Backups the app cannot reach, and one restore you have actually done
Ask: which credential can delete the newest backup? If the answer is any credential the app or an agent holds, there is no backup.
Get every Fix AI Slop Code episode
The code it wrote, the code it should have written and a check, for every episode
What is going on
The free plan has no backups. The paid plan has seven daily and none of your storage files. Point-in-time recovery is a paid add-on. A backup on the same account the agent can delete from is not a backup, which is the PocketOS story in one line.
Where it bit
The video pipeline, in a different shape: nothing is deleted locally until the archive copy has been verified by checksum, and we still found two "archived" exports that were not on the drive at all during the storage sweep. Same rule, same failure mode, different files.
The practice
A scheduled supabase db dump to a bucket the app's credentials cannot write to or delete from. Storage files included. One restore drill, timed, so the number "how long until we are back" exists.
Get this check as a script you can run tonight

The coding agent never holds production credentials
An agent with a production database URL will sooner or later run a migration or a cleanup against it, so production secrets never enter its env
Keys go in headers, never in URLs
A URL is written to server logs, CDN logs, browser history and error trackers, so an API key in a query string is a key in five places
2 min readClaude's /security-review found 31 vulnerabilities, and 5 were real
A product with four years of security work behind it ran Claude's /security-review. It reported 31 vulnerabilities. After the engineers checked each one, 5 were worth fixing
If this check came back with more than you expected, that is worth a conversation