Application security: access, data and responsibilities
Security depends on users, data and actions. It is not a single plugin or a general promise. Requirements belong in scope and pre-launch verification.
Who can view and change data
Define roles and least-necessary access. The server must verify permissions for relevant operations, rather than merely hiding buttons. Test cross-account access.
Which data is actually needed
Collect information required for the workflow and define retention and deletion. Development can use fictional data. Production and backup access should be limited and documented.
Dependencies and access keys
Inventory libraries and external services. Keep secrets out of public content with controlled access. APIs and forms should validate data and handle errors without revealing sensitive detail.
Who handles an incident
Define monitoring, recovery and responsibilities. Sensitive data or regulated processes need additional requirements and verification agreed with responsible people before implementation.