Programming guide

Run a security check before launching a web app

Work through a practical pre-launch security review of your web app, covering secrets, logins, permissions, input handling, dependencies and personal data.

Estimated time: 3–6 hoursUpdated: 28 September 2026

Use this guide before your web app goes live, or before a major update, especially if much of the code was written with AI help. Have access to your code, hosting settings and a list of the data your app stores. For apps handling payments or sensitive data, also consider a professional security review.

Step by step

  1. Search for exposed secrets

    Search your code and its version history for passwords, API keys and tokens. Move any you find into environment variables or a secrets manager, and change the exposed values, since removing them from code does not make old copies safe. Check that configuration files with secrets are excluded from version control.

  2. Review logins and permissions

    Check that you use an established library for authentication and password storage rather than custom code. Test that users can only see and change their own data by trying to access another user's records while logged in. Make sure admin features are protected on the server, not just hidden in the interface.

  3. Check input handling

    Find every place your app accepts input, including forms, URLs, file uploads and API requests. Make sure input is validated and that database queries use parameterised queries or your framework's safe methods. Use the OWASP Top 10 as a checklist for common web risks.

  4. Update and scan dependencies

    List the libraries your app uses, update them to supported versions and run a vulnerability scan if your tools provide one. Remove libraries you no longer use. Retest the app after updates.

  5. Review personal data handling

    List what personal data you collect, why you need it, where it is stored and who can access it. Remove anything you do not need, and make sure data is protected in transit with HTTPS. Check the Information Commissioner's Office guidance on your UK GDPR responsibilities and publish a clear privacy notice.

  6. Prepare for problems

    Set up error logging that does not record passwords or unnecessary personal data. Make sure you have backups and know how to restore them. Write down who to contact and what to do if you suspect a breach, including when you may need to report it to the ICO.

Ready-to-use checklist

  • No secrets in code or history
  • Exposed secrets changed
  • Established authentication library used
  • Access control tested with two accounts
  • All inputs validated
  • Dependencies updated and scanned
  • Personal data list and privacy notice
  • Backups and incident plan ready

Practical tips

  • Ask an AI assistant to review specific files for security issues, but treat its findings as leads to check, not a guarantee.
  • Test with two ordinary user accounts to find permission problems quickly.
  • Read the National Cyber Security Centre's guidance for small organisations for practical next steps.

Common problems

I found an API key committed months ago.

Revoke or change the key with the provider immediately, then remove it from the code and store the new one securely. Check the provider's logs for unusual use and consider whether any data may have been exposed.

A user can see another user's data by changing a number in the URL.

Your server must check that the logged-in user is allowed to access each record, not just that they are logged in. Fix the check for every affected route and add tests to prove it works.

I am not sure whether my app needs to follow UK GDPR.

If it processes personal data about identifiable people, it probably does. Check the ICO's guidance for small organisations, and get professional advice if you handle sensitive data or large amounts of it.