Skip to content

Security Excellence

Build secure systems by default, not as an afterthought.


Principles

  • Least privilege — access should be the minimum required
  • Shift left — security checks belong in development, not just production
  • Never hardcode credentials or store secrets in repositories

Secrets Management

  • Use a secret manager or vault solution
  • Environment variables should be injected at runtime, not baked into code
  • Rotate credentials regularly
  • Audit access to secrets

Dependency Management

  • Maintain an inventory of dependencies
  • Run automated vulnerability scanning in CI
  • Have a defined process for applying security updates

Access Control

  • Role-based access
  • Periodic access review
  • Separate access levels for dev, UAT, and production
  • Production data access limited to approved users only

CI/CD Security

  • Secrets managed via pipeline secret stores, never in config files
  • Dependency scanning on every build
  • Static analysis for common vulnerability patterns

Strong Signals

  • Security checks are automated in CI
  • Secrets are never in source control
  • Access is regularly reviewed and revoked when no longer needed
  • Vulnerabilities are addressed promptly

Weak Signals

  • Hardcoded credentials
  • Shared service accounts
  • No vulnerability scanning
  • Production access granted by default

→ Security and compliance → Architecture Decision Records → Documentation Standards

← Engineering Excellence