> ## Documentation Index
> Fetch the complete documentation index at: https://developers.aptranet.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Security best practices

> Apply least privilege, credential hygiene, safe DNS changes, and secure CDN origin controls.

## Identity and access

* Require phishing-resistant passkeys or TOTP for operators.
* Grant organization and project permissions independently.
* Create one API key per workload and environment.
* Disable or delete credentials when their owner or workload changes.
* Keep API secrets in a server-side secret manager and prevent them from entering logs.

## Cloud CDN

* Use HTTPS to the origin and enable origin TLS validation.
* Restrict direct origin access where your architecture permits it.
* Do not publicly cache responses that vary by `Authorization`, cookies, or user identity.
* Review custom cache keys and ignored query parameters for cross-tenant collisions.
* Validate CORS, request headers, and response-header hiding policies in staging.
* Treat signed-URL keys as secrets and rotate them through a controlled process.

## Cloud DNS

* Lower TTLs before a planned cutover, not during it.
* Verify the complete record set before changing nameservers.
* Preserve mail, verification, CAA, and delegation records during migration.
* Use health checks only for endpoints whose failure behavior you have tested.
* Confirm what happens when every eligible endpoint is unhealthy.

## Incident response

If a credential may be compromised, disable the key or roll its secret, revoke human sessions, inspect recent changes and analytics, and contact [support@aptranet.com](mailto:support@aptranet.com). Include trace IDs but never include secrets.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.