Least privilege
Access and service permissions are limited to what the approved work requires and reviewed when roles or scope change.
Security & Backups
Security is part of how services are designed and operated: minimal software, narrow access, verified changes, protected credentials, layered recovery, and human approval for high-impact actions.
Security principles
The exact safeguards depend on the agreed service and environment. No certification, compliance status, or guarantee is implied by these operating principles.
Access and service permissions are limited to what the approved work requires and reviewed when roles or scope change.
Unnecessary plugins, frameworks, accounts, services, integrations, and public endpoints are avoided.
Passwords, tokens, private keys, and administrative access are never requested through public forms or exposed to browser code.
Backups, dependencies, DNS, email routing, permissions, and rollback requirements are checked before high-impact work.
Supported software, deliberate updates, configuration review, and documentation reduce preventable operational risk.
Payment alone does not authorize provisioning, and destructive or sensitive changes are not silently automated.
Managed website security
Hosted sites use SSL, supported runtime versions, directory-index protection, controlled access, a minimal software footprint, and managed WordPress updates where WordPress is used.
Honest limits
Security controls reduce risk; they do not eliminate it. Specific regulatory, privacy, recovery, retention, availability, and incident-response requirements must be identified, assessed, and written into the engagement before they are treated as commitments.