Skip to main content
Deepak Joshi — founder of Code HippiesCode Hippies

Free learning track

The pre-launch security pass

Nine checks derived from the OWASP Top 10, in the order they actually catch things.

Who this is for: Developers shipping to production without a security team behind them.

What you will be able to do

  • Validate on the server with a schema shared with the client
  • Protect mutating routes with CSRF tokens and rate limits
  • Set the six security headers that matter, and know what each stops
  • Prove no secret reached the client bundle

The material

Articles in this track

Written and published. No sign-up, no email gate.

The pre-launch security pass: nine checks, one afternoon

Most breaches are boring, and so is preventing them. The OWASP-derived checklist I run against every project before it goes to production.

Read it

Tell me what you're building.

Two minutes on the brief form gets you a real conversation: what the software has to do, what it will take, and an honest read on feasibility — whether or not we end up working together.