Credential security
How to hand over credentials to us securely
Credentials do not belong in the first-contact form, plain email, or WhatsApp. We first determine which access is actually required for the agreed work, then confirm the handover method with you. Until you receive that confirmation, do not send passwords, keys, or tokens.
What never belongs in first contact
The form, phone, WhatsApp, and email are for the URL and a description of the symptoms only. Deliberately do not send us any of the following there:
- WordPress password
- SSH key
- Hosting or FTP access
- Database password
- Backup file
- Customer data
- Identity documents
- API secrets
How secure handover works instead
Once we have reviewed your request, we agree the required access and handover method with you. Follow these ground rules:
- Wait until we have explicitly confirmed the secure channel
- Share only the access required for the agreed work
- Use a separate, newly created password or token for each service
- Limit permissions to the access actually required
- Change every shared password, key, and token after the work is complete
Wait for a personal invitation before sending credentials
What to do after the work is complete
Change every password, key, and token shared for the work. Remove accounts created specifically for the incident and confirm that no temporary permissions remain. We record the required steps in the final report.
Questions about secure handover? Get in touch.