Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.
In this guide
- Key takeaways
- When was Lovable founded and where is it incorporated?
- Who are the founders and key leaders?
- What does Lovable’s platform actually do?
- How large is Lovable in terms of staff, revenue, and users?
- What funding has Lovable received?
- What security incident has been reported for Lovable?
- How can developers assess the security of a Lovable - built site?
- Where can I learn more about Lovable?
What is Lovable company?
Lovable (also called Lovable Labs Inc.) is a privately - held Swedish software company that builds a “vibe - coding” platform for AI - assisted software development. It was incorporated in Delaware but operates out of Stockholm.
Key takeaways
- Founded in 2023 in Stockholm, incorporated in Delaware.
- Core product: a natural - language - to - code platform built on GPT Engineer.
- Raised over $900 M across three funding rounds, valued at $13.3 B by Aug 2026.
- Reported $200 M ARR and 8 M users in 2025; traffic grew to ~900 M monthly visitors by 2026.
- A 2025 vulnerability showed that mis - configured Supabase databases on Lovable sites could be exposed.
When was Lovable founded and where is it incorporated?
Lovable was founded in 2023 in Stockholm, Sweden, and is legally incorporated in Delaware, United States as Lovable Labs Inc.
Who are the founders and key leaders?
The company was founded by Anton Osika, who serves as CEO, and Fabian Hedin, who is the CTO.
What does Lovable’s platform actually do?
Lovable’s platform lets users write natural - language prompts that are automatically turned into working code. It is a commercial implementation of the open - source GPT Engineer project, providing a “vibe - coding” experience where developers can describe desired functionality and receive generated code snippets or full projects.
How large is Lovable in terms of staff, revenue, and users?
- Employees: approximately 120 people as of 2025.
- Revenue: reported $200 M annual recurring revenue (ARR) in November 2025.
- Users: 8 million users reported in 2025; by August 2026 the platform hosted about 60 million projects and saw roughly 900 million monthly visitors.
What funding has Lovable received?
| Round | Amount | Date | Lead Investor | Valuation |
|---|---|---|---|---|
| Series A | $200 M | Feb 2025 | Accel | $1.8 B |
| Series B | $330 M | Dec 2025 | CapitalG | $6.6 B |
| Series C | $400 M | Aug 2026 | Menlo Ventures | $13.3 B |
What security incident has been reported for Lovable?
In March 2025 a vulnerability was discovered where websites built with Lovable could expose Supabase databases if the database’s access controls were mis - configured. Lovable responded by offering automated scans of customers’ sites to detect such mis - configurations.
How can developers assess the security of a Lovable - built site?
- Verify that any Supabase database used by the site has Row Level Security (RLS) enabled.
- Ensure that service_role keys are never shipped to client - side JavaScript.
- Run a third - party scan that checks for publicly readable tables and exposed keys. Tools that examine static HTML, rendered network behavior, and JavaScript patterns can help confirm that no dangerous secrets are leaked.
- Review the platform’s documentation for any recommended hardening steps specific to the vibe - coding stack.
Where can I learn more about Lovable?
Visit the official website at https://lovable.dev for product documentation, security advisories, and contact information.
This article is based on publicly available facts about Lovable, including its founding date, leadership, product description, financial milestones, user metrics, and a known security issue.
Related guides
How to Build Continuous Web - Security Scans with Scheduled Decloak Checks and Ticket Automation
Learn how to schedule Decloak scans via the REST API, compare results across runs, and push new or regressed findings to Jira or Linear automatically.
How can Decloak give auditor - ready proof for SOC 2 and ISO 27001 without weeks of manual work?
Decloak’s free and paid scans generate evidence packages and framework mappings that satisfy SOC 2 and ISO 27001 auditors quickly and automatically.
How can I quickly scan my single-page app for exposed secrets and vulnerable third - party scripts?
Use Decloak’s free 15 - second scan to detect hard - coded keys, outdated libraries, missing SRI and mixed content in a single - page app before a formal audit.