SECURITY / CONFIDENTIALITY

Security starts with controlled access.

Before reviewing source code, servers, databases or settings, we agree on what access is needed and aim to use the minimum appropriate permissions.

You don't need to know how to set up technical access. Tell us which service you use, if known, and we can explain the options for preparing a separate work account.

1. Confidentiality

Non-public source code, operational details, customer information and configuration data encountered during an engagement are handled only as needed for the requested work. We can discuss an NDA before sensitive information or access is shared.

2. Least-privilege access

Where possible, please create a temporary or dedicated account rather than share your everyday administrator login.

  • Use separate work accounts
  • Limit access to the required systems and repositories
  • Avoid unnecessary administrator permissions
  • Remove temporary access after the engagement

3. Setting up access

For EC-CUBE, AWS, hosting platforms or GitHub, the method depends on the service. Tell us the service name or what the management screen shows, and we can suggest appropriate access preparation steps. We do not routinely ask you to email the main account password.

4. Passwords and secrets

Please do not include passwords, private keys, API keys or other credentials in ordinary email messages or in source-code repositories. We will agree on a suitable sharing method if access is necessary.

5. Production changes

Changes affecting live systems are made after considering scope, verification and where appropriate backups or recovery paths. Unexpected situations may lead us to stop and report before proceeding.

6. Handling code and data

Client material is not repurposed for unrelated work or another client's engagement. Unnecessary temporary copies are not retained longer than required, and confidential client details are not disclosed to external services without permission.

7. Use of AI

AI tools may assist with research, structuring information and documentation. Credentials and confidential client-specific data are not provided to external AI services without permission. River Leaf Direct remains responsible for final review and important production decisions.

8. After the engagement

Temporary permissions and work accounts should be disabled or removed. We can help identify which access needs to be revoked.

9. What to send first

Simply describe what is happening, the service involved (if known) and when the issue began. Please do not send credentials with the initial inquiry.

Get in touch