The FTC just extracted .5B from Amazon over hard-to-cancel subscriptions. If your course portal, membership site, or checkout was vibe-coded with Lovable, Bolt, or Replit, we find and fix the gaps before a regulator, a hijacked account, or a churned customer finds them first.
Get a Free Security Scan Book an AI App AuditCoaches, creators, and course-sellers increasingly vibe-code their own course portals, checkouts, funnels, and client-intake apps — platforms with documented critical security failures in 2025, including CVE-2025-48757, the Base44 auth bypass, and Replit's agent deleting a production database. Their regulatory surface is unusually concentrated: recurring billing puts them under ROSCA and a 35-state auto-renewal patchwork, their email/SMS list is both core asset and legal liability, and testimonials or income claims sit under active FTC enforcement. A single account takeover of the creator's own email platform, Stripe, or channel can end the business.
These are the apps we see coaches, creators, and course-sellers stand up fast with AI builders — and exactly where the risk sits in each one.
Missing row-level security exposes student names, emails, and payment data — exactly the CVE-2025-48757 flaw where 170 of 1,645 audited Lovable apps (10.3%) leaked data across 303 endpoints.
AI-generated Stripe subscription code typically ships with no compliant cancel flow, no consent records, and no renewal reminders — ROSCA and California's AB 2863 violations at up to per violation. A custom payment page also pulls the site into PCI DSS 4.0 script-integrity requirements.
Platform-level auth bypass is a real risk: Wiz showed any "private" Base44 app could be opened with just a public app_id.
No lawful-basis or consent capture and no opt-out plumbing for EU/California subscribers — GDPR exposure up to €20M/4%, CCPA at – per violation — plus the harvested list often sitting in an unsecured database.
TCPA exposure runs – per text. Since April 11, 2025 the FCC requires honoring revocation via any reasonable method within 10 business days — AI-built forms rarely log consent or process non-STOP opt-outs.
Coaching intake covering sleep, stress, anxiety, weight, or medications is health-adjacent. A wellness app "drawing information from multiple sources" can fall under the FTC Health Breach Notification Rule, where unauthorized disclosure counts as a breach at /violation.
API keys hardcoded in frontend code is a documented failure pattern — one founder's exposed keys were maxed out by attackers within days of launch.
Recurring billing, an email list, and testimonials on a sales page put coaches and creators under more overlapping regulation than most solopreneurs realize.
| Regulation | When It Applies | Penalty |
|---|---|---|
| ROSCA | Any online recurring/negative-option billing — memberships, subscriptions, free trials | Up to /violation; Amazon paid .5B |
| California ARL (AB 2863, eff. Jul 1, 2025) | Contracts with CA consumers — requires click-to-cancel, same-medium cancellation, 3-year consent records, annual renewal reminders | CA AG/DA enforcement; private lawsuits under §17200 |
| State auto-renewal laws (35 states + DC) | Selling subscriptions into those states | Varies by state; several allow private rights of action |
| CCPA/CPRA | For-profit doing business in CA meeting thresholds, including ad-pixel data sharing | /violation, intentional or minors; Healthline paid .55M |
| GDPR | EU/UK residents on your email list or buying your course — no size exemption | Up to €20M or 4% of worldwide turnover |
| PCI DSS 4.0/4.0.1 | Accepting cards; custom payment pages trigger script-authorization requirements (mandatory since Mar 31, 2025) | –nth escalating to nth, plus breach costs |
| TCPA + FCC revocation rules | Marketing texts/calls without prior express written consent; must honor opt-out within 10 business days since Apr 11, 2025 | /text, willful, uncapped class exposure |
| FTC Health Breach Notification Rule | Wellness/mental-health-adjacent coaching apps drawing identifiable health info from multiple sources | Up to /violation (per day of continuing violation) |
| FTC Consumer Reviews & Testimonials Rule | Fake/AI-generated testimonials, undisclosed insider reviews, unsubstantiated earnings claims | Up to /violation; Operation AI Comply has sued course sellers |
.5B settlement (B civil penalty + .5B redress to ~35M consumers) over deceptive Prime enrollment and cancellation — the controlling precedent for anyone selling subscriptions.
697,313 user records — emails, phones, metadata — scraped via exposed API endpoints; no passwords or financial data taken.
Any "private" app on the platform was accessible with just a public app_id, bypassing SSO; fixed within 24 hours.
170 of 1,645 showcased Lovable apps (10.3%) exposed names, emails, API keys, and financial records via missing Supabase row-level security.
M FTC order and M+ refunds to 40,000+ consumers for billing after cancellation requests and sharing mental-health data for ads — directly analogous to wellness-coaching intake data.
Sweep against AI-hyped business-opportunity and course schemes, including a seller with alleged losses of M+; permanent bans secured in 2025.
Yes, if you have any auto-renewing subscription, membership, or free-to-paid trial billed online. ROSCA requires clear disclosure, express informed consent, and a simple cancellation mechanism, with penalties up to per violation. Amazon's .5B settlement shows the FTC is actively enforcing this.
If it uses Supabase and you haven't explicitly verified row-level security on every table, it may be. This flaw exposed 170 of 1,645 audited Lovable apps, leaking student names, emails, and payment data across 303 endpoints. We test for this exact misconfiguration.
Usually not HIPAA itself, since most coaches aren't covered entities, but the FTC's Health Breach Notification Rule can still apply if your app draws identifiable health information from multiple sources. Unauthorized disclosure counts as a reportable breach at up to per violation.
Yes, if you use testimonials or reviews. The rule, effective October 21, 2024, bans fake or AI-generated testimonials, undisclosed insider reviews, and unsubstantiated income claims, with penalties up to per violation.
Enable MFA on your email platform, Stripe, and content-channel logins, and avoid hardcoding API keys in frontend code. US account-takeover losses hit .6B in 2024, and a single hijacked login can end a solopreneur business overnight.
Most course-portal, checkout, or intake-form audits complete within a few business days. We start with a free automated scan, then a manual review of authentication, RLS/database access, and billing-flow compliance before handing you a prioritized fix list.
Related searches: is my lovable app secure · lovable supabase row level security fix · AI built course website security audit · click to cancel law membership site 2025 · ROSCA compliance online course subscription · california automatic renewal law coaching program · GDPR requirements email list coach · stripe subscription cancellation law · my email marketing account hacked what to do
Get a free automated scan of your course, membership, or coaching app — then a full audit if you need one.
Get Your Free Security Scan