Security Audit, but it checks only your database, not your whole project. To check your whole project, including its code, see Check your project’s security.
View Security settings
To open the security settings for your project’s database, follow these steps:
- Log in to your Bolt project.
- In the top center of your screen, click the database icon.
- Click Security.
Fix security issues
Any database security issues Bolt identifies appear on theSecurity Audit page. In the example screenshot below, the RLS Policy Always True warning shows:

- Function Search Path Mutable
- Leaked Password Protection Disabled
If you see this warning, the Prevent Leaked Passwords setting is turned off for your database. It’s on by default for Bolt databases, so this usually means it was turned off or your database is managed in Supabase using a free Supabase plan, where the setting isn’t available. To learn more, see Leaked Password Protection.