Glossary of AI app security and QA terms
The words testers, buyers and AI tools use, each defined in a sentence and linked to the page that explains it properly.
This glossary defines the security and QA terms that come up when building with AI tools and testing what they produce. Each term links to a longer answer on this site.
- Access control
- Rules deciding what each user may see and do. The most common failure in AI-built apps. More.
- Agent
- An AI system that can call tools or take actions, not just answer. More.
- Anon key
- Supabase's public API key. Safe to expose; row level security decides what it can do. More.
- Authentication
- Proving who a user is: login, sessions, reset. More.
- Deciding what an authenticated user may do. More.
- Black box testing
- Testing the running app without the source code. More.
- CVE
- A public identifier for a disclosed vulnerability. More.
- Excessive agency
- An AI agent with more permissions or autonomy than its task needs. More.
- Fuzzing
- Sending large volumes of malformed input to find crashes and mishandling. More.
- IDOR
- Insecure direct object reference: reaching another user's record by changing its ID. More.
- Indirect prompt injection
- Instructions hidden in content a model reads, such as a web page or document. More.
- Jailbreak
- A prompt that gets a model past its policies. More.
- LLM
- Large language model, the kind of model behind chat assistants. More.
- OWASP
- The Open Worldwide Application Security Project, which publishes the Top 10 lists. More.
- Penetration test
- A human-led attempt to break a system within an agreed scope. More.
- Prompt injection
- Input that changes what a model does against your instructions. More.
- QA testing
- Checking the app works correctly for people using it in good faith. More.
- RAG
- Retrieval-augmented generation: the model answers from documents fetched for each question. More.
- Rate limiting
- Capping how often a user or IP can call an endpoint. More.
- Red teaming
- Open-ended adversarial testing, here of an AI feature or agent. More.
- Retest
- Verification by the tester that fixes closed the findings. More.
- Row level security
- Database policies deciding which rows each user may read or write. More.
- Secret key
- A credential that must never reach the browser, such as a payment or service role key. More.
- Security rules
- Firebase's equivalent of row level security. More.
- Service role key
- Supabase's admin key. Bypasses row level security; server-only. More.
- System prompt
- The hidden instructions your app gives the model. Assume users can read it. More.
- Tenant
- A customer organization in a shared multi-customer app. More.
- Vibe coding
- Building software mainly by describing it to an AI tool and accepting its code. More.
- Webhook
- A server-to-server notification, such as a payment provider confirming a charge. More.
Common questions
What is the difference between authentication and authorization?
Authentication proves who you are. Authorization decides what you may do. AI-built apps usually get the first right and the second wrong.