NEWS
Verax AI Risk Assessment is live. See what's exposed
Bolt
Bolt
 
Risk Overview
Moderate Risk
4.1
/10
Code Generation
·
Website Generation
·
Workflow Automation
·
Top Risks

Agentic risk: generates and deploys live web applications and executes code in browser environment. AI inputs processed by Anthropic (Claude) under separate terms. Training use of anonymized/aggregated content with limited opt-out. No HIPAA compliance for sensitive data. Security certifications not publicly confirmed. Deployed apps may contain API keys/secrets if user is careless.

Mitigations

Review and execute DPA for enterprise use. Verify subprocessor list and Anthropic data processing terms. Do not include secrets or sensitive data in prompts or published code. Use enterprise account for opt-out of aggregated training use. Confirm SOC 2 status before enterprise deployment. Follow security reminder to not include API keys in published projects.

Get started
Is your team using 
Bolt
 
safely?

Highest Risk Categories

The highest-scoring risk categories identified in this assessment.

Training Use

May use AI Inputs and AI Outputs 'on aggregated, anonymized, or de-identified data' to 'operate, maintain, and improve the Services, including improving AI performance.' Users may have ability to limit or opt out depending on account type/plan. Privacy policy updated May 2026 — significantly more detailed than the 2017 version. Third-party AI providers (Anthropic Claude) process inputs subject to Anthropic's terms.
5
/10

Legal Terms

Privacy policy updated May 2026 includes GDPR and CCPA compliance. Legitimate interests basis for processing. Standard contractual clauses for international transfers. Full ToS review needed for arbitration clauses — StackBlitz ToS references are available but not fully assessed here. HIPAA compliance not confirmed — explicitly noted as concern in third-party reviews. No clear arbitration/class action waiver confirmed.
5
/10

Security Posture

Privacy policy updated 2026 mentions commercially reasonable safeguards. No HIPAA compliance confirmed. No SOC 2 or ISO 27001 certifications publicly confirmed. No GDPR/CCPA regulatory framework documentation confirmed in earlier policy version (2017 version was outdated). 2026 policy significantly improved but third-party certification gaps remain. No bug bounty program found. No public breach history.
5
/10

Unlock the complete assessment

Run a free assessment to access the full AI tool risk analysis.
Start Free Assessment
Updated July 2026 • AI-assisted research • Reviewed by Verax • Report an issue

Reference Documentation

Official documentation and policies referenced as part of this assessment.