Free learning track
The pre-launch security pass
Nine checks derived from the OWASP Top 10, in the order they actually catch things.
Who this is for: Developers shipping to production without a security team behind them.
What you will be able to do
- Validate on the server with a schema shared with the client
- Protect mutating routes with CSRF tokens and rate limits
- Set the six security headers that matter, and know what each stops
- Prove no secret reached the client bundle
The material
Articles in this track
Written and published. No sign-up, no email gate.
The pre-launch security pass: nine checks, one afternoon
Most breaches are boring, and so is preventing them. The OWASP-derived checklist I run against every project before it goes to production.
Read itTell me what you're building.
Two minutes on the brief form gets you a real conversation: what the software has to do, what it will take, and an honest read on feasibility — whether or not we end up working together.