iOS Security Standards
Priority: P0 (CRITICAL)
Implementation Guidelines
Key Storage
- Keychain: Use for Auth tokens, passwords, and PII. Never store in
UserDefaults. - SecItem API: Use
SecItemAdd,SecItemUpdate, andSecItemDeletefor persistent secure storage. UsekSecClassGenericPasswordfor tokens. - Biometrics: Use
LocalAuthenticationfor Face ID or Touch ID. UseLAContextand verify availability withcanEvaluatePolicybefore evaluation.
Data Protection
- File Encryption: Use
Data.WritingOptions.completeFileProtectionwhen saving files to disk. - App Sandboxing: Respect the sandbox; do not attempt to access files outside of your container.
- Sensitive Data: Avoid storing PII in unprotected files.
Network Security
- ATS: Don't disable App Transport Security (ATS) globally in
Info.plist. In-transport encryption is mandatory. - SSL Pinning: Use ServerTrustManager or TrustKit for backend-critical applications to prevent MITM attacks.
Anti-Patterns
- No secrets in UserDefaults: Always use Keychain.
- No unhandled LAError: Check for userCancel, authenticationFailed, etc.
- No PII/token logging: Ensure sensitive logs are stripped in Release builds.
References
- Keychain & Biometrics Implementation
Related Topics
- common/security-standards
- architecture