Trust & security
Building your software means holding your keys.
To do the work we usually need access to your hosting, your domain, your analytics and sometimes your payment provider. That deserves more than a line in a contract.
- Least
- Access we ask for
- Yours
- Who owns the accounts
- On handover
- When our access ends
- None
- Certifications claimed
Access
The smallest key that opens the door.
Most security failures in agency work are not break-ins. They are access that was granted broadly, never scoped down, and never revoked.
We ask for the narrowest role
Not an admin account
Accounts stay in your name
We are invited, not the owner
Access ends at handover
You do not have to ask
No shared logins
Individually attributable
Handling
Where credentials actually live.
A password manager, never a message
No email, no chat
Secrets never enter the repository
Environment only
Client data stays in your systems
We don't take copies
Two-factor on everything
On our side too
Being straight with you
What we are not claiming.
Plenty of companies imply certifications they don't hold. We'd rather list ours honestly — which currently means listing none.
No SOC 2 or ISO 27001
Not audited
We're a small team
Know the trade-off
You should still keep your own backups
Whoever builds it
Report something
We'll respond
Ask before you hand anything over.
If there's something here you need clarified for your own compliance, ask — a real person answers.