How do I check my app is secure before launch?
Check what attackers try first: who can see whose data, logins, open keys and databases, injection, payments, rate limits, HTTPS and old dependencies.
My website has been hacked. What do I do?
Take it offline, change every password, find how they got in, restore a clean backup, update, and ask Google to review. Then check if customer data was taken.
I leaked an API key. What do I do?
Revoke it and create a new one now, before anything else. Deleting it from the code doesn't help: it's still in the history. Then check what it was used for.
Do I have to report a data breach? (Australia)
If the Privacy Act covers you and the breach is likely to cause serious harm, yes: tell the OAIC and those affected. Suspected breaches: assess within 30 days.
My database is open to the internet. How do I close it?
Turn off public access, let only your app's servers through the firewall, and require a strong login. Then check the logs: it may already have been copied.
Supabase RLS is disabled. Is my data public?
A table in an exposed schema without Row Level Security is readable and writable through your public key, which is in your app. Turn RLS on for every table.
Is my Firebase database open to anyone?
If it was set up in test mode and never locked down, possibly. The API key being public is normal: the security rules are what protect the data. How to check.
Are my app's uploaded files public? (S3)
New S3 buckets are private by default, but a policy can open them. Turn on Block Public Access, and serve private files through short-lived signed links.
Are my environment variables public?
Anything your frontend can read, every visitor can read. Settings prefixed VITE_ or NEXT_PUBLIC_ end up in the browser. Secrets belong on the server.
Is it safe to keep login tokens (JWTs) in localStorage?
It's a risk: any script on your page can read localStorage, so one injected script can steal every logged-in session. HttpOnly cookies can't be read by scripts.
My project shows dozens of security warnings (npm audit). Should I worry?
Some, not all. npm audit lists known holes in the packages you use; many are in build tools that never reach users. Fix what ships, and test before forcing.
How much does a penetration test cost in Australia?
Australian testing firms publish indicative prices from a few thousand dollars for a small web app to tens of thousands for bigger scopes. What sets the price.
More of the dictionary
Search everything →Not sure what's wrong with yours?
Tell us what you built. We'll go through it and tell you in writing what's broken, what it takes, and whether it can be saved. Free.
Submit your project