Security that keeps up with you

Bolt builds with secure defaults, reviews every app before it ships, and runs your code in an isolated browser environment.

An on-demand security engineer

The Bolt.new security agent reads your project, writes the fixes, and applies them for free.

Secure by default

In-built security guardrails

Security starts at generation, not after. Bolt bakes the right patterns into the code it writes.

01

Row Level Security as standard practice

When Bolt generates code that touches a database, it follows Row Level Security best practices as far as the application allows.

02

Authentication that ships correctly

Sessions, password handling, and access checks come from patterns that hold up.

03

Framework defaults, kept intact

Parameterized queries, safe templating, escaped output.

04

Guardrails in the generation layer

Our system prompts carry security constraints on the code that comes out.

Security in detail

Contained coding at speed and scale

Bolt executes your project client-side, inside your browser, in an isolated WebContainer environment. Your code isn't running on shared infrastructure while you build, which removes an entire category of risk before it exists.

01

Isolated by default

Every project runs in its own browser-level sandbox, separated from other projects and from our infrastructure.

02

Encrypted at rest and in transit

Data at rest is encrypted with AES-256 or better. Everything in transit uses TLS 1.2 or higher over HTTPS.

03

Monitored continuously

Automated scanning and intrusion detection run around the clock, watched by a 24/7 security operations team.

04

Tested by outsiders

Independent third-party assessors test our platform every year, and we share pentest report summaries on request.

FAQ

Security questions, answered

No. Your code and prompts are never used to train foundation models. On enterprise deployments, they never leave your tenant.

Bolt is SOC 2 Type 2 certified and compliant with GDPR and CCPA. Full audit details and policies are available on our trust profile.

Yes. BYOK deployment lets you run Bolt inside your own AWS or Azure tenant with full infrastructure isolation and no shared compute, meeting HIPAA, FedRAMP, and SOC 2 requirements.

Turn it on once and Bolt reviews every app before it goes live. When an issue is found, one button analyzes it, applies the fix, and publishes the secured version, at no extra cost.

Our full trust profile at trust.bolt.new has audit reports, published policies, and a way to request documentation directly for your security review.

Bolt Logo

© 2026 StackBlitz - All rights reserved.