← The AI Hype Audit — all 181 verdicts
HOLDS UP “The CISOs at Lovable and Supabase helped us write the checklist” — verified, and a model for how vendors should do it
The claim“Non-engineers are shipping production apps now. Security teams are the last line of defence when something goes wrong. The CISOs at Lovable and Supabase helped us write the checklist for that.” — linking a downloadable “CISO Vibe Coding Checklist for Security.”
Everything checkable checks out. The checklist exists at aikido.dev as a real downloadable report covering technical guardrails, AI-specific controls, and org policy. The Lovable/Supabase CISO involvement is corroborated by a joint Aikido–Lovable–Supabase security masterclass webinar, and Aikido has a genuine product integration with Lovable (agent-based pentesting) — these are working partners, not name-drops. The premise is also independently real: non-engineers shipping production apps and bypassing security defaults is a documented, widely reported problem, to the point that Supabase published its own vibe-coding security checklist. The only note worth logging: it's a lead magnet — an email-gated download from a vendor that sells the solution to the problem it describes. That's standard content marketing, but the content is substantive, the named experts are accountable, and the sales pitch stays off the poster.
What holds up
- The checklist report page is live at Aikido's site — a real, substantive artifact
- The CISO collaboration is corroborated by a joint Aikido–Lovable–Supabase security masterclass webinar
- Supabase independently published its own vibe-coding security checklist — the problem is real, not vendor-invented
What doesn't
- Email-gated lead magnet from the vendor selling the fix — the standard, disclosed kind of interested party
The catch
The only catch is the ordinary one — the checklist author sells the medicine — and even that is handled the honest way: real problem, named accountable experts, substance up front.
How to actually do it
- If your team ships vibe-coded apps, download it — and read Supabase's free ungated checklist alongside it
- Apply the boring core first: auth defaults, row-level security, secrets handling, and a human review gate before production
- Use this post as the benchmark: when an AI post names accountable experts and links a substantive artifact, that's what credible looks like
Verified end to end — honest vendor content about a real problem, worth the email it costs.
- Confidence
- High
- Posted by
- Aikido Security (verified page) — a security vendor whose product addresses the problem it describes
We test hype for free. We build the real thing for a living.
Thirty minutes, no pitch — and you'll leave with something useful either way.
Book a call with Todd or start with the free Business Checkup →The Verdict Weekly
Three verdicts every Friday. Free forever, unsubscribe anytime, no spam — that would be ironic.
© Schreier Group · schreiergroup.com · See a wild AI claim? Drop it here and we'll test it.