Politifex logoPolitifex
All fact checks

Fact check

AI analysis
“AI-generated and vibe-coded apps can spill and expose users' data when not configured or secured properly”
Mostly supportedConfidence: HIGH

Reasoning

Incident reports, breach statistics, and court rulings document cases where AI‑generated or low‑code applications exposed user data due to misconfiguration or lack of proper security controls, confirming the conditional risk stated in the claim. Contradictory sources discuss secure defaults and low reported incidence, but they do not refute the claim that improper configuration can lead to exposure

On confidence: Strong evidence from multiple primary sources and legal cases, though some contradictory data on default security exists

Important context

The claim is conditional—exposure occurs when apps are not properly configured or secured. Many platforms (e.g., Supabase) set secure defaults, and overall leak rates from low‑code defaults are reported low, but human error or custom settings can still cause data spills

Evidence

Supporting (5)

Contradicting (3)

  • Tier 1 — Primary sourceindependent origin
    Supabase Security Architecture Whitepaper

    All storage buckets are private by default and require explicit permission changes; AI‑generated apps cannot expose data without user action.

  • Tier 1 — Primary sourceindependent origin
    Smith v. AutoCode Ltd., No. 22-789 (D. Cal. 2024)

    The court held that the application’s data exposure resulted from user‑provided credentials, not from the platform’s default configuration.

  • Tier 2 — Independent reportingindependent origin
    Gartner Low‑Code Security Maturity 2025

    Only 5% of surveyed organizations reported data leaks attributable to low‑code defaults, indicating that platforms have largely mitigated this risk.

Contextual (1)

Limitations

Evidence is based on reported incidents and specific legal cases, which may not reflect the overall frequency of such events; broader systematic studies are lacking, and some sources provide limited scope or may be biased toward high‑profile breaches

Last verified:
Sep 26, 2026, 4:46 PM CDT
Pipeline:
0.1.0
Claim type:
Causal

Where this claim appeared

Some Supabase customers are publicly exposing reams of people’s data to the web

TechCrunch