Lanes
One lane at a time — the goal, the critical path, and the current wave of blockers.
Approve: Security & SecretsTo do · blockerNEEDS MATTHEW: audit every SECURITY DEFINER function for the PUBLIC execute grantTo do · blockerPer-account rate limiting on write endpointsDoneRate limit auth endpointsDoneAgent-run pre-launch security auditTo doRotate all credentials at production cut-overTo doEncrypt card connector tokens — currently plaintextTo doMake the cookie banner actually gate non-essential storageDoneNEEDS MATTHEW NOW: anon can delete any account — one REVOKE closes itDoneNEEDS MATTHEW: v_account_tier leaks the full customer roster to anon — confirmed liveDoneAdd in-product Report link on the public destination viewerTo doContact PATCH was wiping every card field — fixed, PR #164DoneNEEDS MATTHEW: GitHub Actions billing wall — all CI is blockedDoneEnable Supabase leaked-password protectionTo doPublish security.txt (vulnerability disclosure)DoneConfirm sandbox flag unset in productionDoneAdd CORS middleware to tactile-apiDoneAdd CSP header on web responsesDoneAdd HSTS headerDoneSAST scanning in CIDoneCookie consent bannerDoneAudit log table for sensitive opsDoneAdd abuse-report endpointDoneDocument secrets inventoryTo doDependency scanning in CIDoneAgent-harness escape strings were shipping in page source — stripped, PR #167Done
Wave
Security & Secrets
v1.0 security hardening + secrets discipline. Agent-run security audit before production cut-over (no third-party pen test for v1.0).
TacTile › Launch TacTile › Foundations › Security & Secrets
18/26 done8 open2 open blockers
Selected taskclear
SAST scanning in CI
DoneOwner · Vivt_970fc2fe
Static analysis wired into CI.
Unlocks 1Approve: Security & Secrets
Show the prompt
To doIn progressDoneBlockedPick a wave on the left · tap a task to expand it