Presented by Retool
Vibe coding puts working software in the hands of anyone who can write a prompt. It doesn’t secure any of it. Teams are shipping tools in an afternoon — finance analysts, sales ops managers, support agents — and almost none of it is secured the way software running inside a company is supposed to be.
“Tools get built in hours, sometimes minutes, and they don’t look like ‘systems’ to the people building them.”
That’s how one enterprise CISO described what’s happening inside their organization right now. We surveyed 307 CIOs, CTOs, and CISOs to find out how widespread the problem is. The pattern was consistent: the tools are already inside the building, and hardly anyone can see them, let alone secure them.
Securing something starts with knowing it exists
Only 5% of CTOs, CIOs, and CISOs say they’re very confident they have full visibility into all the internal tools running across their organization. That’s a problem.
Software procurement used to leave a paper trail (usually in the form of vendor contracts, security reviews, or at least a line item somebody had to approve). But AI-assisted and vibe-coded tools are a call coming from inside the house.
Sixty percent of builders report having built something outside IT’s oversight in the past year. Every one of those tools is now something IT hasn’t secured and no one is accountable for. Consider what that looks like in practice: a sales manager exports customer data from Salesforce to a CSV, signs up for a vibe coding platform on a personal account, builds a visualization app, and publishes it to a public URL. Within days, it’s indexed by Google and anyone can find it before IT even knows it exists.
Vibe coding turned security into a board-level problem
Just 4% of leaders say they have governance in place that covers AI-generated code regardless of how it was written; another 4% say the question hasn’t even come up yet. That leaves the overwhelming majority of organizations applying old assumptions about who builds software, and how often, to a process that no longer matches either.
Each tool your team vibe-codes is a potential point of data exposure, compliance failure, or outage that nobody has assessed. This is what makes it a security problem and not just a governance one. Every unsecured tool is a surface someone could get in through, or data could leak out of. The first security incident traced back to a tool nobody knew existed will raise the question: how did this happen without anyone seeing it coming? At that point, you should have.
Securing vibe-coded apps means governance as infrastructure, not configuration
When security is applied per tool, you depend on every builder getting the configuration right, every time, regardless of their coding background or experience. That’s a tall order even for full-time builders, but tools today are being shipped by users across a business trying to self-serve solutions for their full-time roles.
Treat security as a property of the platform, not a task assigned to each builder. Most platforms enforce security at the app level, so when AI writes the app, it’s also writing the security rules. A platform-level approach puts the checkpoint at the data layer instead — every interaction between an app and enterprise data passes through the same governance controls, configured by the organization, enforced regardless of who built the app or how.
Retool’s secure vibe-coding solution is one example of this shift. Instead of living inside each app, access controls sit at the resource and data layer, so every app inherits them automatically. Query-level audit logging runs across every app, and data access is governed with row- and column-level controls that live with the data. SSO, SCIM, and group-based RBAC are built in and applied the same way, whether an app was hand-built, AI-generated, or fully vibe-coded.
Lock down your vibe-coded apps before it’s too late
Slowing down AI adoption is counterproductive to most organizations’ mandates. But without visibility and the ability to secure what gets built, each new incident puts whoever’s accountable in the hot seat.
Leaders should treat security and accountability as properties of the platform itself, enforced regardless of who’s building or how careful they happen to be. That way your organization isn’t scrambling after an incident forces the question.
David Hsu is CEO at Retool.
Sponsored articles are content produced by a company that is either paying for the post or has a business relationship with VentureBeat, and they’re always clearly marked. For more information, contact sales@venturebeat.com.
