Why this matters
Meets SOC 2 transport security and log hygiene expectations.
Enable config.force_ssl = true; add filter_parameters to redact PII and secrets; use secure_same_site for cookies.
Meets SOC 2 transport security and log hygiene expectations.
Side-by-side examples engineers can pattern-match during review.
Rails.logger.info("token=#{token}")Rails.application.config.filter_parameters += [:password,:token,:email]Rails.application.config.force_ssl = trueRails.application.config.force_ssl = falseFrom the same buckets as this rule.
Public services must require TLSv1.2 or higher and set HSTS (max-age ≥ 15552000, includeSubDomains). Reject plaintext HTTP and weak ciphers; cookies must be Secure and HttpOnly with SameSite set.