Secure App Deployment
Installation
SKILL.md
2.4.2 Secure App Deployment
Guidelines to ensure security, compliance, and revenue protection for mobile applications, PWAs, and backend infrastructure.
1. Platform Gatekeeping and Compliance
- Apple App Store: Map third-party SDK data in Privacy Manifests. Use highly specific purpose strings in
Info.plist. Implement strict UGC filtering and reporting. - Google Play Store: Enforce Android 15 (API level 35) targeting. Integrate Age Signals API for matchmaking/gambling. Never request disabling Google Play Protect.
- DMA Compliance: Accommodate Apple's Notarization security scanning for EU alternative distribution.
2. Revenue Security and In-App Purchases (IAP)
- Zero Client Trust: Manage sensitive purchase logic and cryptographic verification exclusively on the backend.
- Google Play Billing: Transmit
purchaseTokenvia TLS. Validate via Google Play Developer API. Grant entitlements only forPURCHASEDstate. - Apple App Store: Implement the App Store Server API (JWS payloads) and Server Notifications V2. Deprecate legacy on-device validation.
3. PWA Defenses
- Service Workers: Register to narrowest scope. Enforce strict CSP. Use Subresource Integrity (SRI) hashes.
- Data Persistence: Never persist JWTs/PII in
localStorageorsessionStorage. UseIndexedDBwith Web Crypto API application-level encryption. - Authentication: Implement WebAuthn and FIDO2 standards (hardware biometric authenticators).