Handling

You are handing us the keys. Here is how we hold them.

This is the part of the engagement that nobody asks about on the first call and everybody thinks about afterwards. It is written down so you do not have to ask.

Commitments

Eight, and they are contractual.

Each of these appears in the engagement agreement. If one of them is a problem for your insurer or your own policy, say so before we start — they can be tightened, and one of them being unworkable is not a reason to abandon the engagement.

01

Read access only, by default

A health check requires no write access to anything. If remediation is agreed later, write access is granted for that scope and revoked when it ends.

02

Least privilege, and time-boxed

We ask for the narrowest access that lets the work happen, on accounts created for us rather than shared ones, and we ask you to disable them the day the engagement closes. If you forget, we will remind you.

03

Your credentials are never emailed

They come through a password manager share or a one-time secret link. Anything sent to us by email is treated as compromised, and we will say so and ask for it to be rotated.

04

Production data stays in production

Where a restore or a copy is genuinely required — a backup test, for instance — it happens in an isolated environment that is destroyed at the end, and the report says it happened.

05

Encrypted at rest, on hardware we control

Working copies live on full-disk-encrypted machines, not on shared drives and not in a third-party AI tool. Nothing from your system is used to train anything.

06

Deleted on request, and on a schedule anyway

Working material is destroyed ninety days after the engagement closes, or immediately if you ask. The report itself we keep, because you may ask us for it again.

07

Findings go to you first, and only to you

A vulnerability we find is yours. It is not a case study, it is not a conference talk, and it is not mentioned to anyone — including in anonymised form — without written permission.

08

We tell you what we broke

Read access still occasionally causes something: a query that loads a server, a login that locks an account. If we cause it, it is in the report, named, whether or not you noticed.

If we find something serious

Disclosure runs to you, immediately, ahead of the report.

If we find something that appears to be under active exploitation, or credentials already published in a breach corpus, you hear about it the same day by telephone. It does not wait for the report, and it does not wait for the invoice.

If the finding touches personal information in a way that may trigger a reporting obligation under Quebec's Law 25, we will say so plainly and in writing — and then point you at a lawyer, because we are not one and the deadline is yours to meet, not ours.

What we are not

Honest limits.

We are a small studio, not a certified assessor. There is no SOC 2 report behind this page and we are not going to imply otherwise — if your procurement process requires one, we are the wrong supplier and we would rather tell you now than at the end of a proposal.

A health check is a posture review conducted with source access. It is not a penetration test and does not replace one. Where a finding needs a specialist, the report says so and names what to ask for.