Skip to content
Unbase44

Is Base44 secure? Reported vulnerabilities, access rules and what to check in your app

Researchers have reported flaws in Base44 itself, and by their own accounts the main ones were fixed. Most of what keeps an app's data safe, though, is settings the owner controls. Here are the reported incidents, how Base44's access rules work, and a checklist for your own app.

Updated 8 min readBy the Unbase44 team

On this page

The short version

Is Base44 safe? The useful answer comes in two parts.

The platform. Security researchers have publicly reported flaws in Base44 itself, most of them in 2025. The best known came from Wiz, which found that private apps could be joined using only their public app ID, and from Imperva, which found ways to steal sign-in tokens. In both cases the researchers said Base44 fixed the problem, and Wiz said there was no evidence that any customer was affected. Base44 says it holds SOC 2 Type II and ISO 27001 certifications, runs penetration tests and has a bug bounty program.

Your app. Most of what decides whether your app’s data is safe is in settings you control: who can open the app, the access rule on each table, whether backend functions check who is calling, where your API keys live, and who has admin rights. Base44’s own documentation says plainly: “You are responsible for your app’s security settings.”

This page lists the reported incidents with dates and sources, explains how Base44’s access rules work, and gives a checklist for your own app.

Reported security issues, with dates and sources

These are the issues reported publicly by security researchers and reputable press, as of October 2026. Each line describes what was reported, nothing more.

Published Reported by What was reported Outcome reported
29 July 2025 Wiz Research Undocumented registration and email-verification endpoints let anyone who knew an app’s app_id, a value visible in app URLs and public files, create a verified account on a private app, bypassing sign-in controls including single sign-on. Reported 9 July 2025 and fixed within 24 hours. Wiz said there was no evidence that any customer was affected.
27 August 2025 Imperva Threat Research An open redirect in the login flow that could send a user’s access token to another site; stored cross-site scripting on app.base44.com, possible because premium code editing was enforced only in the browser; and the main Base44 login token being passed to user-built apps in the URL. Reported in March 2025. Imperva said the vendor fixed all the issues, with partial fixes in March and more changes in April.
31 August 2025 Walla, reporting research by Dos-Op A NoSQL injection weakness in sign-in and permission checks, with more than 200 apps said to be vulnerable. Reported to Base44 on 22 August 2025; Base44 released an update three days later, and the researchers said some admin pages were still reachable. Disputed: Base44 said the issue came from customer configuration, and in a response published by Geektime said the researcher had removed his own app’s security rules.
7 May 2026 Security Boulevard, reporting research by RedAccess About 380,000 publicly accessible apps and other assets built with Lovable, Base44, Netlify and Replit, about 5,000 of them holding sensitive corporate data. Not a platform flaw. The researchers pointed to apps left publicly accessible, with the privacy setting left to the person who built them. No breakdown by platform was given.

In the same Geektime article, Base44 said the Imperva issues were found and fixed in March 2025, when it had few users, and that the Wiz issue affected fewer than 3% of apps.

Two patterns run through these reports. The platform flaws were in sign-in and token handling, which Base44 operates and fixes centrally. The 2026 research, like the dispute over the Dos-Op findings, is about how individual apps were configured. That part is yours.

What Base44 handles at the platform level

According to Base44’s security page and security overview, as of October 2026:

  • SOC 2 Type II and ISO 27001 certification, and a data processing agreement on request for GDPR.
  • Encryption in transit (TLS 1.2 or newer) and at rest (AES-256). Stored credentials are encrypted with AWS Key Management Service, using a key Base44 manages; Enterprise workspaces can have a dedicated key.
  • Penetration testing by internal and third-party teams, an invite-based bug bounty program, and 24/7 security monitoring.
  • Rate limiting on all public endpoints.

The same documentation lists some limits worth knowing:

  • Data is not end-to-end encrypted; Base44 says its admins can access your data if needed.
  • Sign-in tokens are stored in the browser’s localStorage. HttpOnly cookies aren’t available.
  • Per-app CORS settings aren’t available, and headers such as Content-Security-Policy and Strict-Transport-Security can’t be set per app. You can control embedding and browser-feature permissions.

How Base44’s access rules work

App visibility

Every app has one visibility setting: Public (anyone on the internet), Private (invited people only, sign-in required) or Workspace (your Base44 workspace, sign-in required). Private apps need a paid plan. A public app that doesn’t require sign-in can’t tell visitors apart, so any table it can read is readable by everyone.

Data access rules (row level security)

Each table has rules for Create, Read, Update and Delete (Managing data permissions). In the editor, each action can use these rule types:

Rule Who gets access
All Users Anyone, even without signing in
Creator Only Only the person who created the record
Entity-User Field Comparison People whose account matches a field on the record, such as assigned_to = their email
User Property Check People with a given account property, such as the Admin role

If a person matches any one rule, they get access. Base44 sets rules automatically as the AI builds your tables and shows a Permission risks detected banner when it spots something too open.

Base44’s developer documentation shows what sits underneath. The rules live in each table’s schema as row level security, with optional field level security for single fields such as a salary. Conditions can compare a record to the signed-in user:

"rls": {
  "create": true,
  "read": { "created_by": "{{user.email}}" },
  "update": { "created_by": "{{user.email}}" },
  "delete": { "user_condition": { "role": "admin" } }
}

Denied reads return nothing, as if the records didn’t exist. Denied writes fail with a permission error. One exception matters: code in a backend function that uses Base44’s service role skips these rules entirely, so the function itself has to check who is asking.

What to check in your own app

Work through these on every app that holds anything personal or commercial. Base44’s security scan covers several of them and is free on every plan.

  1. Visibility. Is the app public when it should be private or limited to your workspace? Anyone can find and open a public app, and the 2026 research above was about apps left public.
  2. Every table’s rules. Look for All Users on Read for anything personal, such as orders, messages, form submissions or user profiles. Personal data usually wants Creator Only, or a field comparison. Then sign in as different roles in Preview and confirm each sees only what it should.
  3. Public entities. Contact forms and sign-up tables often allow anyone to Create. That’s fine as long as Read, Update and Delete are restricted to your admin role.
  4. Backend functions. The scan flags functions that return data without checking who is signed in (“Anyone can run this function”). Pay extra attention to functions that use the service role, and make webhook handlers verify the sender’s signature.
  5. Secrets in frontend code. An API key written into a page or component is visible to every visitor. Keep keys in Base44’s secrets and call outside services from backend functions; the scan’s Exposed secrets check looks for this.
  6. Credit-using features. The scan’s Credit protection check flags AI, image or email features that can be called from outside your app, where someone could spend your integration credits.
  7. Admin roles and collaborators. Base44 adds collaborators to your app as Admin by default, and on public apps people with the User role can invite other users. Review your Users list, remove accounts you don’t recognize, and keep the Admin role to the people who need it.
  8. Embedding. If your app has sign-in or payments, set embedding to No one, or to Only these sites if you embed it on your own website.

Run the scan again after any big change, such as new tables, new integrations or new permissions. Code-vulnerability scanning and the optional Wiz integration need the Builder plan or higher.

What changes when you run the app yourself

Moving an app off Base44 doesn’t make it secure, and it doesn’t make it less secure by itself. It changes who is responsible for which part.

  • Your access rules come with you, including their mistakes. With Unbase44, every table moves with its access rules, and the Base44-compatible backend enforces them on your own server. A table that’s open to everyone on Base44 is open to everyone after the move. Fix the rules first.
  • The platform work becomes yours. Base44’s certifications, penetration tests, bug bounty and 24/7 monitoring cover Base44’s platform. They don’t come with your hosting. On your own accounts, you or your developer keep the server and its dependencies updated, watch the logs and respond to problems. Your hosting provider covers its own layer.
  • You can see and change everything. The server code sits in your own GitHub repository under the MIT license, with documentation, so a developer or security reviewer can read exactly how sign-in and access checks work.
  • Your keys live in your accounts. Secrets sit in your hosting environment, and email and AI run on your own provider accounts. After the move, Revoke access on the app’s page deletes every key Unbase44 held.
  • You choose where data lives. The region is whatever you pick for your hosting and database, which matters for GDPR and data residency.

If your app handles health data or other regulated information, the rules are stricter wherever it runs. Our HIPAA guide covers that case.

Questions and answers

Is Base44 safe to use?

Base44 says it holds SOC 2 Type II and ISO 27001 certifications, encrypts data in transit and at rest, and runs penetration tests and a bug bounty. The flaws researchers reported in 2025 were fixed, according to those researchers. Whether your own app is safe depends mostly on its visibility, access rules, backend functions and where its API keys live, which Base44 says are your responsibility.

Has Base44 had a security breach?

Researchers have reported vulnerabilities in the platform, each reported as fixed. Wiz reported in July 2025 that private apps could be joined using only their app ID; the flaw was fixed within 24 hours, and Wiz said there was no evidence that any customer was affected. Imperva reported token-theft flaws in August 2025 that it said were fixed. Separately, research published in May 2026 found apps built with several builders, Base44 among them, left publicly accessible with sensitive data in them.

Does Base44 have row level security?

Yes. Each table has rules for create, read, update and delete, such as “creator only” or “admins only”, and Base44’s developer docs also describe field level rules for single fields. Backend functions that use the service role skip these rules, so those functions need their own checks.

Are my API keys safe in Base44?

Keys stored in Base44’s secrets are encrypted and only reachable from backend functions, according to its documentation. A key typed into frontend code is visible to anyone who opens your app. The security scan checks for exposed secrets.

Does moving off Base44 make my app more secure?

No, not by itself. Your access rules move with the app, mistakes included, and the platform-level security work Base44 does becomes your job or your host’s. What you gain is control: the code, the keys and the data location are yours to inspect and decide.

Sources

Checked on October 4, 2026. Base44 changes quickly; if something here is out of date, tell us.