Vibe-Coded Apps Are Reaching Production Faster Than They Are Being Tested
AI build tools let anyone ship a working app in a weekend. Here is what we find when we penetration test them, and what to do before yours goes live.
We are seeing more internal tools built on AI platforms | client portals, intake forms, matter trackers. They work. That is exactly the problem: working and secure are not the same thing, and the speed of the build creates a false sense of finish.
The recurring findings
- Database access rules missing entirely, so any visitor can read every record.
- API keys and secrets shipped in front-end code where anyone can read them.
- Authorisation checked in the interface only, so hiding a button hides nothing.
- File uploads with no type or size validation.
- Verbose error messages that hand an attacker your schema.
Why standard advice does not land
Traditional penetration testing was priced and paced for annual releases. A team shipping changes weekly needs testing on the same rhythm, with a report that is readable by the person who will fix it.
That is why our Vibe Code penetration test runs monthly on subscription, with a retest of previously flagged issues included. Fast builds need a fast feedback loop.
Before you go live
- Confirm row-level access rules exist on every table holding client data.
- Move every secret to server-side configuration.
- Re-check authorisation on the server for every action, not just in the UI.
- Have someone independent try to break it.
Read next
This Week: Why Most Proclaim Builds Fail A Simple Audit
Notes from a week of Proclaim build audits | what we keep finding, why it happens, and the three checks every firm should run on its own build.
LeadershipWhat A Fractional CTO Actually Costs A Law Firm
A straight answer on pricing, what you get for it, and when a fractional arrangement stops making sense compared with a full-time hire.
Facing something similar?
Book a 30-minute strategy call and we will tell you straight what we would do.
Book a strategy call