Security
Security is a way of building and running systems. We describe the practices we actually use. We do not claim a certification we do not hold.
Secure development
Review, dependency updates and no secrets in the repository or the browser.
Encrypted transport
TLS for sites, APIs and administrative access.
Access control
Separate roles. Production access is limited to the people who operate it.
Secrets management
Keys live outside the code and outside the client.
Backups
Data that the business cannot recreate is backed up and the restore path is known.
Monitoring and logging
We want to see a failure before a customer describes it.
Least privilege
A service gets the access its job needs, not the access that was easiest to grant.
Isolation
Environments and services are separated so a fault stays local.
Discuss a project
Security is a way of building and running systems. We describe the practices we actually use. We do not claim a certification we do not hold.
Discuss a project