Flutter Security

Security standards for Flutter applications based on OWASP Mobile.

ngxtm d24da20 3 files · 2.0 KB Updated

File contents

Mobile Security

Priority: P0 (CRITICAL)

Standards for basic mobile security and PII protection.

Implementation Guidelines

  • Secure Storage: Use flutter_secure_storage for tokens/PII. Never use shared_preferences.
  • Hardcoding: Never store API keys or secrets in Dart code. Use --dart-define or .env.
  • Obfuscation: Always release with --obfuscate and --split-debug-info.
  • SSL Pinning: For high-security apps, use dio_certificate_pinning.
  • Root Detection: Use flutter_jailbreak_detection for financial/sensitive applications.
  • PII Masking: Mask sensitive data (email, phone) in logs and analytics.

Reference & Examples

For SSL Pinning and Secure Storage implementation details: See references/REFERENCE.md.

Related Topics

layer-based-clean-architecture | performance

ngxtm/devkit/tree/main/rules/flutter/security commit d24da20a54

Frequently asked questions

npx skillmds@latest add ngxtm-devkit/flutter-security