started · updated
Low-code platforms drive innovation while increasing shadow IT security risks
The rapid adoption of low-code and no-code platforms is presenting both operational opportunities and significant security challenges for organizations. Companies like Forceworks are utilizing low-code models to offer unlimited deployment and customization for fixed costs, pushing the technical boundaries of what can be achieved through abstraction layers.
However, the democratization of application development has led to the rise of shadow IT. Because these tools allow non-technical users to bypass traditional Software Development Lifecycles (SDLC), applications are often deployed without authentication, security reviews, or access controls. Recent incidents involving platforms such as Lovable, Replit, and Vercel have highlighted risks including exposed API keys, unencrypted data repositories, and public exposure of sensitive customer information. A 2023 study noted that out of 380,000 publicly accessible applications on these platforms, 22% contained exposed credentials or proprietary data.
Entities
Forceworks · Lovable · Replit · Vercel