Base44
Check who can reach your Base44 app, and what they can see.
Base44 builds the app, its data and its sign-in together, which is what makes it fast. It also means the access settings decide almost everything about who can see your data, and they are easy to leave as they were on the first day.
Common failure modes
These turn up in fast-built apps whatever they were built with, once an app grows faster than anyone reviews it. Most can be fixed where the app is.
-
The platform, and the layer you own
A flaw in the platform itself is the platform's to fix. What an app owner controls is the layer on top: the access settings, the data rules and the code the app runs. That layer is what an audit checks.
Base44 has had an authentication bypass in the platform itself. The Hacker News
-
Apps open to anyone who signs up
An internal tool or a customer portal left open to public sign-up gives every new account whatever a signed-in user can see.
-
Records any user can read
Data rules that check only that someone is signed in, rather than which records are theirs, let one customer see another's.
-
Keys for other services
Integrations with payment, email or AI services need their keys kept on the server side, never in code or settings the browser can read.
-
Changes made by prompt
Each prompted change is new code. Without review, and a way to test the flows that matter, a fix in one place can open a gap in another.
Veracode found that 45% of AI code-generation tasks introduced a vulnerability, and that security performance had 'remained unchanged over time' as models improved. Veracode, via BusinessWire
-
A business-critical tool with one way in
When an internal tool becomes one the business depends on, it needs more than one owner account, an export of its data, and a plan for when something goes wrong.
What the audit checks on a Base44 app
The code and product audit reads the code, not only what is visible from outside, and ranks every finding by what it means for the business. On a Base44 app, that includes:
- The app's access settings: who can sign up, who can sign in, and what each role can see.
- Data rules for every kind of record, checked against who should see what.
- Integrations, and where their keys live.
- Backend functions, and what they trust from the browser.
- Ownership, exports and recovery: what happens if an account is lost or data is deleted.
- Your product and business goals, from an interview, so every finding is ranked by what it means for the business.
Production-ready where you are
The default recommendation is to make the app hold up on Base44. Moving off is recommended only when the audit shows it is worth the cost.
Run the free check on your Base44 app.
It scans what your app already shows the world, such as keys in its JavaScript, its headers, HTTPS and versions, and Aaron reviews the result within two business days. It runs only after you confirm by email and show the app is yours.