Built with Base44
The last step in their docs is you.
Base44 builds the security scan into the dashboard and puts the rest in writing: the tools are theirs, the settings are yours.
Every claim below is Base44’s own documentation, linked to the page it came from. What follows is the half of the job its own pages say waits for you.
Base44 is a trademark of its owner. This page quotes public documentation to explain a scope of work. There is no partnership, endorsement or affiliation in either direction.
What stays yours
What the dashboard waits for.
Base44 encrypts, hosts and deploys, and its overview is direct about the remainder: some settings depend on how your app is built and who uses it. These four are the remainder.
Running the scan before you publish
The overview is unambiguous: “You are responsible for your app’s security settings. Base44 provides the tools, but always review your permissions and run a security scan before you publish.” The scan exists either way; the sentence is about whether it ran.
Reading what it found
“The security scan checks your entire app and shows you a clear list of any issues it finds.” The clear list is the platform’s half. The list read, weighed and acted on is yours.
The permission rules on every table
Base44 writes data permissions as you build, and its own page names the stake: “If permissions are not set up correctly, the wrong people could view or change data in your app.” An automatic setup is a draft, and a draft guarding customer data wants a reader.
Knowing that one rule is enough
The rules combine as OR, in the platform’s words: “If a person matches any one rule, they get access.” A careful rule sitting next to a loose one is, in effect, the loose one.
Check it tonight
The scan first, then three questions.
Base44 put the first check inside the product. The other three take a browser and a private window.
Run the security scan and read every card
Dashboard, Security, Run Security Scan. It checks six kinds of issue and lists what it finds. Everything on that list is a decision your platform has already queued for you.
Read each entity’s rules as OR, not AND
Open the permissions on every table and remember the sentence: matching any one rule grants access. You are looking for the single loose rule parked next to the careful ones.
Check who can open the app at all
Private, workspace, or public with the link. If it says public and the app was meant for a team, the entire difference is one dropdown that was never revisited.
Load one of your records without signing in
Copy the address of a record you own and open it in a private window. If it renders, sign-in was decoration on that path, and the scan’s login-verification check deserves a second look.
A finding the scan already made costs nothing to read and something to ignore. The free prompt reads for what the scan does not.
What a read adds
What a scan calls clean.
The scan checks six kinds of issue, and the six are real. It cannot say whether a rule that passes is the right rule for your users, and it has no row for the thing that was never built.
The audit is that read. The method it follows is public, boundaries first.
€350 + VAT · 48 hours
An independent pass over your app.
Your repository and your live app, every finding with the evidence, what it costs you and a prompt you can paste back into Base44.
€430.50 including VAT.
Start here
Ask for the fit check first.
Five questions about the app and its users, and a start date if it fits.