Security — Mandatory

Security Essentials

Foundational

These rules are absolute. You cannot negotiate them. Every line on this page is a Never. "Never" means never — in any situation, for any reason, by anyone, on any system. No deadline, no manager's instruction, no "just this once", and no "it's only internal" makes any of them acceptable.

This is not advice. These rules are a condition of working here. If you knowingly break one, it is a serious disciplinary matter. Depending on the harm caused, it may be gross misconduct and grounds for immediate dismissal. You may also face personal legal and regulatory liability. Not knowing a rule is not an excuse. If you do not understand a rule, ask before you act. Do not explain afterwards.

Identity & accounts

Secrets & keys

Authentication & authorization

Handling untrusted input & integrations

Sensitive data

Decisions & safety

AML, KYC & regulated decisions

Change control & automation

Be clear: every rule here exists because breaking it has, somewhere, leaked customer data, let the wrong person in, or destroyed the evidence needed for an investigation. Following them costs you seconds. Ignoring them can cost the company its licence, its customers, and its reputation. There is no clever exception, no special case, and no amount of pressure that justifies breaking one of these rules. If a rule seems to block legitimate work, stop and escalate it before you write any code. Do not decide on your own to break it. If you do, we treat it as a deliberate act, not an honest mistake.