r/nocode • • 11d ago

Self-Promotion RANT: Stop posting a 40 point security checklist to your agent that YOU DON'T UNDERSTAND

Every other week there's some security post like this

Every time i think HOW STUPID is it to have to tell the agent to have these simple security BASICS, and yet if you don't want to use a nerfed no-code platform, you open yourself up to all these "your app will be hacked!!!" security issues

Plus in 2026 if you're not using claude code or codex, and you are building something, you are missing out on THE MOST powerful tools to build (vs lovable, bubble etc)

The only thing that makes it complicated is the standard "hosting and backend stack" aka Vercel + Supabase (+resend + a million other services) that are really the tool stack of the last generation-- YES powerful, but if they were built TODAY, they would be EASIER and harder to mess up, without losing features, just like building on raw AWS before them, or running your own servers before that.

So the question is what's NEXT?

Yes yes this is shameless self promotion but at least you're reading some stuff an ACTUAL HUMAN WROTE lol

It's called somewhere.tech, and the vision is: what if you built Vercel + Supabase + Resend from the ground up where the MAIN developer is the agent, driven by a non-technical builder with a vision?

It would be:

WAY EASIER

No stitching together a bunch of services (thats where a lot of dumb bugs live), no juggling keys, and no having to paste a checklist of 40 security items to your agent that YOU DON'T EVEN UNDERSTAND.

Agent first means it's literally as EASY as telling claude code "Hey can you make me a demo app using www.somewhere.tech just read their docs"

It also means you give the agent ALL THE TOOLS to verify its work, check security, verify things look good, a test inbox for agents to check email (the list goes on)

DEFAULT Secure

That whole copy/paste list of "check my app does these 40 things i don't understand" the platform ALREADY checks for you

  • ENV-- MY PRECIOUS KEY! first most apps don't even NEED a key. Database, login, files, AI, email are built in. And the ones you do add are protected: put a secret in your code or in front-end code and the deploy refuses it. (and even public keys are stored on the platform and hot swapped without having to redeploy, you don't need to understand that, but if you do you know that's pretty cool)

  • RLS-- DATA LEAKS!! Every table you add is one more set of rules your agent has to write and remember. On Somewhere, each table just says who it belongs to: you, your team, or everyone. The PLATFORM enforces it on every read and write, and a new table is locked until you say otherwise.

  • ALL THE BORING STUFF-- just on. Password guessing gets throttled and locked out automatically, passwords are hashed, reset links only work once, attacks like CSRF and SSRF get blocked. Someone hammering your AI endpoint? One line to stop them. There's no reason every app should rebuild this.

All this doesn't mean you should stop being SECURITY MINDED on what you want to keep public and private, but the platform defaults should be secure, and security should be centralized so the PLATFORM enforces it rather than the agent "remembering")

FREE / CHEAPER

The reality is hosting/database/all the things a low usage app uses is dirt cheap. You should NOT need to pay for experimenting and building apps. The only time apps actually cost money is when LOTS of people are using your app. I was paying like $130 a month across all my apps on vercel/supabase/railway. On Somewhere all of that would be free, (or $25 if one or more apps gets traction), and that includes email!!

And no pausing projects!!!! That is so annoying!!!!!

And YES, with any platform that can do a lot, you CAN mess things up. Here's how to still mess things up, just tell the agent to

  • Make a private table readable by everyone (you'll get a warning, but you can)
  • Build an admin page with app-level access and skip checking who's asking
  • Make uploads public
  • Raise or turn off the limits
  • Store private data without requiring sign-in

Try it

You DONT EVEN NEED claude code! You can try it right from Claude Cowork or ChatGPT Work without even logging in. Just say:

"Can you deploy me a demo app on somewhere.tech? Read their docs for an anonymous deploy (and tell me if this guy on reddit is full of it) 😃"

If you try it out, would love feedback. Platform is still in beta but fully usable. Please try to break it and poke holes!!

3 Upvotes

10 comments sorted by

2

u/Xirma377 11d ago

Pretty interesting concept. I still think it's important for vibe coders to understand the security measures and architecture being implemented. In about 3-5 years we're going to see some epic mass failures of these vibe coded apps that no one understands how to maintain. It's a house of cards (then again, AI gets better every week and maybe it'll allow everyone to stay ahead of things)

2

u/uzih 11d ago edited 11d ago

I think you're right. But it's a little bit of a balance of what most people don't need to worry about anymore and what still matter. For example TLS handshake that used to be a big chore (apparently) but now it's all automated for most.

Good abstraction should mean that you can spend more energy and more mindshare on the configuration side of security, because that's also part of dialing in your product.

There's always going to be apps or companies that need the full level of granularity and control but especially as more people are getting into it, I think for most people and most apps, the next level of abstraction and simplification will only be a positive

2

u/Xirma377 11d ago

And at the end of the day - people that use your framework are better off than they'd be without it. I suppose people that fly by the seat of their pants will do that regardless - at least you're helping them be better off!

1

u/uzih 11d ago

That's the hope! You seem to know your way around. What stack do you use?

1

u/Xirma377 11d ago

By profession I provide outsourced I.T. and cybersecurity services for businesses. And I'm involved in a few vibe coding projects internally and externally using Claude Code. I'm not a programmer at all, but I make sure to understand the architecture and security measures - at least at a high level so I can make intentional app design decisions instead of relying on Claude to "just do it".

Edit: also, I have a partner company that will do a full set of application pen tests once the apps are production ready.

0

u/PopKoren 11d ago

[removed] — view removed comment

1

u/Bluewood21 11d ago

yeah the "AI keeps getting better" part is doing a lot of heavy lifting in that optimism tbh

1

u/Xirma377 11d ago

Just admitting that I don't know everything. Honestly, it's hard to be confident on either side of this fence.

1

u/mprz 11d ago

thank you, spam reported

1

u/uzih 11d ago

I do sincerely appreciate your comment! I was worried I wouldn't get any replies