Firebase Security Guide
Q&AFirebase
How do I secure Firestore properly?
Firestore security requires writing granular Security Rules that validate authentication, authorization, and data structure for every collection and document. Rules should check request.auth and enforce ownership and data constraints. Avoid broad wildcard allow rules. UNPWNED tests bounded anonymous read and access patterns and reports confirmed exposure. It does not parse or certify every Firestore rule.
Check your Firebase app now
Run free security scanLast reviewed: 2026-04-07. Based on publicly available security research and UNPWNED scan telemetry.
