Skip to content
Topic

Security

MCP

Keeping AI Automation Safe: Secrets, Permissions and Human Approval

An AI assistant with live access can go wrong in three places: it reads a secret it should not, it acts without approval, or it fails where nobody is looking. Here is the design answer to each, plus seven questions to put to your developer before you switch anything on.

Sandeep Mundra Sandeep Mundra
Keeping AI Automation Safe: Secrets, Permissions and Human Approval
MCP

Keeping AI Automation Safe: Secrets, Permissions and Human Approval

An AI assistant with live access can go wrong in three places: it reads a secret it should not, it acts without approval, or it fails where nobody is looking. Here is the design answer to each, plus seven questions to put to your developer before you switch anything on.

Sandeep Mundra · 14 Sep 2026 · 9 min read

The Ultimate Production-Readiness Checklist for AI-Built SaaS Products
SaaS

The Ultimate Production-Readiness Checklist for AI-Built SaaS Products

A vibe-coded SaaS is not production-ready because the demo works. It is ready when twenty gates — auth, RLS, API caps, CI, and GDPR — can fail the release.

Sandeep Mundra · 22 Aug 2026 · 6 min read

Preventing Client-Side Key Scraping in AI-Generated React Bundles
Security

Preventing Client-Side Key Scraping in AI-Generated React Bundles

If a React bundle can call OpenAI, Stripe, or Supabase with a privileged key, the internet already has that key. Move the call to the server.

Sandeep Mundra · 20 Aug 2026 · 6 min read

Hardening Authentication & Middleware in AI Next.js Applications
Next.js

Hardening Authentication & Middleware in AI Next.js Applications

Client-side redirects from Bolt and v0 are not auth. Put the session in an httpOnly cookie and check it in Next.js middleware and every data route.

Sandeep Mundra · 17 Aug 2026 · 7 min read

Why 90% of Vibe-Coded Apps Leak Data (And How to Audit Yours)
Security

Why 90% of Vibe-Coded Apps Leak Data (And How to Audit Yours)

Most MVPs built on Lovable, Replit, or Cursor ship with an exposed database key or inverted access policy. Here's what IndiaNIC's security team finds in audits, and the 72-hour framework we use to fix it before launch.

IndiaNIC · 1 Aug 2026 · 7 min read

Other topics

Your privacy choices

Pick what we may store. You can change this any time.

Cookie settings

Granular control, stored on this device and honoured on every page.