# Go-live checklist

> Tick these off before your first production key; the list is saved in this browser.

- [ ] Keys and webhook secrets live in a secret manager, never in code
- [ ] Webhooks verify signatures on the raw body and reject timestamps more than five minutes from your server's clock
- [ ] Webhook handlers dedupe on the event's signed id and answer within five seconds
- [ ] Failed and dead-lettered webhook deliveries alert someone
- [ ] Imports page with cursors and save change cursors in the same transaction as the records
- [ ] Your app shows partial imports, missing categories, and empty categories differently
- [ ] Reads stop on 410 consent_inactive and your retention policy runs
- [ ] A revoked or expired receipt removes that source's records from your copy
- [ ] deletion.requested deletes what you hold for that subject
- [ ] Connect sessions request only the categories your product uses
- [ ] externalId values are opaque and never contain names, emails, or health details
- [ ] Logs and alerts never contain record bodies or subjects
- [ ] The application has its purpose, categories, retention period, privacy policy URL, and webhook URL
- [ ] Recommended: a conformance run passes on a separate sandbox application

When it's all done, create a production key in the console. If a required setting is missing, the console lists it. See [Environments and keys](/docs/get-started/environments-and-keys).
