We built this, but is it secure?
The file browser and standards checker I built for Autodesk Forma was done. Working, in use, nothing left on the list.
Which is when it occurred to me what that tool actually is. It signs in as me. It holds a live connection to real project data, under my credentials, for as long as I am logged in.
We built this, but is it secure?
The right instinct, the wrong question
That question is the correct thing to feel and the wrong thing to type.
Nobody can hand us a yes. And a no does not say where to start, which is the only thing we actually need at that moment.
Claude Code has a security review built in, so /security-review is the short path. When I ask in plain words instead, the wording that works looks like this:
Read this project and tell me what someone would go after, worst first.
Worst first is doing the real work in that sentence. It forces a ranking, and a ranking is the only form of this list any of us can act on before dinner.
What comes back
A list, graded high to low, with the reasoning attached to each finding.
The categories are less exotic than the word security suggests. Mostly they are ordinary questions we could have asked ourselves and did not. Who can reach this thing, and what does it answer to? What is a browser allowed to load into the page? What happens to a file whose name somebody else chose? Where do the access tokens sit while we are signed in?
It also reports what came back clean, and that turned out to matter as much as the problems. No credentials in the source. Debug mode off. The app answering only to this machine instead of to the whole network.
A review that prints nothing but problems teaches us nothing about what we already got right, and what we got right is the part we most need to not break later.
Ranked is not decided
Here is the part that is easy to skip.
A severity label is a general claim. It is what that finding usually means, across all the projects that could have it. Ours is not all projects. It is one tool, on one machine, on a network we control.
Sometimes that makes a finding smaller than its label. Sometimes much bigger, because the data on the other end could belong to a customer and is not ours to gamble with.
I fixed the high ones immediately. The rest over some time, which is not the same as ignoring them. A risk we have looked at and consciously deferred has a name and a reason. One nobody has looked at is just waiting.
So: is it secure? Still the wrong question. It read every file faster than I would have and it did not get bored on the third blueprint. What it cannot know is where this thing lives and who is on the other end.
It brings the list. The call is ours, because the work goes out under our name and not the software's.
Be Better - Make sure it's secure.