
Backups, and losing everything: the copy you'll need once
Lesson 6 of where your data lives: what a backup actually is, what your plan does and doesn't do for you, and the Replit story that made it real.
Sam Ortega · 39m ago · 4 min
7 articles · newest first

Lesson 6 of where your data lives: what a backup actually is, what your plan does and doesn't do for you, and the Replit story that made it real.
Sam Ortega · 39m ago · 4 min

Lesson 5 of where your data lives: the service behind a huge share of AI-built apps. What's inside the box, what's free, and what it asks of you.
Sam Ortega · 39m ago · 4 min

Frontend, server, database, API, secrets: the parts of your app you can't see, drawn as the journey of one tap, and why every security rule has to live on the far side of it.
Sam Ortega · 42m ago · 6 min

Whatever your app sends to the browser, anyone can read. Which keys are designed to be public, which must never be, how secrets end up there, and the server-function fix, from each vendor's own docs.
Sam Ortega · 42m ago · 7 min

The one database setting behind the biggest vibe-coded app exposures, shown as a table: who sees what with RLS off, who sees what with it on, and the policy your AI tool should be writing.
Sam Ortega · 42m ago · 7 min

An AI-built social network left its whole database readable and writable. The key wasn't stolen; one setting was missing. What happened, from Wiz's write-up, and the lesson for anyone building on Supabase.
Sam Ortega · 42m ago · 7 min

The six mistakes behind 2026's vibe-coded app exposures, turned into checks you can do without reading code: RLS, secrets, server-side auth, admin, webhooks and rate limits.
Sam Ortega · 42m ago · 8 min