Update on my entry: before publishing, Lovable's security scan warned that my app's database rules let anyone read the customer tables. I checked it myself, and it was true: with the app's public key, all 5 tables returned data. It's the same kind of problem as CVE-2025-48757.The fix: every read and write now goes through server functions, and the public key has no access. The same check now gets "permission denied" on all 5 tables.If you built on Lovable Cloud, you can check yours in two minutes. Open Cloud → SQL editor and run:select tablename, policyname, roles from pg_policies where schemaname = 'public' and (qual = 'true' or with_check = 'true');Any row is a rule that says "true". If its roles include anon or public, anyone with your app's public key can use it.Then check for tables with row level security off:select relname from pg_class c join pg_namespace n on n.oid = c.relnamespace where n.nspname = 'public' and c.relkind = 'r' and not c.relrowsecurity;Both came back empty for my app after the fix. Happy to help if yours doesn't.