---
title: "Security belongs in your briefing, not at the end"
description: "Building an app with AI is fast. Building a secure app requires you to include security from the start, keep your secrets safe, and have a second agent attack your work."
language: en
source: https://coachsteff.live/en/veiligheid-vanaf-de-briefing
---

# Security belongs in your briefing, not at the end

Vibe coders who say they have built three apps today must be one hundred percent sure that those apps not only work, but are also secure. I say this in every building training, and I always see a few people swallow hard. Working has become the easy part. Being secure does not happen by itself.

## Why afterwards does not work

The classic reflex is: build first, and if it works, we look at security. When building with AI, that is extra risky. The agent makes architecture choices at every step based on what it knows. If it does not know that security is important, it chooses the fastest route. And that fastest route is often difficult to bend back afterwards.

That is why security belongs in your briefing, the document with the requirements with which you start the build. Write in it that the app must be resistant to hidden instructions in input, that secrets are stored encrypted, that personal data is protected and that the app must pass a vulnerability test. An agent that knows this from the beginning builds differently.
