Security & Backups

Reduce risk with fewer assumptions and tighter boundaries.

Security is part of how services are designed and operated: minimal software, narrow access, verified changes, protected credentials, layered recovery, and human approval for high-impact actions.

Security principles

Controls that apply across the stack.

The exact safeguards depend on the agreed service and environment. No certification, compliance status, or guarantee is implied by these operating principles.

Least privilege

Access and service permissions are limited to what the approved work requires and reviewed when roles or scope change.

Minimal attack surface

Unnecessary plugins, frameworks, accounts, services, integrations, and public endpoints are avoided.

Protected credentials

Passwords, tokens, private keys, and administrative access are never requested through public forms or exposed to browser code.

Verified changes

Backups, dependencies, DNS, email routing, permissions, and rollback requirements are checked before high-impact work.

Maintained systems

Supported software, deliberate updates, configuration review, and documentation reduce preventable operational risk.

Human approval gates

Payment alone does not authorize provisioning, and destructive or sensitive changes are not silently automated.

Managed website security

A focused hosting environment with layered recovery.

Hosted sites use SSL, supported runtime versions, directory-index protection, controlled access, a minimal software footprint, and managed WordPress updates where WordPress is used.

Website backup layers

  • Provider-level nightly account backups on the Canadian hosting platform
  • Independent WordPress backups stored away from the web server on the approved schedule
  • Pre-change backups before significant updates, migrations, or DNS-dependent launches
  • Restore verification as part of the documented recovery practice

Honest limits

No system is unhackable, failure-proof, or permanently secure.

Security controls reduce risk; they do not eliminate it. Specific regulatory, privacy, recovery, retention, availability, and incident-response requirements must be identified, assessed, and written into the engagement before they are treated as commitments.

Discuss Security Requirements