This blog covers application security as it turns up in real assessments: mobile app hardening, API authorisation, web access control, cloud blast radius, secure coding practice and the compliance questions Indian product teams get asked. 18 posts, each dated and revised when the advice changes.
For a small product team, the Digital Personal Data Protection Act reduces to five engineering obligations: keep an inventory of personal data, collect and record consent for each purpose, delete data on request and when its purpose ends, report breaches to the Data Protection Board and affected users, and apply reasonable security safeguards.
Twenty checks, grouped the way an attacker looks at an app: what ships inside the package, what lands on the device, what crosses the network, and what the server accepts.
Security spend fails when it arrives in the wrong order. Here is what buys the most risk reduction at each funding stage, with indicative rupee figures.
Pinning fails in one of two ways: not implemented, or implemented so tightly that a routine certificate renewal takes the app offline for everyone who has not updated.
· updated 18 Jun 2026
Want this run against your own product?
Scope and a fixed quote within two working days. First consultation is free.