codexier.

SaaS & MVPs

Security Checklist Before Your First Paying Customer

By CodexierPublished 5 min read

The first paying customer changes what a bug costs. Until then, a leaked record is embarrassing; after, it is a GDPR breach with a 72-hour notification clock and a customer who trusted you with their data. The good news is that the controls that matter most at this stage are cheap and specific. This checklist is what we go through before a client's product takes its first payment.

Authentication and passwords

  • Password hashing with a modern algorithm (argon2 or bcrypt) via your framework or provider, plus rate limiting on login and reset endpoints.
  • Session tokens that expire, are invalidated on logout and password change, and are stored in httpOnly cookies rather than local storage.
  • Password reset that never reveals whether an email exists and expires the link within an hour.
  • Two-factor authentication available for admins now and for customers when they ask; B2B buyers will ask early.

Access control and roles

The most common serious flaw in early SaaS is not a clever attack but a missing check: a user changes an id in the URL and sees another company's invoice. Authorisation must be enforced where the data is read, with the tenant id coming from the session and never from the request.

ControlMinimum before first paymentHow to verify
Tenant isolationEvery query filtered by the caller's tenant; row-level security if the database supports itLog in as tenant A, request tenant B's ids by hand
RolesOwner, member and your own support role, each with an explicit permission listTry every admin action as a member
Support accessStaff access to customer data is logged and time-limitedRead the log after a support session
API keysScoped per tenant, revocable, shown onceRevoke one and confirm the old key fails

Test with two real tenants you created yourself. Automated scanners do not find authorisation bugs; a person with two browser windows does.

Secrets and environment handling

Database passwords, payment provider keys and signing secrets leak in predictable ways: committed to git, pasted in a chat, baked into a client-side bundle. Each is avoidable with one rule and one tool.

  • Secrets live in the hosting platform's environment configuration or a secrets manager, never in the repository, and a pre-commit scanner blocks accidental commits.
  • Separate keys for development, staging and production. A leaked test key must not touch real money or real customers.
  • Payment secrets stay server-side. Only publishable keys reach the browser, and webhooks verify the provider's signature.
  • Rotate any secret that has ever been shared by chat or email, today, and write down who can rotate what.

Backups and restore tests

A backup you have not restored is a hope, not a control. Managed databases back up automatically, but the questions that matter are whether you can get a specific tenant's data back to a specific point in time, how long that takes, and whether file storage is included.

Daily automated backups

Database and file storage, retained for at least thirty days, stored in a different account or region from production so a compromised account cannot delete both.

One timed restore

Restore last night's backup to a fresh environment, note the minutes it took and the steps that surprised you. Repeat quarterly.

Point-in-time recovery

Enable it if the database offers it. A bad migration at 14:03 should be recoverable to 14:02, not to last midnight.

Logging and incident plan

Under GDPR you must be able to assess a breach and, if required, notify IMY within 72 hours of becoming aware of it. That is impossible without logs that say who accessed what, and a plan short enough that a stressed founder follows it.

  1. Log authentication events, admin actions, data exports and failed authorisation checks, with timestamps and user ids, retained for at least ninety days.
  2. Alert on anomalies you can define today: many failed logins, an export of a whole tenant, a new admin created.
  3. Write a one-page incident plan: who is called, how access is revoked, which customers are told, who contacts IMY, where the timeline is written.
  4. List your subprocessors and where data is hosted; customers will ask for it in their first security questionnaire.

If your first version was built fast and you are not sure which of these hold, a scaling and hardening pass covers exactly this list, and a 15-minute call is enough to tell you which items are urgent. Pricing is on the pricing page.

When this is more than you need

If your product is free, stores no personal data beyond an email address and is used by people you know, do the auth and secrets items and leave the rest until money or customer data arrives. If you are selling to a regulated enterprise, this list is the floor, not the ceiling; they will ask for SOC 2 or ISO 27001 evidence and you should plan for it with an adviser, not a checklist. Our GDPR guide for SaaS founders covers the paperwork side.

Frequently asked questions

Do we need a penetration test before the first customer?

Not usually. A penetration test finds what remains after the basics are in place; doing it before this checklist wastes most of the budget on findings you could have fixed yourself. Do the list, then buy a scoped test when a customer's procurement requires one.

Is a managed platform like Supabase or Firebase secure by default?

They secure the infrastructure, not your rules. Row-level security policies, storage permissions and API keys are yours to configure, and a misconfigured policy exposes every row to every user. Test tenant isolation by hand regardless of platform.

What do we tell customers who ask about security?

A one-page summary of the controls above, your hosting region, your subprocessors and your incident contact. Honest and specific beats a long policy copied from a template. Most small B2B buyers accept this until they grow into formal audits.

Not sure which items your product already passes?

Bring your stack and hosting setup to a short call. We go through the checklist with you, tell you which items are urgent before you take payment, and what a fixed-price hardening pass would cost.

Book a free 15-minute call