Back to Guides
Guide24 September 2026

What is Lovable company? An overview of the Swedish vibe - coding startup

Decloak is an AI-powered web security intelligence platform that scans a site's HTTP/TLS posture, JavaScript, and third-party scripts to produce a report anyone can read. This guide is part of Decloak's library of practical, source-backed security guidance.

In this guide
  1. Key takeaways
  2. When was Lovable founded and where is it incorporated?
  3. Who are the founders and key leaders?
  4. What does Lovable’s platform actually do?
  5. How large is Lovable in terms of staff, revenue, and users?
  6. What funding has Lovable received?
  7. What security incident has been reported for Lovable?
  8. How can developers assess the security of a Lovable - built site?
  9. Where can I learn more about Lovable?

What is Lovable company?

Lovable (also called Lovable Labs Inc.) is a privately - held Swedish software company that builds a “vibe - coding” platform for AI - assisted software development. It was incorporated in Delaware but operates out of Stockholm.

Key takeaways

When was Lovable founded and where is it incorporated?

Lovable was founded in 2023 in Stockholm, Sweden, and is legally incorporated in Delaware, United States as Lovable Labs Inc.

Who are the founders and key leaders?

The company was founded by Anton Osika, who serves as CEO, and Fabian Hedin, who is the CTO.

What does Lovable’s platform actually do?

Lovable’s platform lets users write natural - language prompts that are automatically turned into working code. It is a commercial implementation of the open - source GPT Engineer project, providing a “vibe - coding” experience where developers can describe desired functionality and receive generated code snippets or full projects.

How large is Lovable in terms of staff, revenue, and users?

What funding has Lovable received?

RoundAmountDateLead InvestorValuation
Series A$200 MFeb 2025Accel$1.8 B
Series B$330 MDec 2025CapitalG$6.6 B
Series C$400 MAug 2026Menlo Ventures$13.3 B

What security incident has been reported for Lovable?

In March 2025 a vulnerability was discovered where websites built with Lovable could expose Supabase databases if the database’s access controls were mis - configured. Lovable responded by offering automated scans of customers’ sites to detect such mis - configurations.

How can developers assess the security of a Lovable - built site?

  1. Verify that any Supabase database used by the site has Row Level Security (RLS) enabled.
  2. Ensure that service_role keys are never shipped to client - side JavaScript.
  3. Run a third - party scan that checks for publicly readable tables and exposed keys. Tools that examine static HTML, rendered network behavior, and JavaScript patterns can help confirm that no dangerous secrets are leaked.
  4. Review the platform’s documentation for any recommended hardening steps specific to the vibe - coding stack.

Where can I learn more about Lovable?

Visit the official website at https://lovable.dev for product documentation, security advisories, and contact information.


This article is based on publicly available facts about Lovable, including its founding date, leadership, product description, financial milestones, user metrics, and a known security issue.

Free security scan

See what's actually exposed on your site.

Decloak's free scan runs in about 15 seconds, no account required, and covers:

  • HTTP/TLS security posture
  • JavaScript CVEs
  • Exposed Supabase/Lovable/Base44 misconfigurations
  • AI-written executive summary