Nova-Rewards

Nova Rewards — Security Best Practices

Version: 1.0
Last Updated: 2026-03-30


Smart Contracts (Soroban / Rust)

Access control

Arithmetic

State management

Testing

Deployment


Backend API (Node.js)

Authentication & authorization

Input validation

Secrets management

Rate limiting & abuse prevention

Logging

Dependencies


Frontend (Next.js)

Wallet & key handling

Content security

Data handling

API communication


Infrastructure

Network

Secrets & credentials

Patching

Backups

Monitoring & alerting


Development Workflow

Code review

Secrets in development

CI/CD

Bug bounty


Compliance Checklist (Pre-Launch)


Reviewed by: Security Team
Next review due: 2026-09-30