Irfan Habib
Co-Founder, Plutonapps
Co-founder of Plutonapps and a coder by passion who became a T-shaped product developer, Irfan works on distributed systems and leads Plutonapps' engineering, where the team builds its own AI products and turns AI-built apps into dependable production software. He studied at the Indian Institute of Science Education and Research (IISER) Pune.
LinkedInArticles
Lovable Stripe integration: set it up safely
How the Lovable Stripe integration works, built-in payments vs your own Stripe account, and the webhooks, keys and tests a paying app needs before launch.
How much does it cost to build an app in 2026?
What it costs to build an app or MVP in 2026: AI builders, Lovable developers, agencies, in-house hires and subscriptions compared, plus running costs.
Vibe coding security risks, and how to fix them
The security risks of vibe coding: exposed data, leaked keys, trusting the browser, fake packages and unsafe AI features, with a test and a fix for each.
How to hand over an AI-built app to developers
How to hand over a Lovable or AI-built app to developers: accounts to move, the handover pack, how GitHub sync works, and how to test it is complete.
Lovable authentication and secure user roles
How to add sign-in and user roles to a Lovable app safely: where roles must live, how to protect admin areas, Google sign-in, MFA, and how to test it all.
Backups and disaster recovery for Supabase apps
What Supabase backs up on Free, Pro and PITR, what it leaves out, how Lovable Cloud backups work, and how to rehearse a restore before you need one.
Supabase RLS policy examples and mistakes
Supabase RLS policy examples for owner, team, public, admin and storage access, with a test for each and common mistakes that break or open your tables.
Technical due diligence before you raise
What investors check in technical due diligence, what changes when AI wrote your code, the evidence to prepare, and a 30-day plan before you raise.
Scaling a Lovable app: what breaks first
Scaling a Lovable app: why the database breaks first, how to fix indexes, connections and slow functions, and how to load-test before a traffic spike.
How to test an AI-built app before launch
How to test a Lovable or AI-built app before launch: which journeys to test first, two-account access checks, payment failures, and tests on every change.
Lovable SEO: why your site is not indexed
Why a Lovable site is not indexed by Google: privacy settings, noindex, robots.txt, client-side rendering, duplicates, and the Search Console fix for each.
How to choose a tech partner for your MVP
How to choose a tech partner for your MVP: what to decide first, questions to ask, who owns the code, red flags, and why a paid first task beats a pitch.
App maintenance cost: what an app costs to run
What it costs to run an app after launch: hosting, database, monitoring, upgrades, security patches and engineering. Sourced prices and a 5-step estimate.
Apps built with Lovable that run in production
Real apps built with Lovable, with sources: which run in production, which are pre-launch, and what each one needed after Lovable to carry users and money.
Lovable limitations and how to work around them
Lovable limitations in 2026: credits, backend logic, testing, staging, mobile and migration, with a workaround for each and when to bring in engineers.
Refactor or rebuild your AI-built app?
Refactor or rebuild an AI-built app? A six-area scorecard, the signs a rebuild is right, and how to replace an app piece by piece without stopping it.
Lovable app to the App Store and Google Play
How to get a Lovable app into the App Store and Google Play: PWA, Capacitor, wrapper or rebuild, Apple's review rules, Google's testing step and costs.
Lovable prototype to production: a case study
How Looph went from a Lovable prototype to production in 28 working days: the baseline, the gates, row-level security on 172 tables, hosting and releases.
Lovable OpenAI integration: keep your key safe
Add OpenAI to a Lovable app safely as of 2026: Lovable AI vs your own key, Secrets and edge functions, per-user limits, spend caps and prompt injection.
Lovable email with Resend: reach the inbox
Send email from a Lovable app with Resend that reaches the inbox: domain records, Supabase auth emails, the email verification error, retries and bounces.
Most advanced AI models right now (Oct 2026)
The most advanced AI right now, checked 7 Oct 2026: Claude Opus 5.5, GPT-6 Astra and Gemini 4 Argon, which leads each leaderboard and how they are ranked.
Which rules your product actually has to meet
GDPR, UK GDPR, CCPA, HIPAA, PCI DSS, SOC 2, ISO 27001 and the EU AI Act in plain words: who each applies to and what it means for a Lovable app.
Comparisons and guides
Agency vs freelancer vs in-house developer vs subscription
Four ways to get a product engineered, compared on cost, speed, risk and who runs it after launch, including when each is the better fit.
Development subscription vs agency: which should you choose?
How each prices work and change, what happens after launch, and when a fixed-scope agency project is the better fit.
In-house developer vs development subscription: the real cost
What a US software developer costs once benefits are counted, from BLS data, against a flat monthly subscription, and when hiring still wins.
Lovable vs Bolt vs Replit: which should you start in?
Pricing, backend, hosting, code ownership and mobile support from each vendor's own docs, and what all three leave to do before production.
Lovable app not working in production? How to make it production-ready
Why apps that work in preview break with real users, the checks that make one production-ready, and who keeps it running.
How to hire a Lovable developer (and what it costs)
Freelancers, Lovable partner agencies and engineering subscriptions compared on cost, scope and who runs the app afterwards.
Lovable app security checklist: is your app secure?
A checklist for RLS, keys, payments and monitoring, with a way to verify each item, and what CVE-2025-48757 means for you.
How to migrate off Lovable Cloud to your own Supabase
Lovable Cloud vs your own Supabase, what the export includes and leaves behind, and a cutover plan that keeps production running.
Glossary
AI app builder
An AI app builder turns a plain-language description into a working web app: screens, data and logic. What one does well, and what it leaves for engineers.
Audit log
An audit log is a permanent, append-only record of who did what in a system. What belongs in one, how it differs from app logs, and why buyers want it.
Authentication vs authorization
Authentication proves who a user is; authorization decides what they may do. The difference, with examples; why AI-built apps often get only the first right.
Background job
A background job is work an app does outside the user's request, like sending email, through a queue that can retry. What it is, and why live apps need them.
CI/CD
CI/CD means every change is built and tested automatically, then released through an automated pipeline. What CI and CD each mean, and why apps need both.
Code audit
A code audit is a structured review of a codebase for security holes, reliability risks and maintainability. What it covers, and when an AI-built app needs one.
Code handover
A code handover moves software, its knowledge and its access from one team to another. What a complete one includes, and what to ask for before you sign off.
Data processing agreement (DPA)
A data processing agreement is the GDPR contract between a business and a supplier that handles personal data for it. What a DPA covers, and who needs one.
Database index
A database index lets the database find rows without scanning the whole table. What an index does, and why apps without the right ones slow down as they grow.
Development subscription
A development subscription buys software engineering as a flat monthly plan instead of hourly billing or fixed projects. How it works, and how it compares.
End-to-end testing
End-to-end testing drives a real browser through a user's whole journey, such as sign-up to checkout. What E2E testing is, versus unit and integration tests.
Feature flag
A feature flag is a switch that turns a feature on or off for some or all users without a new release. What flags are for, the four kinds, and how they fail.
Fractional CTO
A fractional CTO is a senior technology leader who works for a company part time, setting technical direction without a full-time salary. What one does.
Idempotency
Idempotency means running an operation twice has the same effect as once, so retries never charge or send twice. What it is, and how idempotency keys work.
Incident response
Incident response is the plan for detecting, containing and recovering from outages and breaches, then learning from them. What it involves for a small team.
Load testing
Load testing puts an app under realistic traffic to measure how it performs before users do. What it is, how it differs from stress testing, what to watch.
Lovable Cloud
Lovable Cloud is the backend built into Lovable: database, sign-in, storage and server functions on Supabase. What it covers, and what production still needs.
Minimum viable product (MVP)
A minimum viable product is the smallest complete version of a product that gives real users real value. What an MVP is, and how it differs from a prototype.
Model Context Protocol (MCP)
MCP, the Model Context Protocol, is an open standard connecting AI assistants to apps through tools. What it is, how it works, and why products are adding it.
Multi-factor authentication (MFA)
Multi-factor authentication asks for two or more kinds of proof at sign-in, such as a password and a one-time code. What MFA is, and how it differs from 2FA.
Multi-tenancy
Multi-tenancy means one app and database serve many customers, each walled off from the others. What it is, how isolation is enforced, and where it fails.
OAuth
OAuth 2.0 lets an app act on a user's account elsewhere, such as reading Gmail, without their password. What OAuth is, and how it relates to Google sign-in.
Observability
Observability is knowing what a live system is doing, and why, from its logs, metrics and traces. How it differs from monitoring, and what a new app needs.
Penetration test
A penetration test is an authorised, simulated attack on your app by testers to find weaknesses that can be exploited. What it covers; when to get one.
Point-in-time recovery (PITR)
Point-in-time recovery restores a database to its exact state at a chosen moment, not just last night's backup. What PITR is, and how it relates to RPO and RTO.
Product engineering
Product engineering is building and running software as a product: architecture, data, security, testing, releases and operations, end to end. What it covers.
Production-ready
Production-ready software is safe to put in front of real users: secured, tested, monitored and recoverable. What the term covers, as a checkable list.
Rate limiting
Rate limiting caps how many requests a user, key or IP address can make in a period. What it protects against, and why AI features need spending limits as well.
Refactoring
Refactoring restructures existing code without changing what it does, so the next change is cheaper. What it is, and when to refactor rather than rewrite.
Regression testing
Regression testing re-runs existing tests after every change to prove that what worked before still works. What it is, and why AI-built apps need it most.
Role-based access control (RBAC)
Role-based access control grants permissions to roles, like admin or viewer, and roles to people. What RBAC is, how it relates to least privilege, and pitfalls.
Row-level security (RLS)
Row-level security is a database rule that decides which rows each user may read or change, enforced by the database. Why AI-built apps need it on every table.
Schema migration
A schema migration is a versioned script that changes a database's structure, applied in order everywhere. What it is, and why AI-built apps need them.
Secrets management
Secrets management is how an app stores, limits, rotates and audits its API keys, passwords and tokens. What it covers, and the leaks it stops in AI-built apps.
Single sign-on (SSO)
Single sign-on lets people use one company login for many apps, via SAML or OpenID Connect. What SSO is, and why enterprise customers ask for it before buying.
SLA vs SLO vs SLI
An SLI measures a service, an SLO sets its target and an SLA promises it in a contract. The difference, what 99.9% uptime means in minutes, and error budgets.
SOC 2
SOC 2 is an independent auditor's report on how a company protects customer data. What it is, Type 1 vs Type 2, and the engineering work that sits behind it.
Staff augmentation
Staff augmentation adds outside engineers to your team, managed by you, for as long as you need them. How it differs from managed teams and subscriptions.
Staging environment
A staging environment is a private copy of production where each release is checked before real users see it. What staging is, and how it differs from previews.
Supabase
Supabase is an open-source backend platform built on PostgreSQL, with sign-in, storage and APIs. What it gives an AI-built app, and what it leaves to you.
Supabase anon key vs service role key
The Supabase anon (publishable) key is safe in the browser; the service role (secret) key bypasses row-level security. Which is which, and where each belongs.
Technical co-founder
A technical co-founder is a founder who owns building the product and holds equity for it. What the role involves, and the options when you cannot find one.
Technical debt
Technical debt is the future cost of shortcuts in code: each later change takes longer until it is paid down. What it is, and why AI-built apps collect it fast.
The real product
The real product is the live version of the app you design in Lovable, engineered and run by Plutonapps. What it is, and why it was once called a Product Twin.
Vendor lock-in
Vendor lock-in is when leaving a supplier costs so much you effectively cannot. How it happens with AI app builders and agencies, and how to keep the exit open.
Vibe code cleanup
Vibe code cleanup is engineering work that makes AI-generated code safe and maintainable for real users. What it covers, and how it differs from a rewrite.
Vibe coding
Vibe coding means building software by describing it to an AI in plain language and accepting the code it writes. What it is, and where it stops working.
Webhook
A webhook is an HTTP request one service sends your app when an event happens, such as a payment succeeding. How webhooks work, and how they fail in production.