VibeCoded

Glossary of AI app security and QA terms

The words testers, buyers and AI tools use, each defined in a sentence and linked to the page that explains it properly.

Last reviewed 2026-09-30Written by Jacob Masse, TrazTech Inc.

This glossary defines the security and QA terms that come up when building with AI tools and testing what they produce. Each term links to a longer answer on this site.

Access control
Rules deciding what each user may see and do. The most common failure in AI-built apps. More.
Agent
An AI system that can call tools or take actions, not just answer. More.
Anon key
Supabase's public API key. Safe to expose; row level security decides what it can do. More.
Authentication
Proving who a user is: login, sessions, reset. More.
Authorization
Deciding what an authenticated user may do. More.
Black box testing
Testing the running app without the source code. More.
CVE
A public identifier for a disclosed vulnerability. More.
Excessive agency
An AI agent with more permissions or autonomy than its task needs. More.
Fuzzing
Sending large volumes of malformed input to find crashes and mishandling. More.
IDOR
Insecure direct object reference: reaching another user's record by changing its ID. More.
Indirect prompt injection
Instructions hidden in content a model reads, such as a web page or document. More.
Jailbreak
A prompt that gets a model past its policies. More.
LLM
Large language model, the kind of model behind chat assistants. More.
OWASP
The Open Worldwide Application Security Project, which publishes the Top 10 lists. More.
Penetration test
A human-led attempt to break a system within an agreed scope. More.
Prompt injection
Input that changes what a model does against your instructions. More.
QA testing
Checking the app works correctly for people using it in good faith. More.
RAG
Retrieval-augmented generation: the model answers from documents fetched for each question. More.
Rate limiting
Capping how often a user or IP can call an endpoint. More.
Red teaming
Open-ended adversarial testing, here of an AI feature or agent. More.
Retest
Verification by the tester that fixes closed the findings. More.
Row level security
Database policies deciding which rows each user may read or write. More.
Secret key
A credential that must never reach the browser, such as a payment or service role key. More.
Security rules
Firebase's equivalent of row level security. More.
Service role key
Supabase's admin key. Bypasses row level security; server-only. More.
System prompt
The hidden instructions your app gives the model. Assume users can read it. More.
Tenant
A customer organization in a shared multi-customer app. More.
Vibe coding
Building software mainly by describing it to an AI tool and accepting its code. More.
Webhook
A server-to-server notification, such as a payment provider confirming a charge. More.

Common questions

What is the difference between authentication and authorization?

Authentication proves who you are. Authorization decides what you may do. AI-built apps usually get the first right and the second wrong.