Skip to main content
All posts
Published July 24, 2026 in Announcements

Enterprise features July roundup

Enterprise features July roundup

Lovable is a software creation platform. People describe what they want in plain language and Lovable builds real, working software from it: internal tools, customer-facing apps, prototypes that grow into production systems. Inside a company, whole teams use it, often people who have never shipped software before.

Teams love it because they can build in hours what used to take a quarter. But the person accountable for security sees that same speed paired with shadow IT and sprawl, and suddenly needs to know: what is everyone building, who can get into it, and what is it touching?

Speed without control is a liability, and controls that kill the speed defeat the point. Lovable's job is to give enterprises both. Here are recent releases that give admins governance and control.

AIUC-1 certified

Lovable is the first software creation platform certified under AIUC-1, the leading third-party standard for AI security, safety, and reliability. Earning this certification requires passing comprehensive adversarial testing across risks like secure code generation, secrets protection, and hallucinations. Read more about how Lovable's platform performed in our white paper.

Reusable authentication

One of our most requested features is reusable authentication. This will allow apps built in your workspace to automatically recognize users, whether logged in through SSO, Google, or email, who are using internal apps. This means:

  • Internal tools don't need a separate login page built or consent flow. The agent automatically reads identity, removing any friction for users.
  • Authentication is secure by default. Identity arrives as a short-lived signed token that apps verify before use.

Publishing controls

When a team publishes an app, admins can decide exactly who can reach it: anyone, only your workspace, or a named list of people, including outside guests invited by email.

Access to the published app and access to the underlying project stay separate, so publishing something never exposes its source, its chat history, or work in progress. Publishing deploys a snapshot, and unpublishing takes the live URL down instantly while the project itself stays untouched.

Admins get workspace-wide controls over all of it:

  • set whether new projects are open to the whole workspace or restricted to invited people only
  • decide what access level outside collaborators can have and whether they can bypass SSO
  • switch off outside sharing entirely
  • limit who is even allowed to publish externally to admins and owners

External sharing is captured in Workspace Insights, so a private app shared beyond where it should be shows up.

A single view of everything your teams build

Once teams get into the flow of creating, workspaces grow fast. Workspace Insights gives admins and owners one view of everything being built, prioritized by what needs review first.

You'll be able to see security findings, ownership, lifecycle, cost, publish status, and any activity signals that may need attention. On Enterprise plans this also includes PII findings.

Workspace Insights is our complement to the Security Center tabs. Code analysis, supply chain security, and secrets overviews focus on the specific security areas, whereas Workspace Insights adds information on governance.

You're able to:

  • See a workspace-wide summary of total projects, externally published projects, and projects with high review priority.
  • Filter for abandoned projects, security scan findings, and projects with no owner.
  • Search by project name, owner, or description, and filter by review priority, publishing status, and finding type.
  • Expand any project row to review the findings and signals that explain why the project is flagged.
  • Click a project name to open the full project details page with description, built-in backend setup, connectors, website details, PII status, activity metrics, and open findings.
  • Run a fresh security scan on a project. Enterprise workspaces can also run a fresh PII scan.
  • Export the table to a CSV file for audits, reporting, or leadership reviews.

Automated security scanning

Lovable has two built-in security scanners: Basic Scan and Deep Scan.

The Basic Scan runs automatically before every publish, in about 10 to 15 seconds, checking project configuration, database schema, row-level security policies, and exposed sensitive data, and returning a clear pass, warning, or critical result. It's a fast safety net rather than a full code audit.

The Deep Scan is a full code audit. It's an AI-powered review of the whole codebase any builder can run in one click, in two to four minutes. It will do:

  • Access control reviews: Detects overly permissive data-access rules and database functions that bypass row-level security.
  • Backend endpoint protection: Flags edge functions and APIs that lack proper authentication or authorization.
  • Code-level vulnerability reviews: Identifies exposed secrets, unsafe input handling (such as SQL injection or XSS), insecure storage settings, and information leakage through errors or logs.
  • Project-specific issue reviews: Surfaces issues tied to context you've added in your security memory.

Enterprise admins can also schedule deep security scans in advance, so that they run on a regular cadence for high-profile projects.

Cleanup of abandoned apps

Some apps get built for a moment in time and are never opened again. Lovable gives admins a way to manage these as they may still be published and connected to data.

Lovable finds them with a daily check, flagging any that passes a configurable window of inactivity with no edits and no visits. Admins see the full list in the Security Center and can turn on automatic cleanup for the workspace. When they do, the owner gets an in-project countdown plus email warnings five days and one day before deletion, and can keep the app to stop the clock. Even past the deadline, a removed app is soft-deleted first and recoverable during a grace period before anything is permanently gone.

All of these features are live and more. Try them all today at www.lovable.dev or speak to a member of our team.

Idea to app in seconds

Build apps by chatting with an AI.

Start for free