Blog category

Security & Compliance

Security and compliance for teams that outsource development: how code, data and IP are protected, and what regulated products need. Regulated topics are reviewed before they are promoted.

21 articles

9 min read· October 2026

Building a Patient-Portal SaaS: Access, Privacy by Design, QA

How to build a patient-portal SaaS where access control, audit logging and privacy by design go into the first feature, not a later sprint, and a QA plan to prove they hold. Covers relationship-based access, least privilege, data minimisation, consent, and what to build versus rent. Engineering guidance only: compliance is for your adviser.

Read article
8 min read· October 2026

A Commission and Split-Payment System for a Brokerage

A commission system that loses a cent in rounding, or lets an agent see another agent’s pay, is the one bug a brokerage will not forgive. The data model for splits that always sum to the gross commission, money as integer minor units, an append-only ledger, strict access control, and the tests that prove every split balances. General guidance; confirm tax and payout rules with your adviser.

Read article
9 min read· October 2026

Owner Statements and Trust Accounting in Property SaaS

Holding other people’s rent is where property SaaS stops being a CRUD app. Owner statements and trust (client-money) accounting need a double-entry ledger, segregated balances, bank reconciliation and an audit trail that never rewrites history. The data model, the balance guarantees, and the tests that prove the books balance. General information only; confirm trust-accounting rules with your adviser.

Read article
12 min read· October 2026

Testing Login, Roles and Data Access in an AI-Built App

A test plan for login, roles and data access in your own AI-built app: write a role matrix, test every cell with two accounts per role, check that users cannot edit their own role, that sign-up is as closed as you think, that admin checks run on the server, and that sessions end when they should.

Read article
11 min read· October 2026

OWASP Top 10 Testing Checklist for Web Apps (2025 Edition)

A practical checklist that turns each of the ten OWASP Top 10:2025 categories into tests you can run on a web app: what to try, which tool helps, and what a pass looks like. With a cross-account test you can drop into CI, and a plain line on when you need a certified pentest instead.

Read article
9 min read· October 2026

Penetration Testing vs Vulnerability Scanning vs Security Testing

A vulnerability scan is automated and finds known issues. Application security testing is a person testing your app’s own rules against OWASP guidance. A penetration test is an independent, scoped attack with a report auditors accept. What each finds, what each proves, and which one your situation needs.

Read article
12 min read· October 2026

Adding SSO (SAML and OIDC) to a B2B SaaS: Build or Buy

Enterprise buyers expect to sign in through their own identity provider. How SAML and OIDC SSO fit a multi-tenant SaaS, what WorkOS and Auth0 charge per connection, what a self-built SAML integration must validate, and the tests that catch account-takeover bugs before a customer does.

Read article
13 min read· October 2026

Lovable App Exposing API Keys or service_role? Fix It in 30 Minutes

A 30-minute plan for a Lovable app that exposes API keys: which keys are meant to be public and which are not, how to find leaked ones in the bundle and git history, the order to rotate and redeploy, an Edge Function that keeps an OpenAI key off the browser, and how to stop it happening again.

Read article
13 min read· October 2026

Vibe-Coded App Security Checklist: 20 Checks Before Launch

Twenty pass/fail security checks for an app built with Lovable, Bolt, Cursor or another AI tool, grouped into data access, secrets, authentication, input handling, platform hardening and recovery. Each has a test you can run in minutes, with the security headers and rate limits this website runs as a worked example.

Read article
11 min read· October 2026

Users Can See Another Tenant's Data: Find and Fix a Tenant Leak

What to do when one customer can see another customer's data in a multi-tenant app: contain it in the first hour, the eight usual causes, how to trace the leaking path, the fix in code and in the database, and the IDOR tests that prove it stays fixed.

Read article
13 min read· October 2026

Designing SaaS Authorization: Roles, Permissions and Tenant Scope

SaaS authorization answers three questions on every request: which tenant, which permissions, and may this user touch this record. How to model permission codes and per-tenant roles, enforce separation of duties in PostgreSQL, layer row-level security underneath, and test every role, with Sundor Skin's 88 permission codes as the worked example.

Read article
10 min read· October 2026

Who Owns AI-Generated Code? What Founders Should Put in Contracts

Who owns code produced with AI tools: what the terms of OpenAI, Anthropic, GitHub Copilot and Lovable say about output, what the US Copyright Office says about human authorship, and the contract points founders should raise with their lawyer and their developers. General information, not legal advice.

Read article
12 min read· October 2026

Your First Enterprise Security Questionnaire, With No SOC 2

You can answer an enterprise security questionnaire without SOC 2 if every answer is true. What CAIQ, SIG and custom questionnaires contain, what a SOC 2 report actually is, how to word Yes, Partial, No and Inherited answers, the document pack to prepare, and when you really need the audit.

Read article
12 min read· October 2026

Designing a SaaS Audit Log Customers Trust: Hash-Chained and Queryable

A SaaS audit log earns trust when it is written in the same transaction as each change, cannot be edited by the application, and proves it has not been altered. The events and fields to record, a PostgreSQL schema partitioned by month, a per-tenant hash chain with the SQL to write and verify it, and how Sundor Skin runs one in production.

Read article
12 min read· October 2026

Quebec Law 25 Transfer Assessments: What Your Offshore Vendor Should Provide

General information for Québec businesses hiring a software vendor outside the province: the privacy impact assessment Law 25 requires before personal information is communicated outside Québec, the written agreement that must follow, the three contract terms the CAI lists for service providers, and a checklist of what the vendor should hand over: a data map, a sub-processor list, a description of security measures, incident terms and an exit plan.

Read article
15 min read· October 2026

Car Dealership Software Security: Lessons From the DMS Outage

In June 2024 a cyber incident at CDK Global, a DMS vendor serving about 15,000 North American dealers, pushed dealerships onto manual processes for roughly two weeks. This guide covers what dealers control: an offline fallback runbook, scoped and expiring API tokens, audit logs, restore drills, MFA and the FTC Safeguards Rule, with a checklist table and a SQL schema.

Read article
15 min read· October 2026

What HIPAA-Compliant Software Development Actually Requires

A plain engineering guide to what "HIPAA-compliant software" means: the Security Rule safeguards, Business Associate Agreements, minimum necessary access, audit controls, encryption, breach notification and cloud BAAs, with a checklist and code.

Read article
13 min read· October 2026

SOC 2 for Early-Stage Startups: What Engineering Has to Change

A first SOC 2 typically costs $10,000 to $80,000 or more all-in, and a Type II needs a 3 to 12 month observation period. What SOC 2 is, Type I vs Type II, the engineering controls auditors test (access reviews, logging, change management, backups, vendors), and when a startup does not need it yet.

Read article
13 min read· September 2026

"RLS Disabled in Public" in Supabase: What It Means and How to Fix It

What Supabase's "RLS disabled in public" error means, why it is the same flaw behind CVE-2025-48757, the SQL to find every exposed table, policies for user-owned, public and server-only tables, and three ways to prove the fix works, including a pgTAP test.

Read article
12 min read· September 2026

SaaS Security Best Practices: How to Pass a Customer's Security Review

What a customer's security review actually asks, and the evidence that answers it: database-enforced tenant isolation, permission-based roles, rate-limited login, security headers, dependency hygiene and an honest line on certifications. With the real controls from platforms RAITHub built.

Read article
6 min read· April 2026

API Security Checklist: 10 Things to Lock Down Before Launch

Rate limiting, input validation, authentication — a practical security checklist for production APIs based on OWASP guidelines and real-world incidents.

Read article