Secure Vibe Coding and the 99%
Lovable CISO Igor Andriushchenko on soft guardrails vs. hard boundaries, securing vibe coding for non-developers, and building a security program at a 10x company. I sit down with Igor Andriushchenko, Head of Security and CISO at Lovable, the AI development platform behind one of the fastest growth stories in the space. Igor joined as the first security hire when the company was around 40 people. A year later he is running a 20+ person team covering product security, GRC, IT, and platform safety for a company with 400 laptops in MDM and no sign of slowing down. We get into what it actually takes to secure AI-native development, both inside a hypergrowth startup and on a platform where most of the people shipping software are not developers and definitely not security practitioners. In this episode: Building a security program for the company you will be in 12 months instead of the one you are in today Soft guardrails versus hard guardrails, and how to decide which one a problem deserves Why hard blocks push AI-assisted workflows into the shadows Rooting guardrail decisions in business goals, risks, and threats rather than tool defaults Democratized development without democratized security, and what a platform owes the 99% Lovable's auto-fix toggle, per-app threat models, and the goal of an app with no security tab at all Whether models will ever produce secure code by default, and why defense in depth still carries the load Governing the reality that every employee vibe coding an app looks a lot like a new vendor GRC engineering as the way to measure control efficiency layer by layer against AI-powered attackers CRA, NIS2, and the EU AI Act landing on citizen developers who never thought of themselves as software manufacturers Chapters: 0:00 Intro 0:23 Igor's background from DevOps to CISO 3:54 Scaling security at a 10x company 6:07 Reinventing the team when growth breaks it 08:26 Soft guardrails versus hard blocks 14:05 Tying guardrails to business risk 17:32 Democratized development, undemocratized security 18:52 Shared responsibility on an AI dev platform 21:16 Auto-fix, per-app threat models, and no security tab 25:21 Will models produce secure code by default? 29:56 Every employee vibe coding is a new vendor 30:57 Enterprise controls, publishing gates, and PII scanning 36:39 AI-powered attackers and why good enough changed 40:43 GRC engineering and measuring control efficiency 46:19 CRA, NIS2, and the citizen developer 52:41 Trust centers for builder apps 54:08 Closing thoughts on the vibe coding community Guest links: Igor on LinkedIn: https://www.linkedin.com/in/igor-andriushchenko Lovable: https://lovable.dev Resilient Cyber: Newsletter and episode archive: https://www.resilientcyber.io Subscribe for more conversations with security practitioners and leaders.



