Purpose
Ensure iOS code is secure by default. For security output format and core refusal policy, see /shared-sec-baseline.
iOS-specific security concerns (always check)
- Keychain for secrets — never UserDefaults for tokens, passwords, or API keys
- ATS enforcement — no exceptions without justification; never disable TLS validation
- Deep link validation — validate scheme, host, and parameters before acting on universal/custom links
- Notification payloads — treat
[Description truncada. Veja o README completo no GitHub.]