Shipping software with AI copilots increases velocity tenfold. But shipping insecure code at 10x speed only accelerates the timeline to a catastrophic security breach.
Before you merge code to main or trigger your production Vercel/AWS deployment, run through this 25-point non-negotiable verification checklist.
Category 1: Secrets & Environment Hygiene
- [ ] 1. No Live Secrets in Commits: Verify no
sk_live_,ghp_, or private keys exist in git history (git log -S "sk_live"). - [ ] 2. No Public Prefix Leaks: Inspect
.envto ensure no secrets haveNEXT_PUBLIC_,VITE_, orEXPO_PUBLIC_prefixes. - [ ] 3. `.gitignore` Verification: Confirm
.env*(except.env.example) is excluded from source control. - [ ] 4. Build Output Audit: Search compiled production chunks in
.next/staticfor accidental key leaks. - [ ] 5. Restrict API Keys: Ensure cloud provider keys (OpenAI, AWS, Resend) are restricted by IP or permission boundaries.
Category 2: Authentication & Session Boundaries
- [ ] 6. Server Action Protection: Verify every function marked
'use server'asserts session credentials. - [ ] 7. HttpOnly Cookie Storage: Ensure JWT session tokens are stored in
httpOnly, secure, sameSite=laxcookies. - [ ] 8. CSRF Origin Verification: Confirm mutating API endpoints reject requests with mismatched
Originheaders. - [ ] 9. Password Hashing: Ensure passwords use bcrypt with cost factor >= 12 or Argon2id.
- [ ] 10. Rate Limiting: Enforce token-bucket limits on
/login,/register, and password reset endpoints.
Category 3: Database & Multi-Tenancy (RLS)
- [ ] 11. RLS Enabled on All Tables: Confirm every Postgres table has
ENABLE ROW LEVEL SECURITYdeclared. - [ ] 12. Multi-Tenant Scoping: Verify every RLS policy checks
tenant_id = auth.user_tenant(). - [ ] 13. No `service_role` Key on Client: Verify the Supabase service role key is strictly confined to server workers.
- [ ] 14. Parameterized SQL: Audit for
$queryRawUnsafeor raw string concatenation in database queries. - [ ] 15. Atomic Balance Deductions: Confirm financial balance updates execute within transactions with decrement locks.
Category 4: Payments & External Webhooks
- [ ] 16. Webhook Signature Verification: Ensure Stripe/GitHub webhooks call
constructEventwith the raw request body. - [ ] 17. Immutable Server Prices: Verify client requests cannot dictate Stripe Price IDs or amounts.
- [ ] 18. Webhook Idempotency: Confirm duplicate webhook deliveries do not credit customer accounts multiple times.
- [ ] 19. Secure Webhook URLs: Ensure all external webhook receiver endpoints use HTTPS.
Category 5: Infrastructure & Compliance Readiness
- [ ] 20. Security Headers Deployed: Verify responses include
Content-Security-Policy,X-Frame-Options: DENY, andHSTS. - [ ] 21. SSRF Protection: Ensure URL fetchers validate IP addresses and block loopback/metadata endpoints (
169.254.169.254). - [ ] 22. Dependency CVE Audit: Run
npm auditor verify zero critical CVEs via OSV.dev. - [ ] 23. GDPR Right to Erasure: Confirm an automated hard-delete endpoint exists for European users.
- [ ] 24. AI Logging & Monitoring: Ensure high-risk AI prompt/completion events are logged with timestamps.
- [ ] 25. Automated CI Scan: Run Bryxe Shield in your GitHub Actions pipeline before every merge.
Automate this entire checklist with Bryxe Shield in under 60 seconds at bryxe.app.
