Security checks

Before shipping

  1. Exclude environment secrets

    Keep .env files out of version control. Commit an example file with placeholders instead.

  2. Scan for secrets

    Run a secret scanner before committing and in CI. Include Git history in the scan.

  3. Rotate leaked keys

    Revoke and replace exposed credentials. Removing them from a file or Git history does not invalidate them.

  4. Keep private API keys on the server

    Check that browser JavaScript, public assets, and API responses contain no private keys.

  5. Pin dependency versions

    Use explicit dependency versions and commit the lockfile for reproducible installs.

Authentication & access

  1. Authenticate protected APIs

    Verify authentication on the server for every endpoint that exposes private data or actions.

  2. Test object ID swapping

    Try accessing another user’s records by changing IDs in URLs and requests. Confirm that access is denied.

  3. Test row-level security

    Where row-level security is used, verify read and write policies with different users, roles, and tenants.

  4. Use established authentication

    Use a maintained authentication library or provider instead of designing your own login and password handling.

  5. Revoke sessions

    Verify that sessions can be invalidated. Use appropriate token lifetimes and test logout and account revocation.

Authorization & input validation

  1. Check administrator permissions on the server

    Enforce privileged actions on the backend. Hiding an admin button is not an authorization check.

  2. Throttle authentication attempts

    Rate-limit login, signup, and password-reset endpoints to reduce brute force and abuse.

  3. Validate server input

    Validate types, lengths, allowed values, and request sizes on the server. Client validation can be bypassed.

  4. Parameterize SQL

    Use bound query parameters. Never concatenate untrusted input into SQL queries.

  5. Encode user content

    Escape output for its HTML, URL, or JavaScript context. Sanitize any user HTML that you intentionally allow.

Data, integrations & cost

  1. Restrict CORS

    Allow only the origins that need browser access. Keep authentication and authorization checks in place independently.

  2. Keep storage private

    Make buckets and uploaded objects private by default. Grant access only to the users who need it.

  3. Isolate uploads

    Validate file types and sizes, store uploads away from executable application code, and isolate file processing.

  4. Verify webhooks

    Verify the provider’s signature before processing a webhook. Reject invalid requests and handle replayed events safely.

  5. Cap AI spending

    Enforce usage budgets and a cutoff for paid AI calls. Alerts alone do not stop spending.

AI & agents

  1. Throttle AI calls

    Apply per-user or per-tenant request and concurrency limits to prevent credit draining.

  2. Treat model input as untrusted

    Account for prompt injection in user input, retrieved documents, and tool results. Keep permission checks outside the model.

  3. Constrain agent tools

    Limit tool access and permissions, especially SQL and shell execution. Require approval for sensitive actions.

  4. Verify AI-suggested packages

    Check package names, sources, and maintainers before installing dependencies suggested by a model.

  5. Review agent configuration

    Review agent instructions, skills, and MCP connections. Check what they can execute and which data they can access.

Production & recovery

  1. Scope production credentials

    Keep production credentials out of agent prompts and workspaces unless explicitly needed. Grant only the required access.

  2. Hide stack traces

    Return generic public errors. Keep detailed diagnostic information in restricted internal systems.

  3. Redact logs

    Remove credentials, tokens, and unnecessary personal data from application logs and traces.

  4. Keep audit trails

    Record who performed sensitive actions, what changed, and when. Restrict access to audit records.

  5. Test database restores

    Restore a backup in an isolated environment and verify the recovered data. A successful backup job is not a restore test.