Skip to content

Trust, Data & Access Safety

Know how access, data and production decisions are controlled before sharing anything sensitive.

Begin with public information or the least access needed, keep credentials out of public forms, identify authorized owners and agree engagement-specific controls before private access or production work begins.

The public starting boundary

These are public content boundaries for the service journey. The final operating and contractual controls must match the actual engagement.

Public evidence first

The free WordPress Scan starts from public website signals and does not require WordPress administrator, hosting, database or source-code access.

No credentials in public forms

Public enquiry forms do not request passwords, access keys, recovery codes or other secrets. Access is arranged separately after scope and authorization are agreed.

No production change by assumption

A public Scan, enquiry or decision conversation does not authorize a configuration change, deployment, data export or production action.

Access principles

Least privilege

Request only the access needed to answer the agreed question or deliver the approved outcome, preferring read-only or narrower roles where practical.

Named authorization

Identify who may grant access, approve production work, accept results and request revocation.

Separate secure exchange

Agree an appropriate channel for credentials or invitations instead of placing secrets in public forms, ordinary documents or tickets.

Environment awareness

Distinguish production, staging, development, hosting, domain, analytics and third-party systems before access is used.

Time and purpose boundaries

Tie access to a named purpose and review whether it is still required at handover, pause or completion.

Visible responsibility

Record which responsibilities remain with the client, hosting provider, software vendor, agency or other third party.

Before private access is requested

  1. Define the question or outcome. Do not request broad access before the evidence need and service boundary are understood.
  2. Name the authorized people. Confirm who owns the system, who may grant access and who approves production decisions.
  3. Inventory the required systems. Separate WordPress, hosting, domain, repository, analytics, advertising and external-provider access.
  4. Select the narrowest practical roles. Prefer invitations, individual accounts, read-only access or staged elevation when the system supports them.
  5. Agree handling and revocation. Confirm the exchange channel, use, storage, retention, handover and access-removal expectations that apply.

What this page establishes—and what remains engagement-specific

AreaPublic service boundaryConfirm for the engagement
CredentialsDo not submit secrets through public forms.Exchange channel, account type, multi-factor authentication and recovery ownership.
AccessUse the least privilege and access needed for the agreed work.Systems, roles, duration, logs, approvals and revocation process.
Client dataDo not assume private customer or payment data is needed.Permitted data classes, environments, storage, location, retention and deletion requirements.
Production changeNo change is authorized by a Scan or enquiry; implementation requires an approved scope.Change owner, review evidence, deployment window, rollback, acceptance and exception process.
ConfidentialityKeep public claims inside approved evidence boundaries.Non-disclosure terms, attribution, client contact and publication permissions.
AssuranceDo not invent badges, certifications, insurance or universal service commitments.Required policies, certifications, insurance, provider terms and procurement evidence.

Client code, content, data and artificial intelligence tools

No blanket permission is assumed to place client code, content, personal information, production data or credentials into an artificial intelligence tool. If such a tool may be useful, the intended data, tool, purpose, storage and retention behavior must be disclosed and checked against the engagement requirements before use.

Production approvals and handover

Before change

Record the approved scope, environments, critical workflows, acceptance evidence, rollback boundary and responsible approver.

During change

Keep observed results, exceptions and scope changes visible instead of treating new evidence as silent authorization.

At handover

Document completed work, remaining risk, access ownership, required revocation and separately scoped next work.

Engagement-specific commitments

This page explains the public trust model. Engagement-specific policies, tools, providers, insurance, certifications, retention periods, contractual terms and service commitments are confirmed in the proposal or agreement.

Frequently asked questions

Should I send a password through a website form or email?

No. Public forms should never be used for passwords, access keys or recovery codes. The required access, approved channel and responsible people are agreed only after the question and scope are understood.

Do you always need administrator or production access?

No. Public evidence, exported artifacts or approved read-only access may be sufficient. Broader privileges are requested only when the agreed work requires them.

Are specific security certifications, insurance or retention terms guaranteed?

Engagement-specific tools, retention, certifications, insurance and contractual commitments are confirmed in the proposal or agreement.

Will client code or data be used with artificial intelligence tools?

Any use of artificial intelligence tools with client code, content or data is disclosed, limited by the engagement requirements and approved where required. The proposal or agreement confirms the tools, data classes and retention behavior.

Free public WordPress assessment

Need a public first look before discussing private access?

Start with the free WordPress Scan. It reviews publicly observable WordPress, response, delivery, maintenance and search signals, then gives you a bounded modernization assessment and a clearer next step. No admin access is required.

The Scan does not confirm private technical root causes. If the report surfaces a signal that matters and you are unsure what to do next, ask us to help interpret the evidence.