← All articlesSecurity · 6 min read
A practical security checklist before your app goes live
Priya Krishnan, CTO & Cloud Lead ·
Most launch-week incidents are not sophisticated attacks. They are default settings nobody changed. This is the checklist we run on every release, including our own.
Identity and access
- MFA on every cloud, registrar and code-hosting account.
- Service accounts with least privilege; no shared root credentials.
- Secrets in a manager, not in the repository or CI logs.
Application
- Security headers: CSP, HSTS, frame-ancestors, referrer policy.
- Rate limiting on authentication, forms and public APIs.
- Input validation on the server, even when the client already validates.
- Dependency audit with no known critical vulnerabilities.
Operations
- Backups tested by restoring them, not by checking that they exist.
- Alerting on error rate and latency, routed to a person.
- A written incident contact list and a status page.
- Logs that do not contain personal data or tokens.
None of these take more than a day. Together they remove most of the findings we would otherwise write up after launch.