Skip to content
NovaAppsSolutions
← All articlesSecurity · 6 min read

A practical security checklist before your app goes live

Priya Krishnan, CTO & Cloud Lead ·

Most launch-week incidents are not sophisticated attacks. They are default settings nobody changed. This is the checklist we run on every release, including our own.

Identity and access

  • MFA on every cloud, registrar and code-hosting account.
  • Service accounts with least privilege; no shared root credentials.
  • Secrets in a manager, not in the repository or CI logs.

Application

  • Security headers: CSP, HSTS, frame-ancestors, referrer policy.
  • Rate limiting on authentication, forms and public APIs.
  • Input validation on the server, even when the client already validates.
  • Dependency audit with no known critical vulnerabilities.

Operations

  • Backups tested by restoring them, not by checking that they exist.
  • Alerting on error rate and latency, routed to a person.
  • A written incident contact list and a status page.
  • Logs that do not contain personal data or tokens.

None of these take more than a day. Together they remove most of the findings we would otherwise write up after launch.

Have a project in mind? Let's build it together.

Tell us about your goals and we'll come back within one business day with a plan and an estimate.

Get a Free Quote