Skip to main content
Back to Blog
BEFOREAFTER
Foundations11 min read

Security Fundamentals: Building Secure Foundations

By Fundare Team

Security Fundamentals: Building Secure Foundations

Security isn't something you add later—it's a foundation you build from day one. Every product needs basic security practices, regardless of size.

The Security Mindset

Security is about:

  • Protecting user data: Their information is your responsibility
  • Preventing breaches: One breach can destroy trust
  • Compliance: Many industries have legal requirements
  • Business continuity: Security incidents disrupt operations
  • Authentication and Authorization

    Authentication (Who Are You?)

    Verify users are who they claim to be:

    **Best Practices**:

  • Strong passwords: Enforce complexity requirements
  • Password hashing: Use bcrypt, Argon2, or similar (never plain text)
  • Multi-factor authentication (MFA): Add second factor for sensitive operations
  • Session management: Secure session tokens, proper expiration
  • **Common Mistakes**:

  • Storing passwords in plain text
  • Weak password requirements
  • No rate limiting on login attempts
  • Session tokens that never expire
  • Authorization (What Can You Do?)

    Control what authenticated users can access:

    **Principles**:

  • Least privilege: Users get minimum access needed
  • Role-based access control (RBAC): Assign permissions by role
  • Resource-level permissions: Check permissions for each resource
  • **Implementation**:

    ```

    // Bad: Trust client

    if (user.isAdmin) {

    deleteUser(userId);

    }

    // Good: Verify on server

    if (user.isAdmin && canUserDelete(user, userId)) {

    deleteUser(userId);

    }

    ```

    Input Validation and Sanitization

    Never trust user input:

    Validation

    Check that input meets requirements:

  • Type checking: Ensure strings are strings, numbers are numbers
  • Length limits: Prevent buffer overflows
  • Format validation: Email addresses, phone numbers, etc.
  • Business rules: Values make sense in context
  • Sanitization

    Clean input to prevent injection attacks:

  • SQL injection: Use parameterized queries
  • XSS (Cross-Site Scripting): Escape HTML, use CSP headers
  • Command injection: Don't execute user input as commands
  • **Example**:

    ```

    // Bad: SQL injection risk

    query = "SELECT * FROM users WHERE id = " + userId;

    // Good: Parameterized query

    query = "SELECT * FROM users WHERE id = ?";

    db.query(query, [userId]);

    ```

    Data Protection

    Encryption

    **At Rest**: Encrypt data in databases, file storage

  • Use database encryption features
  • Encrypt sensitive files
  • Protect backup data
  • **In Transit**: Use HTTPS/TLS

  • Always use HTTPS in production
  • Enforce HTTPS (redirect HTTP)
  • Use strong TLS versions (1.2+)
  • Secrets Management

    Never hardcode secrets:

  • Environment variables: For configuration
  • Secret managers: AWS Secrets Manager, HashiCorp Vault
  • Rotate regularly: Change secrets periodically
  • **What to protect**:

  • API keys
  • Database passwords
  • Private keys
  • OAuth secrets
  • API Security

    Rate Limiting

    Prevent abuse and DoS attacks:

  • Limit requests per IP/user
  • Different limits for different endpoints
  • Return 429 (Too Many Requests) when exceeded
  • API Keys and Tokens

    **API Keys**: For server-to-server communication

  • Store securely
  • Rotate regularly
  • Scope to specific permissions
  • **JWT Tokens**: For user authentication

  • Use short expiration times
  • Include user ID and permissions
  • Sign with strong secret
  • Validate on every request
  • CORS (Cross-Origin Resource Sharing)

    Control which domains can access your API:

  • Restrictive: Only allow your frontend domain
  • No wildcards: Don't use `*` in production
  • Credentials: Only allow when necessary
  • Dependency Security

    Keep Dependencies Updated

    **Why**: Vulnerabilities are discovered regularly

    **How**:

  • Use dependency scanning tools
  • Update regularly (monthly)
  • Test updates before deploying
  • Monitor security advisories
  • **Tools**:

  • npm audit: Built into npm
  • Snyk: Comprehensive vulnerability scanning
  • Dependabot: Automated dependency updates
  • Minimize Attack Surface

  • Only install what you need: Fewer dependencies = fewer vulnerabilities
  • Remove unused dependencies: Regular cleanup
  • Use trusted sources: Official packages, verified publishers
  • Infrastructure Security

    Network Security

  • Firewalls: Restrict access to necessary ports
  • VPC: Isolate resources in private networks
  • WAF: Web Application Firewall for HTTP traffic
  • Access Control

  • SSH keys: Use keys, not passwords
  • IAM: Principle of least privilege
  • MFA: Require for admin access
  • Audit logs: Track who accessed what
  • Monitoring and Alerting

  • Log security events: Failed logins, permission denials
  • Alert on anomalies: Unusual patterns, spikes in errors
  • Incident response plan: Know what to do when something happens
  • Compliance Basics

    GDPR (EU)

    If you handle EU user data:

  • Right to access: Users can request their data
  • Right to deletion: Users can request data removal
  • Data portability: Users can export their data
  • Privacy policy: Clear, understandable
  • SOC 2

    For B2B SaaS:

  • Security controls: Documented and tested
  • Access controls: Who can access what
  • Monitoring: Logging and alerting
  • Incident response: Plan and procedures
  • HIPAA (Healthcare)

    If you handle healthcare data:

  • Encryption: Required for PHI
  • Access controls: Strict authentication
  • Audit logs: Track all access
  • Business Associate Agreements: With vendors
  • Security Checklist

    Development

    Input validation on all user inputs
    Parameterized queries (no SQL injection)
    Output encoding (prevent XSS)
    Authentication on all protected routes
    Authorization checks for all operations
    HTTPS in production
    Secrets in environment variables
    Dependencies updated and scanned

    Infrastructure

    Firewall rules configured
    Database encrypted at rest
    Backups encrypted
    Access logs enabled
    Monitoring and alerting set up
    Incident response plan documented

    Operations

    Security updates applied regularly
    Access reviewed periodically
    Secrets rotated regularly
    Security incidents documented
    Team trained on security practices

    Common Vulnerabilities

    OWASP Top 10

  • Injection: SQL, NoSQL, OS command injection
  • Broken Authentication: Weak passwords, session management
  • Sensitive Data Exposure: Unencrypted data, weak encryption
  • XML External Entities: XXE attacks
  • Broken Access Control: Missing authorization checks
  • Security Misconfiguration: Default settings, exposed services
  • XSS: Cross-site scripting
  • Insecure Deserialization: Remote code execution
  • Using Components with Known Vulnerabilities: Outdated dependencies
  • Insufficient Logging: Can't detect or investigate attacks
  • Incident Response

    When something goes wrong:

  • Contain: Stop the attack, isolate affected systems
  • Assess: Understand what happened, what data was accessed
  • Notify: Inform affected users, authorities if required
  • Remediate: Fix vulnerabilities, restore systems
  • Learn: Post-mortem, improve processes
  • Conclusion

    Security is a foundation, not a feature:

  • Build it in from day one
  • Keep dependencies updated
  • Monitor and alert
  • Have an incident response plan
  • At Fundare, we help teams build secure foundations from the start. The goal isn't perfect security—it's good enough security that protects users and your business without slowing development.

    Remember: Security is everyone's responsibility, not just the security team's.

    Start a project →