KBAISE/ for lovable
Library
Docs

Trust center

about 5 minBuildingchecked 3d agoOfficial page
The short version

The Trust Center creates a public page for your app that shows security checks Lovable has verified. This helps you share evidence of your app's security with customers, investors, and reviewers without you having to write or update it yourself.

Anyone who publishes an app with Lovable and needs to show its security status to others, like customers or investors.

Do this, in order

  1. 1

    Go to your project's settings.

    This is where you manage publishing options for your app.

  2. 2

    Find the 'Publishing' section.

    The Trust Center is a feature related to how your app is published.

  3. 3

    Enable the 'Trust center' option.

    This turns on the feature and tells Lovable to start generating your app's security page.

  4. 4

    If your app was published before the Trust Center existed, republish it.

    This ensures Lovable can evaluate your current app and generate the security page with up-to-date information.

Paste this into your project

Please enable the Trust Center for my project. I understand it will create a public security page for my app at /.well-known/trust.html and a machine-readable version at /.well-known/trust.json.

Words decoded

SBOM
A 'Software Bill of Materials' is like an ingredient list for your app, showing all the ready-made software components it uses.
HTTPS
This is a secure way for your web browser to connect to a website, keeping your information private and safe from prying eyes.
SOC 2 or ISO 27001
These are formal, in-depth certifications that prove a company meets high standards for managing its information security. The Trust Center is not one of these.
Deployment
This refers to a specific version of your app that has been put live and is accessible to users.

Where people get stuck

  • Do not assume the Trust Center is a formal security certification like SOC 2 or ISO 27001; it provides facts, not an audit.
  • Do not try to edit the Trust Center page or add your own claims, as it is generated and served by Lovable and cannot be changed by your app's code.
  • Do not expect a Trust Center for unpublished projects, preview versions, or apps only shared with workspace members, as it's only for externally published apps.
  • Do not worry if a check is missing from your Trust Center page; it just means Lovable can't confirm it, not that there's a breach or problem.
  • Do not expect the Trust Center to slow down or break your app's deployments; its checks run separately and do not interfere.

The short version, steps, decoder and prompt on this page are written automatically from Lovable's own documentation and can lag or misread it. The official page is always the authority.