongs there.
Do testers need Bolt access?
No. They need the running app, test accounts and ideally the exported code.