Matt Palmer reported 303 inadequately protected Supabase endpoints across 170 of 1,645 analyzed Lovable projects. The technical boundary was Row Level Security behind direct browser-to-database access; attribution of responsibility to the platform remains disputed.