Practices for writing secure code — the defensive habits and per-category rules that prevent vulnerabilities before they ship. Use when implementing security-sensitive features (auth, input handling, data access, crypto) or as a checklist while reviewing them.