Uploaded on Sep 20, 2026
This presentation focuses on the security challenges associated with the rapid adoption of low-code and no-code platforms like Retool by "citizen developers" (business builders). It highlights vulnerabilities, such as a 2023 breach affecting 27 cloud customers through social engineering and deepfakes, and emphasizes the need for continuous discovery, robust guardrails, and ongoing monitoring for credential exposure across all business-built applications.
Securing Retool and the Citizen Developer Attack Surface
2026 | BUSINESS-BUILT APPLICATION SECURITY RESEARCH
Securing Retool and the
Citizen Developer Attack Surface
Why business-built apps need the same security discipline as engineering-built ones
Further reading: retool security
Business Builders Are Outpacing Security Reviews
Independent research and a real-world breach point to the same gap:
27 39% 70%
cloud customers affected in a 2023 Retool of organizations already use low-code of enterprises projected to be using low-
breach that combined SMS phishing with platforms to empower citizen developers code/no-code tools by 2025
an AI deepfake voice call
Source: AI Incident Database, 2023; Forrester Developer Survey; Gartner
2 / 5
Where No-Code Security Actually Breaks Down
The risk isn't hypothetical — it shows up in both the platform and the people building on it:
Credentials embedded in app resources A documented Retool self-hosted vulnerability let any user with basic 'Use'
permissions discover resource authentication credentials via a standard API
endpoint.
Social engineering targets builders directly The 2023 Retool breach began with SMS phishing and an AI-generated deepfake
voice call used to obtain multi-factor codes, not a platform flaw.
Business builders lack security training Citizen developers building on no-code platforms are rarely trained on secure
coding, data classification, or access-control fundamentals.
Frameworks built around data security for no-code platforms extend structured governance to apps built outside of engineering, without slowing builders down.
3 / 5
From Unmanaged Builders to Governed No-Code Security
THE GAP WHAT'S NEEDED INSTEAD
Security teams often have no inventory of what business Continuous discovery of every app, workflow, and credential
builders have created across Retool and similar no-code tools built outside of engineering
App-level credentials and connections are provisioned once and Guardrails that apply consistent access-control and data-
rarely reviewed as apps change hands or scale handling standards to business-built apps
Citizen developers are held to the same trust level as Ongoing monitoring for credential exposure and
engineering teams without equivalent security training misconfiguration, not a one-time review
Source: CVE-2024-42056, NVD; Forrester Developer Survey
4 / 5
Building a Secure Citizen Developer Program
Inventory every business-built app
1
Know what's been built on Retool and other no-code tools, not just what engineering AT A GLANCE
deployed.
Verify how credentials are stored 39%
2
of organizations already empower citizen developers
Confirm app-level resource credentials aren't exposed beyond their intended scope. with low-code tools
Support citizen developers directly
3
Give business builders practical guardrails instead of assuming engineering-level
awareness. 70%
Monitor continuously of enterprises projected to use low-code/no-code
4 tools by 2025
Treat no-code security as an ongoing discipline, not a launch-day checklist.
5 / 5
Comments