Moving fast and staying secure
Not all engineers in your company will be security-minded, so encourage a culture of security where you follow best-practices as a habit. Perfect security doesn’t exist, but big problems can be systemically avoided. Pretend that your API traffic is public knowledge, and design your systems defensively.