Home › Security & Website Access
Security & Website Access

Careful Access, Documented Changes

Handing someone access to your website is a matter of trust. This page sets out exactly how we handle that access — what we ask for, what we never ask for, and what happens to it when the work ends.

You keep ownership of your accounts throughout. We work with your access; we never take it over.

Ask About Our Security Process Website Security Services
Do not send passwords, API keys or login details through any form. If access is needed, we agree a secure method first.

How We Handle Your Credentials

The first rule is simple: credentials do not travel through forms, emails or chat messages.

Nothing sensitive in the open

We never ask for a password in a form, an email or a message thread. If someone claims to be us and does, it is not us.

A secure sharing method

Where access is required, we agree a specific, secure way to grant it and confirm it in writing before it is used.

Your accounts stay yours

We prefer a separate, limited account you create and control, rather than the keys to your main administrator login.

Least Privilege, in Practice

The right amount of access is the amount the task needs — and not a level more. It depends on the work, not on convenience.

Type of workTypical accessWhat we do not need
Content and image updatesEditor access to the area involvedServer or hosting credentials
Updates, backups, monitoringMaintenance-level access to the site and its backup toolYour email or payment accounts
Security work or a fixThe minimum needed for the specific issue, agreed in writingAccess beyond the sites in scope
Migration or server changeHost and DNS access for the move, then handed backOngoing access once the move is done

Access is scoped to the sites we are engaged for. We do not expect, or want, a single login that unlocks everything you own.

Two-Factor and Account Hygiene

Strong logins and two-factor authentication are standard practice, not an optional extra.

Two-factor where supported

We enable two-factor authentication on the access we hold wherever the platform supports it, and we recommend the same for your own logins.

No shared logins

We use named or limited accounts rather than one password passed around a team, so access can be traced and withdrawn cleanly.

Ask and we will confirm

If you want to know exactly what is enabled for your site, ask us and we will tell you plainly.

Backup Before Change, Staging First

A change with no way back is a gamble. We remove the gamble before we start.

What we do before risky work

  • Confirm a recent, complete backup exists
  • Verify that the backup can actually be restored, not just that a job ran
  • Test the change in staging where the setup allows it
  • Keep a rollback path ready for the duration of the work

Why it matters

A backup that has never been test-restored is not really a backup. Most of the pain in website failures comes from discovering that gap at the worst possible moment. We check the restore path as part of the work, so a rollback is a decision, not a hope.

Logged and Traceable

If we touched your site, there is a record of it.

Approved work is logged

What was done, when, and against which request — so there is never a dispute about what was agreed.

Checks are recorded

The verification steps after an update or fix are noted, not assumed.

Rollbacks are visible

If something is reverted, that is recorded too — including the reason, not just the outcome.

This record feeds your monthly report, so the work you paid for is visible even in a quiet month.

Data Isolation and Confidentiality

Your site and its data are treated as yours to hold, not ours to reuse.

Kept separate

Access and records for one client are not pooled with another. Work on your site stays within the scope of your engagement.

Not shared on

Your data is not sold, published or used to market to your customers. Agency client lists are held under the same rule.

Handed back on exit

When the relationship ends, access is revoked and anything we hold is returned or removed on a defined path.

What We Ask From You

Good security is a two-way arrangement. A little care on your side makes the whole thing stronger.

  • Grant access through the agreed secure method, not by pasting passwords into messages
  • Give us a single point of contact for approvals
  • Tell us when something changes on your side — a new host, a new admin, a departure
  • Keep your own administrator accounts under your control
  • Confirm scope in writing before new work begins
  • Tell us early if you suspect a problem, rather than waiting to be sure

An Honest Note on Risk

Security is about reducing risk, not eliminating it. We would rather say that clearly than sell a promise we cannot keep.

No website is zero-risk, and no maintenance provider can guarantee that yours will never be attacked, broken or breached. What we can control is the quality of the groundwork: keeping software current, holding only the access we need, verifying backups before risky changes, watching for the quiet failures, and responding in an organised way when something does go wrong. That is the honest version of "we keep your site safe."

Want the detail behind this page? See Website Security Services and Website Security Audit.

Security & Access FAQ

Do you need my passwords?

No. We never ask for passwords through a form, an email or a chat message. If work needs access, we agree a secure method and use an account you control, rather than asking you to hand over credentials in the open.

What access do you actually need?

Only what the specific task requires, and only for the sites in scope. A content change and a security fix do not need the same level of access. Access is agreed in writing before work starts.

Do you keep access after the work is done?

No. Access is revoked or rotated when the task or the relationship ends. You can ask at any time what access we hold for your site and we will show you.

Can you guarantee my site will never be hacked?

No, and any provider who promises that is not being straight with you. No website is zero-risk. Our job is to reduce the risk, detect problems early, and respond quickly when something happens.

Will you work on a copy before touching my live site?

For risky changes, yes. Updates and structural work are tested in a staging environment first where the setup allows it, and a verified backup is taken before changes that carry real risk.

Do you keep a record of what you change?

Yes. Approved work, the checks that were run and any rollbacks are logged. The record is what makes the work auditable and shows up in your monthly report.

Questions About How We Handle Access?

If you want to know exactly how your site and accounts would be handled, ask. We would rather answer the question than have you guess.

Ask About Our Security Process Contact Us
Do not include passwords, API keys or login details.