Security that keeps up with you
Bolt builds with secure defaults, reviews every app before it ships, and runs your code in an isolated browser environment.
An on-demand security engineer
The Bolt.new security agent reads your project, writes the fixes, and applies them for free.
Secure by default
In-built security guardrails
Security starts at generation, not after. Bolt bakes the right patterns into the code it writes.
Row Level Security as standard practice
When Bolt generates code that touches a database, it follows Row Level Security best practices as far as the application allows.
Authentication that ships correctly
Sessions, password handling, and access checks come from patterns that hold up.
Framework defaults, kept intact
Parameterized queries, safe templating, escaped output.
Guardrails in the generation layer
Our system prompts carry security constraints on the code that comes out.
Security in detail
Contained coding at speed and scale
Bolt executes your project client-side, inside your browser, in an isolated WebContainer environment. Your code isn't running on shared infrastructure while you build, which removes an entire category of risk before it exists.
Isolated by default
Every project runs in its own browser-level sandbox, separated from other projects and from our infrastructure.
Encrypted at rest and in transit
Data at rest is encrypted with AES-256 or better. Everything in transit uses TLS 1.2 or higher over HTTPS.
Monitored continuously
Automated scanning and intrusion detection run around the clock, watched by a 24/7 security operations team.
Tested by outsiders
Independent third-party assessors test our platform every year, and we share pentest report summaries on request.
FAQ
Security questions, answered
No. Your code and prompts are never used to train foundation models. On enterprise deployments, they never leave your tenant.
Bolt is SOC 2 Type 2 certified and compliant with GDPR and CCPA. Full audit details and policies are available on our trust profile.
Yes. BYOK deployment lets you run Bolt inside your own AWS or Azure tenant with full infrastructure isolation and no shared compute, meeting HIPAA, FedRAMP, and SOC 2 requirements.
Turn it on once and Bolt reviews every app before it goes live. When an issue is found, one button analyzes it, applies the fix, and publishes the secured version, at no extra cost.
Our full trust profile at trust.bolt.new has audit reports, published policies, and a way to request documentation directly for your security review.