Factory Security

Security conventions for builds that touch sensitive data, regulated industries, or AI-generated code paths. Covers KMS encryption at rest, BAA verification for PHI in email/SMS, safe URL redirects, admin-client bypass guardrails, in-memory rate-limiter caveats, the "read-only by default" stance for AI-generated code, mandatory-review-queue pattern, and request tracing for support workflows.

nonlinear-xyz 95a7d2a 10.7 KB Updated

File contents

nonlinear-xyz/factory-kit/tree/main/skills/factory-security commit 95a7d2aed5

Frequently asked questions

npx skillmds@latest add nonlinear-xyz/factory-security