Critical and high-severity security issues that must be resolved before any customer data enters the system. Covers auth, multi-tenancy isolation, SQL injection, secrets rotation, and CORS.
Database transactions, exception handling, retry logic, connection pooling, missing indexes, and pagination. Prevents data corruption and cascading failures under production load.
Structured logging with request context, DSGVO-required audit trails for all data access and mutation, meaningful health checks, and proper error response sanitization.
Integration tests for tenant isolation and auth, transaction rollback tests, API versioning, pagination standards, and Go SDK coverage. Codifies all M1-M3 assumptions as automated tests.
Move auth tokens to httpOnly cookies, add error boundaries, lock down IPFS/DSMS gateway, and eliminate remaining client-side data exposure.