# IOS Security

> Secure iOS apps with secure storage, biometrics, and data protection. Use when implementing secure storage, Face ID/Touch ID, or data protection in iOS.

- Skill: `hoangnguyen0403/ios-security` (Agent Skill, multi-file: 3 files)
- Install (CLI): `npx skillmds@latest add hoangnguyen0403/ios-security`
- Raw SKILL.md: https://api.skillmd.com/api/skills/hoangnguyen0403/ios-security/raw
- Safety review: PASS (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Security
- Author: HoangNguyen0403 (https://skillmd.com/u/hoangnguyen0403)
- Updated: 2026-08-19
- Page: https://skillmd.com/skills/hoangnguyen0403/ios-security

---

# iOS Security

## **Priority: P0 (CRITICAL)**

## Implementation Workflow

1. **Store secrets in secure storage** — Use `SecItemAdd`, `SecItemUpdate`, and `SecItemDelete` with `kSecClassGenericPassword` for tokens/PII. Never use `UserDefaults`.
2. **Add biometric auth** — Use `LocalAuthentication` with `LAContext`. Verify availability with `canEvaluatePolicy` before prompting.
3. **Encrypt files** — Use `Data.WritingOptions.completeFileProtection` when saving to disk.
4. **Keep ATS enabled** — Never disable App Transport Security globally in the iOS Info configuration.
5. **Pin certificates** — Use `ServerTrustManager` or `TrustKit` for production apps to prevent MITM attacks.
6. **Strip sensitive logs** — Ensure PII and tokens removed from logs in Release builds.

See [Secure storage and biometrics implementation examples](references/implementation.md)

## Anti-Patterns

- **No Secrets in `UserDefaults`**: Always use secure storage for tokens and PII
- **No Unhandled `LAError`**: Check for `userCancel` and `authenticationFailed` in biometric flows
- **No PII/Token Logging**: Strip sensitive data from all logs in Release builds

## References

- [Secure Storage & Biometrics Implementation](references/implementation.md)

## Related Topics

- common/security-standards
- architecture

## Canonical response anchors

When this skill applies, preserve the following domain terminology or equivalent concrete examples in the answer when relevant:
- iOS app configuration
- LocalAuthentication

