
4/26/2019
What this post added
This post details the foundational elements and strategic pillars of Shopify's application security program. It outlines the approach to scaling secure applications by standardizing on a technical baseline (Ruby on Rails), improving service visibility through production engineering initiatives, and providing secure defaults for new projects. It also discusses scaling security teams by specializing roles and utilizing external validation services, and scaling security interactions through automated tripwires, code-level security checks (e.g., for `html_safe`), and infrastructure-level safeguards.