A week out — secrets and history
- ▢No API keys, tokens, or passwords in source — including the ones you committed and deleted. secrets-in-git-history
- ▢.env is gitignored, and .env.example contains placeholders, not real values. env-example-real-values
- ▢Nothing server-only is reachable from client bundles (check your browser tab's Network panel for key-shaped strings). secrets-in-client-bundle
- ▢CI workflow files can't leak secrets on pull requests. ci-secret-exposure
A week out — access and data
- ▢Every API route checks auth server-side — log out and confirm the important pages actually block you. authless-api-route
- ▢Admin routes verify roles on the server, not in the UI. client-side-role
- ▢Records are read by owner, not just by ID. idor
- ▢Database policies: RLS on, policies not permissive, no browser-direct queries. supabase-rls
- ▢Auth endpoints rate-limited; reset tokens unguessable. auth-rate-limit
Launch day — the public surface
- ▢HTTPS redirects; HSTS present. https-hsts
- ▢No debug endpoints, no served /.git, no stack traces with internal paths. debug-endpoint-live
- ▢CORS scoped to the origins you actually need. cors-wide-open
- ▢Cron/queue endpoints don't answer unauthenticated GETs. public-cron-endpoint
Launch day — the money paths
- ▢Payment amounts verified server-side against the catalog, never trusted from the client. payment-amount
- ▢Paid API endpoints check entitlement before serving. paid-endpoint-auth
- ▢Webhooks verify signatures against the raw body. webhook-signature
Run it, don't read it
The free scan runs the Critical half of this list in about two minutes. The Launch Pack ($179) adds the Rescue tech-debt scan, unlimited re-scans until every fix is verified green, and a badge you can put on the launch post — which is the honest version of "trust me, it's checked".