Lovable has become the first coding agent platform certified under AIUC-1, a security standard for AI agents that comes with something unusual attached: the certifying body also underwrites the risk.
Customers using a certified agent are insured, through Lloyd’s of London, against the failures the standard is meant to prevent. Certification and liability arrive together.
What the standard covers
AIUC-1 comes from the Artificial Intelligence Underwriting Company, developed with input from Stanford, MIT, MITRE, and the Cloud Security Alliance. It sets 51 requirements across six principles.
Those span secrets management, secure code generation defaults, sandboxed execution, human oversight, and enterprise governance. Each requirement needs documented policy, technical implementation, operational process, and quarterly third-party red-teaming behind it.
Crucially it is independently verified rather than self-attested, which distinguishes it from most AI governance frameworks currently in circulation.
Why insurance is the interesting part
Actuaries pricing AI agent risk is a more concrete accountability mechanism than a voluntary code of conduct. Someone has to be willing to lose money if the controls fail.
It also fills a genuine void. AI agents are breaking into companies on their own and the law has no clear answer on who to blame, with computer-misuse statutes assuming a human intruder and product-liability law reaching developers only if a court accepts an autonomous system is involved.
Insurance routes around that. It does not resolve who is legally at fault, it just makes someone contractually responsible for the cost.
The risk is not hypothetical
The failure modes AIUC-1 targets are already documented. Four separate agent attacks in a single month shared one underlying flaw, and research bodies have logged unauthorised agent actions across controlled test runs.
For a platform where 80% of builders are non-technical, sandboxed execution and secure defaults are not optional extras. They are the difference between a prototype and something a bank will run.
Solving the security review
The second announcement is trust centres. Every app published on Lovable now gets a dedicated security page at its own address, showing which controls are live.
It reads those directly from the app, with nothing for the builder to fill in, covering vulnerability checks, software bill of materials, deployment traceability, health monitoring, and database authorisation reviews.
That targets a specific bottleneck. Almost every B2B deal involves someone checking whether the software is safe, and a non-technical founder with a Lovable app has historically had nothing to hand them.
And the permissions problem
The third piece is app user connectors, letting each end user of a published app connect their own third-party account so the app acts on their behalf with their own permissions.
Authentication runs through Lovable’s connector gateway, and it works with Google, Microsoft, Slack, Salesforce, and HubSpot. It removes the pattern where one shared credential does everything for everyone, which is exactly what security reviewers object to.
What the three have in common
None of these announcements makes the code better. All three make the app easier to buy.
Enterprise is the acknowledged next frontier for vibe coding, and the barrier there has never really been whether the software functions. It is whether a security team signs off.
Lovable reached $500 million in annualised revenue with 146 staff and is reportedly in talks to raise at a $13.2 billion valuation. Consumer and prosumer growth got it there, and enterprise contracts are what would justify the next number.
The open question
Certification is not the same as safety, and a quarterly red-team is a snapshot rather than a guarantee. An insured failure is still a failure.
What it does change is who carries the cost when something goes wrong, which for a procurement officer is frequently the only question that matter
Get the TNW newsletter
Get the most important tech news in your inbox each week.