Securing Retool and the Citizen Developer Attack Surface


Esti

Uploaded on Sep 20, 2026

This presentation focuses on the security challenges associated with the rapid adoption of low-code and no-code platforms like Retool by "citizen developers" (business builders). It highlights vulnerabilities, such as a 2023 breach affecting 27 cloud customers through social engineering and deepfakes, and emphasizes the need for continuous discovery, robust guardrails, and ongoing monitoring for credential exposure across all business-built applications.

Comments

                     

Securing Retool and the Citizen Developer Attack Surface

2026 | BUSINESS-BUILT APPLICATION SECURITY RESEARCH Securing Retool and the Citizen Developer Attack Surface Why business-built apps need the same security discipline as engineering-built ones Further reading: retool security Business Builders Are Outpacing Security Reviews Independent research and a real-world breach point to the same gap: 27 39% 70% cloud customers affected in a 2023 Retool of organizations already use low-code of enterprises projected to be using low- breach that combined SMS phishing with platforms to empower citizen developers code/no-code tools by 2025 an AI deepfake voice call Source: AI Incident Database, 2023; Forrester Developer Survey; Gartner 2 / 5 Where No-Code Security Actually Breaks Down The risk isn't hypothetical — it shows up in both the platform and the people building on it: Credentials embedded in app resources A documented Retool self-hosted vulnerability let any user with basic 'Use' permissions discover resource authentication credentials via a standard API endpoint. Social engineering targets builders directly The 2023 Retool breach began with SMS phishing and an AI-generated deepfake voice call used to obtain multi-factor codes, not a platform flaw. Business builders lack security training Citizen developers building on no-code platforms are rarely trained on secure coding, data classification, or access-control fundamentals. Frameworks built around data security for no-code platforms extend structured governance to apps built outside of engineering, without slowing builders down. 3 / 5 From Unmanaged Builders to Governed No-Code Security THE GAP WHAT'S NEEDED INSTEAD Security teams often have no inventory of what business Continuous discovery of every app, workflow, and credential builders have created across Retool and similar no-code tools built outside of engineering App-level credentials and connections are provisioned once and Guardrails that apply consistent access-control and data- rarely reviewed as apps change hands or scale handling standards to business-built apps Citizen developers are held to the same trust level as Ongoing monitoring for credential exposure and engineering teams without equivalent security training misconfiguration, not a one-time review Source: CVE-2024-42056, NVD; Forrester Developer Survey 4 / 5 Building a Secure Citizen Developer Program Inventory every business-built app 1 Know what's been built on Retool and other no-code tools, not just what engineering AT A GLANCE deployed. Verify how credentials are stored 39% 2 of organizations already empower citizen developers Confirm app-level resource credentials aren't exposed beyond their intended scope. with low-code tools Support citizen developers directly 3 Give business builders practical guardrails instead of assuming engineering-level awareness. 70% Monitor continuously of enterprises projected to use low-code/no-code 4 tools by 2025 Treat no-code security as an ongoing discipline, not a launch-day checklist. 5 / 5