Episode Details
Back to Episodes
Securing Millions of AI-built Apps: How Lovable Defends Against Insider Threats
Description
Empowering non-technical users to build production-grade applications requires a proactive, secure-by-design architecture. In this episode, Ashish sits down with Marcus Hallberg and Samuel Kelemen, security engineers at the AI software creation platform Lovable, to discuss how they actively secure AI-generated code and protect creators from supply chain risks.
Focusing on solutions rather than alarmism, Marcus and Samuel detail their response to an incident where malicious contractors mimicked AI agent commits. They outline their multi-layered defense strategy: securing a predefined tech stack, utilizing integrated security scanners, and tuning coding agents with strict guardrails to ensure secure output by default. The conversation also covers the evolution of the shared responsibility model in the AI era, the critical importance of foundational hygiene like Git commit signing, and the necessary transition from local "YOLO mode" to secure, sandboxed agent environments. Discover how platforms can leverage AI not just to write code, but to actively assist users in finding and resolving security issues through concepts like "CISO agents."
Guest Socials - Marcus's Linkedin + Samuel's Linkedin
Podcast Twitter - @CloudSecPod
If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:
If you are interested in AI Security, you can check out our sister podcast - AI Security Podcast
(00:00) Introduction to Securing AI App Builders(02:00) Marcus & Samuel's Backgrounds and Roles at Lovable(04:30) Empowering Non-Technical Users to Build 40 Million Apps(08:30) Securing Predefined Tech Stacks and Tuning Coding Agents(11:00) Managing Trust When Customers Hire External Contractors(14:00) Addressing Supply Chain Risks with Synced GitHub Repositories(17:30) Educating Users and Developing "CISO Agents" for Support(24:00) Analyzing the Attack: How Threat Actors Mimicked Agent Commits(31:00) The Importance of Basic Hygiene: MFA and Commit Signing(38:30) Moving Agents from "YOLO Mode" to Sandbox