Skip to main content
Back to Newsletter
Marketing Compliance

Locked By Default

Gerald GabardiJuly 21, 20265 min read

Written with AI assistance for research, structure, and drafting. The experience, research, and conclusions are the author’s own. The cover image was AI-generated.

Locked By Default

AI tools that build entire apps from plain conversation are having a rough year on the security front. Independent researchers have been scanning apps built this way, and the results aren't a handful of typos. One researcher who scanned dozens of apps built on a popular AI app builder found that roughly two-thirds carried critical or high-severity vulnerabilities, averaging around ten findings per app. One of those apps, with over a hundred thousand views, had a flaw that exposed the personal data of more than eighteen thousand people.

That's not one bad app. Research looking at AI-generated code across these tools more broadly puts the vulnerability rate somewhere between 40 and 62 percent. That's a real, industry-wide pattern, not a fluke.

The Same Mistake, Over and Over

Here's what's actually happening underneath those numbers. The AI builds the feature you asked for, a login, a form, a member feed, and it works. It looks finished. What it skips, more often than it should, is the setting that decides who's allowed to read or write the data sitting behind that feature.

Every one of these platforms sits on a database, and every table in that database needs a rule: can anyone read this, can anyone write to it, or is it locked to just the person it belongs to. A well-built table refuses every request by default until a specific rule says otherwise. A table left without that rule isn't just under-protected, it's wide open to anyone who knows it exists, no login required.

That single missing setting is the root cause behind nearly every one of these incidents. Not a hacker exploiting some clever trick. A database that was never told to lock its own doors.

The One Setting to Ask About

This isn't specific to any one platform, and it isn't a reason to distrust AI-assisted building in general. It's a reason to know exactly one thing about whatever you build on: does it lock every new table by default, or does it leave that decision to whoever's typing the prompt.

Dedicated Cloud, the backend infrastructure this hub runs on, defaults new tables to deny-by-default: a table with no explicit rule is invisible to a visitor, not just restricted. That's a structural choice, not a marketing claim, and it's exactly the kind of default that prevents the failure pattern showing up in the research above.

As an affiliate of ESTAGE, I earn a commission from qualifying purchases. HubArchitect™ is built on ESTAGE.

A Simple Question Worth Asking About Your Own Build

If you don't know whether your own backend locks by default, that's worth finding out before you find out the hard way. Ask whoever built it, or ask the AI building it directly, to confirm every table holding real data has access rules turned on, not assumed. It's a five-minute question that either gets you a clear yes, or tells you exactly what to fix.

Structure isn't just clean pathways and a clear offer. It's just as much about what's actually protecting the data sitting behind the page nobody ever looks at.

Gerald

HubArchitect™

Already building this on ESTAGE?

Squared Away is two hours, one to one, inside your own hub. Pick a day and a time on its page.

Book a Session

Where to go from here

Join the free community, or take the Hub Readiness Diagnostic.

The HubArchitect™ community is hosted within the ESTAGE ecosystem and contains affiliate offers. Community rules →

About the Author

Gerald Gabardi is a retired U.S. Marine Corps veteran and the founder of HubArchitect™, with thirteen years in intelligence analysis behind him — a job that comes down to separating what a source claims from what actually supports it, and saying so when that is inconvenient. He has built on ESTAGE for three years, including time as a beta tester, and more than fifty projects since the AI tooling arrived. He works with entrepreneurs and small business owners to evaluate their digital presence and build stronger, connected digital hubs in place of scattered tools and unclear customer paths. Clients are not left dependent on him either — guided support is available, but the goal is always a hub the client runs themselves.

About HubArchitect™

HubArchitect™ exists for the gap between how good a business actually is and how it looks online. We start with a real look at where that gap shows up, not a pitch, then help build a connected hub instead of another disconnected page. Structure before software. You run it when it’s done.

© 2026 HubArchitect™ / GAPG Innovations. All rights reserved. Brief quotations may be used with attribution. Reproduction or redistribution of this content, in whole or in part, requires prior written permission.

Hub Architect Logo
DIGITAL BUSINESS HUBS

Your Business Is Stronger Than Its Digital Presence.

701 E Franklin Street, Suite 105 #1055,

Richmond, VA 23219

NEWSLETTER

Writing on structure, pathways, and real digital presence. No email required, just read it.

Read the Newsletter →
Veteran-Owned & Operated

© 2026 HUBARCHITECT™ INFRASTRUCTURE, A DIVISION OF GAPG INNOVATIONS. ALL RIGHTS RESERVED.

DISCLAIMER: HUBARCHITECT™ IS A DIGITAL MARKETING AND SOFTWARE INFRASTRUCTURE AGENCY SPECIALIZING IN DIGITAL BUSINESS ARCHITECTURE AND WEB DEVELOPMENT. WE ARE NOT LICENSED ARCHITECTS AND DO NOT PROVIDE PHYSICAL BUILDING, CONSTRUCTION, OR TRADITIONAL ARCHITECTURAL SERVICES. OUR “ARCHITECT” REFERS EXCLUSIVELY TO THE STRATEGIC DESIGN AND TECHNICAL IMPLEMENTATION OF DIGITAL ECOSYSTEMS, WEBSITES, AND BUSINESS SOFTWARE SYSTEMS.

We use necessary cookies to make this site work. If you arrived through a partner or referral link, the platform this site runs on also sets a referral cookie so the referrer can be credited. With your permission, we'd also like to use analytics cookies to understand how the site is used. No analytics cookies load until you choose. Cookie Policy