Skip to content
Pixelspective

Security 5 min read

Five security checks before your business app goes live

Row-level security, fail-closed permissions, hashed share links, two-factor sign-in and role-by-role testing: the checks we run on every system before launch.

The systems that run a business hold its most sensitive data: payroll, pupil records, invoices, customer debts. Most breaches in small and mid-sized organisations aren't sophisticated attacks. They're an endpoint someone forgot to protect, or a screen that hides data the API still returns. These are the five checks we run before anything goes live.

1. Enforce access in the database

Hiding a button isn't access control. We use Postgres row-level security so the database itself decides which rows each person can read or change. If one branch's staff try to load another branch's records — through the app or directly through the API — the database returns nothing.

2. Make permissions fail closed

On a school platform we added a test that walks every API route and fails the build if a route has no permission rule. At runtime, anything without a rule is refused. A new feature can't accidentally ship open.

3. Treat share links like passwords

Links that let customers open a receipt or document without logging in are convenient and risky. Make them long and random, store only a hash of each one, let them expire, and make sure a link can reach only the one thing it was made for.

4. Require two-factor sign-in for staff

Passwords get reused and phished. An authenticator app on every staff account blocks most account takeovers. Plan the recovery process — for the day someone loses their phone — before you switch it on, not after.

5. Test every role, end to end

Before launch, walk every role — cashier, manager, admin, and someone with no account at all — through a realistic week of work. Unit tests check pieces in isolation; a role-by-role walkthrough catches the permission gaps between them while they're still an afternoon's fix rather than an incident.

Hiding a button isn't access control.

None of these checks are exotic. They're simply easy to skip when a deadline is close. If you're about to launch, or you inherited a system and aren't sure how it's protected, a short security review is a cheap insurance policy.

Want a second opinion?

Tell us what you're working on. We'll reply with honest, practical advice — whether or not you hire us.

Every brief is read by Mark Okutu, founder and lead developer, and he replies to each one personally.

Prefer email?

pixelspective1@gmail.com

Or message us on WhatsApp: 024 950 1063

What do you need?
We reply within two working days.