Purpose
Defines the internal security policy and audit checklist covering authentication, API, database, infrastructure, and development practices.
7.1 Authentication
- Strong password requirements enforced: Salting and hashing via
bcryptjs with high cost factors.
- Multi-factor authentication (MFA) available/enforced: 6-digit real email OTP verification enforced via secure Gmail SMTP relay (
nodemailer).
- Secure session management: Cryptographically signed JWT tokens with 24-hour expiration, token rotation, and server-side blacklisting on logout/deletion.
- Secure password reset flow: Time-limited (10-minute validity), single-use OTP codes (
/api/auth/verify-reset-otp) and ephemeral reset tokens (/api/auth/reset-password).
7.2 API Security
- Authentication and authorization enforced on every endpoint: Valid
Bearer <token> header verified by auth.middleware.js. No endpoint relies on client-side checks alone.
- Rate limiting on sensitive/high-risk endpoints: Enforced using
express-rate-limit on /api/auth/send-otp, /api/auth/login, /api/auth/register.
- Input validation and sanitization performed server-side: Enforced using
express-validator on all request bodies, queries, and parameters.
- Protection against SQL/NoSQL injection, XSS, and CSRF: Parameterized statements via
mysql2/promise with placeholder bindings; HTTP security headers enforced by helmet().
- No excessive data exposure in API responses: Passwords, password hashes, and system secrets stripped from API outputs.
- Protection against IDOR (Insecure Direct Object Reference): Multi-tenant isolation strictly enforced with
WHERE id = ? AND user_id = ?.
- JWT/token manipulation resistance verified: Tokens signed using
HS256 with strong secret; invalid algorithms or payloads rejected with 401 Unauthorized.
7.3 Database Security
- Encryption at rest where appropriate: Storage volumes and database partitions encrypted with AES-256 in managed environments.
- Regular, automated backups: Daily automated snapshots and tested backup retention lifecycles.
- Restricted, least-privilege access: Dedicated database service credentials without global admin privileges.
- Database never directly exposed to the public internet: Binds strictly to
localhost or isolated VPC private subnets.
7.4 Infrastructure
- Firewall rules restricting access to internal services: Ingress restricted to HTTPS port 443; internal database/cache ports inaccessible externally.
- HTTPS/TLS enforced everywhere, no cleartext traffic: All traffic over TLS 1.2/1.3; Android
cleartextTrafficPermitted="false".
- Secrets management solution used: Secrets loaded from
.env environment variables, never hardcoded in source code or compiled APK.
- Ongoing monitoring and alerting for anomalies: Health checks at
/api/health, request logging via morgan, and automated error alerting.
7.5 Development Practices
- Code review required before merging to production branches: Pull requests and peer review enforced on
main and release/*.
- Dependency scanning for known vulnerabilities: Automated
npm audit and package security audits.
- Secret scanning on commits and git history: Pre-commit hooks and repository scanning to prevent secret leaks.
- Periodic vulnerability/penetration testing: Regular security assessments across auth, cards, customers, and ledger workflows.
7.6 Never Log
Absolute Prohibition: Passwords, OTPs, credit card numbers, JWT tokens, API secrets, private keys.
❌ Bad: User login: email=abc@gmail.com password=123456
✓ Good: LOGIN_SUCCESS user_id=8291 timestamp=...
7.7 Sensitive Data Categories Requiring Elevated Controls
The following categories receive elevated technical safeguards:
- Health information, financial information, identity documents, biometrics, precise location, children’s data, government IDs (e.g., Aadhaar, PAN), bank details, private messages.
Sign-off Checklist
- ☑ Authentication controls reviewed (MFA, password policy, session handling)
- ☑ API endpoints tested for authz/authn bypass, IDOR, injection
- ☑ Database access restricted and encrypted where appropriate
- ☑ Secrets management in place; no hardcoded secrets in code or APK
- ☑ Logging reviewed to ensure no sensitive data is captured
- ☑ Dependency and secret scanning integrated into CI/CD
- ☑ Elevated review completed for any sensitive data categories handled