Skip to content

Security and Compliance

Security practices for data teams.

For the full framework, see → Security Excellence


Data Access and Governance

  • Mask sensitive fields in dev and UAT environments
  • Limit production data access to approved users only
  • Access should be role-based and reviewed periodically

Secrets Management

  • Never hardcode credentials in code or configuration files
  • Use pipeline secret stores or a vault solution
  • Rotate credentials regularly

Dependency Management

  • Run automated vulnerability scanning in CI
  • Review and update dependencies regularly
  • Track known vulnerabilities and have a defined response process

← Engineering Excellence