SECURITY / CONFIDENTIALITY
Security starts with controlled access.
Before reviewing source code, servers, databases or settings, we agree on what access is needed and aim to use the minimum appropriate permissions.
1. Confidentiality
Non-public source code, operational details, customer information and configuration data encountered during an engagement are handled only as needed for the requested work. We can discuss an NDA before sensitive information or access is shared.
2. Least-privilege access
Where possible, please create a temporary or dedicated account rather than share your everyday administrator login.
- Use separate work accounts
- Limit access to the required systems and repositories
- Avoid unnecessary administrator permissions
- Remove temporary access after the engagement
3. Setting up access
For EC-CUBE, AWS, hosting platforms or GitHub, the method depends on the service. Tell us the service name or what the management screen shows, and we can suggest appropriate access preparation steps. We do not routinely ask you to email the main account password.
4. Passwords and secrets
Please do not include passwords, private keys, API keys or other credentials in ordinary email messages or in source-code repositories. We will agree on a suitable sharing method if access is necessary.
5. Production changes
Changes affecting live systems are made after considering scope, verification and where appropriate backups or recovery paths. Unexpected situations may lead us to stop and report before proceeding.
6. Handling code and data
Client material is not repurposed for unrelated work or another client's engagement. Unnecessary temporary copies are not retained longer than required, and confidential client details are not disclosed to external services without permission.
7. Use of AI
AI tools may assist with research, structuring information and documentation. Credentials and confidential client-specific data are not provided to external AI services without permission. River Leaf Direct remains responsible for final review and important production decisions.
8. After the engagement
Temporary permissions and work accounts should be disabled or removed. We can help identify which access needs to be revoked.
9. What to send first
Simply describe what is happening, the service involved (if known) and when the issue began. Please do not send credentials with the initial inquiry.