Skip to content

Security & risk, read from an operations desk

Everything we have published under Security & risk, read from an operations desk: what it changes for a B2B company of 10-200 people.

  1. Latest

    Security Firm Finds 16,000 Exposed Supabase Databases Tied to Vibe-Coded Apps

    Cybersecurity firm UpGuard found approximately 16,000 Supabase-hosted databases publicly exposing personal data — names, addresses, phone numbers, and some passwords — often due to misconfiguration in AI-generated ('vibe-coded') apps. Supabase says security is a shared responsibility; the exposures show how fast, AI-assisted app building can outpace basic access-control hygiene.

    What changes for operators — If your team has used AI coding assistants or no-code/low-code tools to quickly stand up a customer database, internal dashboard, or lead-capture app on Supabase or a similar backend, this is a direct prompt to audit access rules now, not after a breach. Vibe-coded apps are often shipped by non-security-specialists who accept default settings, and the defaults are not always safe — UpGuard's findings show real production data (contact info, tokens, even intercepted verification codes) sitting open to the public internet. For a 10-200 person company, the fix is cheap relative to the exposure: a scheduled review of row-level security and public API access on every database backing a customer-facing or vibe-coded tool, treated as a standing item, not a one-time launch check.

  1. Claude Now Embeds Detectable Watermarks in Generated Text

    If your sales or support team uses Claude to draft outbound emails, proposals, or knowledge-base articles, assume that output can now be identified as AI-generated by anyone running a compatible detector. Some enterprise clients and procurement processes already require disclosure of AI-assisted content or reject it outright — this watermark makes that detection trivial rather than probabilistic. Ops leads should audit which customer-facing templates run through Claude, decide whether disclosure language needs to be added to contracts or email footers, and check whether any CRM or support tool integrations strip formatting in ways that could break or preserve the watermark. Teams that repurpose Claude output through multiple editing passes (rewriting, translation, merging with human text) should also test whether the watermark survives those transformations before assuming it does or doesn't apply.

  1. Grok Misuse Allegation Puts AI Image Tools Back Under Scrutiny

    If your company has rolled Grok or any similar image-generation feature into internal chat tools, customer-facing apps, or employee devices via X/Twitter integrations, this is a moment to check what content policies and logging are actually enforced — not assumed. A 10-200 person B2B firm rarely thinks of itself as an "AI safety" business, but if a vendor's generative model can be misused this way on a personal account, the same model embedded in your stack carries the same risk profile. Audit which AI tools touch personal photos or customer-uploaded images, confirm content moderation is active by default rather than opt-in, and make sure your acceptable-use policy explicitly bars using company AI subscriptions for image manipulation unrelated to business purposes. This isn't about the news itself — it's about the fact that the underlying tool is in wide commercial use and could sit inside your vendor stack today.

Next step

Free AI Diagnostic

Fifteen minutes, no email required. It maps where your work actually goes and ranks what is worth automating first.

Start the free diagnostic

Starts immediately in the browser.

Fee
Free
Length
15 minutes

You keep the ranked list of candidates either way.