KBAISE/ for lovable
Library
Docs

Workspace security center

about 10 minBuildingchecked 22h agoOfficial page
The short version

The Workspace Security Center helps you keep an eye on security risks across all your projects in one place. It shows you security issues, scan results, and secrets, helping you decide which projects need attention first.

Anyone managing multiple projects on Business or Enterprise plans needs this to ensure all projects meet security standards.

Do this, in order

  1. 1

    Go to your Workspace settings, then Security, and click on Security center.

    This is where you access the central dashboard to see all your projects' security status.

  2. 2

    Review the 'Security insights' tab to see which projects are most critical, like those published externally or with open security issues.

    This helps you quickly identify and prioritize projects that need immediate attention based on their risk level and importance.

  3. 3

    Check the 'Code analysis' tab to see security findings (errors, warnings, info) from scans for each project.

    This shows you specific code-related security problems and helps you ensure all projects have recent scan results.

  4. 4

    Use the 'Supply chain security' tab to find out if any projects are using software components with known vulnerabilities.

    This helps you address risks from third-party code that might affect multiple projects.

  5. 5

    Look at the 'Secrets overview' tab to see all the secret names (like API keys) used across your projects.

    This gives you a central view of sensitive credentials and helps you manage them, though you won't see the actual secret values here.

  6. 6

    If you are on an Enterprise plan, go to the 'Security automation' tab to set up automatic security scans for your projects.

    This ensures your projects are regularly checked for new security issues without you having to manually start scans.

  7. 7

    For any project that needs a closer look, click 'Run deep scan' from the 'Code analysis' tab or use the 'View' option to go directly to that project's security details.

    This allows you to either initiate a new scan or dive into the specifics of a project's security findings to fix them.

  8. 8

    Use the 'Export' dropdown in the top-right corner of any tab to download security data as a CSV file.

    This is useful for audits, reporting, or tracking security posture over time.

Paste this into your project

I need to check the security status of all my projects. Can you guide me to the Workspace Security Center and show me how to review security findings, scan coverage, dependency risks, and secrets across my workspace?

Words decoded

Workspace
Your main account area in Lovable where all your projects are organized.
Security findings
Specific security problems or issues identified in your projects, categorized as errors, warnings, or information.
Scan coverage
How many of your projects have been checked for security issues and how recently those checks were performed.
Secrets
Sensitive pieces of information, like API keys or passwords, that your projects use to connect to other services.
Dependency risks
Security problems that come from using external software components (dependencies) in your projects that might have known vulnerabilities.
PII
Personally Identifiable Information, which is any data that could be used to identify a specific person (e.g., name, email, social security number).
CVE
Common Vulnerabilities and Exposures, a list of publicly disclosed cybersecurity vulnerabilities and exposures.
Cadence
How often something happens, like how frequently an automatic scan is scheduled to run (e.g., weekly, monthly).

Where people get stuck

  • Assuming the Security Center automatically runs scans; you must manually trigger them or set up a schedule (Enterprise only).
  • Expecting to see historical security data; it only shows the most recent scan results.
  • Trying to view actual secret values; only secret names are displayed, not the values themselves.
  • Confusing project-level security findings with individual secret-level findings; findings on a secret row relate to the project, not just that specific secret.
  • Forgetting that scheduled scans (Enterprise) consume credits, while on-demand scans are free.

The short version, steps, decoder and prompt on this page are written automatically from Lovable's own documentation and can lag or misread it. The official page is always the authority.