It Should Be Easy...But It Isn't

AI will build you an App in an afternoon. It’ll leak your data just as fast.

The thing that makes AI coding tools so impressive is the same thing that makes them dangerous. They do whatever you point them at. No judgement. No pause. No “are you sure you want to plug that into your live customer database?”

Tools like Claude Code are very good. We use this kind of thing every day. It’s how we build client web apps and custom automations far faster than old school dev work. So I’m not trying to talk you out of AI. I’m trying to talk you out of assuming that “it works” and “it’s safe” are the same sentence. They aren’t. And the gap between them is where a lot of Kiwi businesses are about to get burned.

What these tools actually do

Let’s be clear about what we’re dealing with, because the demos make it look like magic and it isn’t.

An AI coding agent doesn’t sit politely on the side of the screen suggesting tidy little snippets. It gets into your actual project. It could read your files, your config, your keys. It can run commands, talk to databases, push changes live. If you let it run in YOLO mode it’ll churn through tasks much faster than a human running things.

It’s also why it’ll happily do something catastrophic if nobody set the boundaries. It can’t tell the difference between a test file and your entire customer list. That isn’t its job. It’s yours, or it’s the job of whoever you trusted to drive.

The breach probably won’t be dramatic, at the time.

Forget the sci-fi version where the AI goes rogue and turns evil. That isn’t how this plays out.

It plays out like this. An API key gets committed into a public repo. A live production database gets wired up to a tool that never needed to see it. Someone pastes a spreadsheet full of customer details into a chatbot to “just quickly sort out a formula.” A throwaway script runs with full admin rights because setting up a sandbox felt like faff.

None of that is the AI misbehaving. Every one of those is a person, moving fast, skipping the foundational security decisions that the USER needs to make sure it has up front. That’s rather hard to do if you don’t come from a dev background.

“Not just anyone can use this safely.” Here’s what I mean.

I know how that sounds. A bit gatekeepy. Like I’m protecting the guild. I’m not…but also, I kinda want a cool secret nerd guild. (Please?)

The AI is the easy part now. Anyone can get it to build something. The hard part, the part that takes actual experience, is everything wrapped around it. When we put these tools to work on a client’s build, the boring scaffolding is where the real work lives:

  • We keep secrets away from the tool entirely. Passwords, keys and tokens live somewhere protected, never sitting in the code the AI is reading or in the prompt someone typed in a hurry.
  • We give it the least access it needs for the job in front of it, not a permanent open door to your live data just because that was the convenient option. This one matters more than people think. An AI’s guardrails are self-imposed, so it can ignore, forget, or talk itself past an instruction mid-task. You don’t rely on it behaving, you make sure it can’t reach what it shouldn’t in the first place.
  • We build and test somewhere separate before anything touches your live system. A mistake stays a mistake instead of becoming a Monday-morning phone call.
  • You stay in control of where it runs. The app and the code are yours. Self-hosted, hybrid, or in the cloud, including us running it for you on AWS or handing the whole thing over to your team. We help you pick what suits, so you’re not renting space on someone else’s platform forever unless you want to.
  • A human signs off on everything that ships. The AI suggests; a person who understands your business decides.

None of that is clever. It just gets done, properly, every time, by someone who’s been bitten before.

The risk you can’t see

Here’s the part that should give you pause. You don’t need to have commissioned a single line of AI code to be exposed.

Your team is already using this stuff. Pasting documents, client lists, contracts and half your financials into whatever AI tab is open, because it’s useful and nobody ever told them where the line was…or how set up their AI tool to ensure it doesn’t use that data literally anywhere else, or leaked from that amazing new app that also happens to be a massive security leak.

The answer isn’t to ban it. That ship has sailed, and the tools are too good. The answer is to give your people a safe way to get the same benefit, so the sensitive stuff never leaves a place you control. That’s a decision worth making on purpose. Right now most businesses are making it by accident.

And yes, this is a legal problem too

If you hold customer data, and you do, you’ve already got obligations under the Privacy Act. The second you touch a European customer, GDPR is in the room as well. AI doesn’t lower that bar. It raises the stakes, because it moves faster than you can catch a mistake.

A notifiable privacy breach isn’t a “whoops.” It’s telling every affected customer. It’s the cost of cleaning it up. It’s the kind of reputational hit a small business struggles to walk back. The shortcut that saved you an afternoon can quietly cost you the thing you’ve spent years building.

So what do you do?

You don’t need to become a security expert, but you really should consult one.

Before you let anyone (staff, contractor, agency) point AI at your systems, ask them three things. How do you keep our passwords and keys away from the tool? What’s our data connected to while you work? Who checks the security before it goes live? Clear, confident answers mean you’re probably in good hands. Vague ones, or some version of “oh, the AI handles all that,” mean stop.

AI can build what your business needs, faster and cheaper than you’d think. It’s wicked powerful. But the person holding it knows what they’re doing when it’s pointed at the stuff you can’t afford to lose.

If you’d rather have the speed without betting the business on it, that’s what we’re here for.

Testimonials

Honestly, from what I can see [of my new website] at a quick glance, it looks absolutely amazing!! So much better than before!! I really love the new layout, as well as the headings and descriptions. Everything feels so much more user friendly and easier to navigate. I can’t thank you enough for all your help with this, it is fabulous!!

Lee Clark, Child Preschool Education

The Project Seven team are amazing! They took the load off and enabled us to focus on what we are good at; running the business. They are doing everything from book keeping, answering the phone when we can’t, invoicing to social media posting for us. It makes our “to do list” way more manageable. Thank you of everything you are doing for us!!

Ida Larsson, White Lynx Photography

The Project Seven team have been wonderful over the past few years assisting my company with various administrative services. I could not have done it without them. I highly recommend Project Seven as an exceptionally professional company with the ability to adapt to your individual company’s needs.

Mark Hurdley

The team at Project Seven recently provided their support and expertise on the production of a corporate publication. The attention to detail, creativity and professionalism are just some of the components that really made me go “WOW!” What I enjoyed the most was how they were able to take this work off my plate, and just get it done and get it done well.

Pamela Slater

I have been working with Project Seven for a few months now, and I am so happy with the work they are doing. They have taken over my sales calls, VIP group and social media, which has given back so much more of my time. I can’t recommend Project Seven enough! If you have been thinking about outsourcing some work, you won’t be disappointed!

Jade Crowe