# Best Practices - App Security

**URL:** https://community.weweb.io/t/best-practices-app-security/17278
**Category:** Ask us anything
**Created:** [March 18, 2025, 5:10pm UTC](https://community.weweb.io/t/best-practices-app-security/17278 "2025-03-18T17:10:34Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![TechaSoftware](https://avatars.discourse-cdn.com/v4/letter/t/90ced4/32.png) [@TechaSoftware](https://community.weweb.io/u/TechaSoftware)
#### Post date: [March 18, 2025, 5:10pm UTC](https://community.weweb.io/t/best-practices-app-security/17278/1 "2025-03-18T17:10:34Z")

</div>

Hi all,

I have noticed on X that a developer who shared their build that they built on Cursor has had their work hacked/tampered with - which is a big shame.

I am inexperienced with WeWeb, so I am asking for more insight on best security practices.

I am definitely going to get some sort of security audit done on each project I build - better safe than sorry.

Any advice is welcome!

---

<div class="post-metadata">

### Author: ![Micah](https://sea2.discourse-cdn.com/flex016/user_avatar/community.weweb.io/micah/32/9102_2.png) [@Micah](https://community.weweb.io/u/Micah)
#### Post date: [March 18, 2025, 7:33pm UTC](https://community.weweb.io/t/best-practices-app-security/17278/2 "2025-03-18T19:33:52Z")

</div>

What backend are you using?

---

<div class="post-metadata">

### Author: ![TechaSoftware](https://avatars.discourse-cdn.com/v4/letter/t/90ced4/32.png) [@TechaSoftware](https://community.weweb.io/u/TechaSoftware)
#### Post date: [March 18, 2025, 11:02pm UTC](https://community.weweb.io/t/best-practices-app-security/17278/3 "2025-03-18T23:02:08Z")

</div>

I am going to use Supabase for my backend

---

<div class="post-metadata">

### Author: ![Micah](https://sea2.discourse-cdn.com/flex016/user_avatar/community.weweb.io/micah/32/9102_2.png) [@Micah](https://community.weweb.io/u/Micah)
#### Post date: [March 19, 2025, 12:36am UTC](https://community.weweb.io/t/best-practices-app-security/17278/4 "2025-03-19T00:36:48Z")

</div>

Just don’t use API keys on your front end and enforce proper rls on your tables and you should be good 👍

---

<div class="post-metadata">

### Author: ![ishika](https://sea2.discourse-cdn.com/flex016/user_avatar/community.weweb.io/ishika/32/13250_2.png) [@ishika](https://community.weweb.io/u/ishika)
#### Post date: [March 19, 2025, 5:23am UTC](https://community.weweb.io/t/best-practices-app-security/17278/5 "2025-03-19T05:23:36Z")

</div>

Hey Scott!  
Here are some resources on security best practices:  
1/ [Ensure Web Application Security with 4-Step No-Code Best Practices](https://go.weweb.io/9bkAcV8)  
2/ [Securely using API Keys from a Frontend No-code App](https://go.weweb.io/QaIeEzi)

Hope this helps 🙂

---

<div class="post-metadata">

### Author: ![TechaSoftware](https://avatars.discourse-cdn.com/v4/letter/t/90ced4/32.png) [@TechaSoftware](https://community.weweb.io/u/TechaSoftware)
#### Post date: [March 19, 2025, 4:12pm UTC](https://community.weweb.io/t/best-practices-app-security/17278/6 "2025-03-19T16:12:45Z")

</div>

Thank you Ishika - this is perfect 👌🏻

---

<div class="post-metadata">

### Author: ![Profound5753](https://sea2.discourse-cdn.com/flex016/user_avatar/community.weweb.io/profound5753/32/6870_2.png) [@Profound5753](https://community.weweb.io/u/Profound5753)
#### Post date: [March 22, 2025, 5:47am UTC](https://community.weweb.io/t/best-practices-app-security/17278/7 "2025-03-22T05:47:46Z")

</div>

I also run security audits on Weweb projects. Let me know if you’re ever interested.
