This page was translated from Dutch with AI.

Security belongs in your briefing, not at the end

Vibe coders who say they have built three apps today must be one hundred percent sure that those apps not only work, but are also secure. I say this in every building training, and I always see a few people swallow hard. Working has become the easy part. Being secure does not happen by itself.

Why afterwards does not work

The classic reflex is: build first, and if it works, we look at security. When building with AI, that is extra risky. The agent makes architecture choices at every step based on what it knows. If it does not know that security is important, it chooses the fastest route. And that fastest route is often difficult to bend back afterwards.

That is why security belongs in your briefing, the document with the requirements with which you start the build. Write in it that the app must be resistant to hidden instructions in input, that secrets are stored encrypted, that personal data is protected and that the app must pass a vulnerability test. An agent that knows this from the beginning builds differently.

Keep reading for free

Register with your e-mail address to read the whole article. It is free, and it opens every article and programme in the learning space.

Already registered? No account yet?

Download as Markdown