Security 5 min read
Five security checks before your business app goes live
Row-level security, fail-closed permissions, hashed share links, two-factor sign-in and role-by-role testing: the checks we run on every system before launch.

The systems that run a business hold its most sensitive data: payroll, pupil records, invoices, customer debts. Most breaches in small and mid-sized organisations aren't sophisticated attacks. They're an endpoint someone forgot to protect, or a screen that hides data the API still returns. These are the five checks we run before anything goes live.
1. Enforce access in the database
Hiding a button isn't access control. We use Postgres row-level security so the database itself decides which rows each person can read or change. If one branch's staff try to load another branch's records — through the app or directly through the API — the database returns nothing.
2. Make permissions fail closed
On a school platform we added a test that walks every API route and fails the build if a route has no permission rule. At runtime, anything without a rule is refused. A new feature can't accidentally ship open.
3. Treat share links like passwords
Links that let customers open a receipt or document without logging in are convenient and risky. Make them long and random, store only a hash of each one, let them expire, and make sure a link can reach only the one thing it was made for.
4. Require two-factor sign-in for staff
Passwords get reused and phished. An authenticator app on every staff account blocks most account takeovers. Plan the recovery process — for the day someone loses their phone — before you switch it on, not after.
5. Test every role, end to end
Before launch, walk every role — cashier, manager, admin, and someone with no account at all — through a realistic week of work. Unit tests check pieces in isolation; a role-by-role walkthrough catches the permission gaps between them while they're still an afternoon's fix rather than an incident.
Hiding a button isn't access control.
None of these checks are exotic. They're simply easy to skip when a deadline is close. If you're about to launch, or you inherited a system and aren't sure how it's protected, a short security review is a cheap insurance policy.

