How We Handle Your Credentials
How We Handle Your Credentials
During our engagement, you may need to share access credentials to various platforms — hosting dashboards, domain registrars, ad accounts, social media profiles, analytics tools, and content management systems. Here is how we handle them.
1. Minimal Access Principle
We only request access to the specific platforms and accounts required to deliver your project. We will never ask for unnecessary or unrelated credentials.
2. Secure Storage
All credentials you share with us are stored in an encrypted, password-protected vault. We use industry-standard tools (e.g., 1Password, Bitwarden, or similar) to store and share credentials. Credentials are never stored in plain text, email, or unsecured documents.
3. Limited Access
Only team members actively working on your project have access to your credentials. Access is revoked immediately when a team member finishes their work or leaves the project.
4. Recommended: Use Invite-Based Access
Whenever possible, we recommend granting access via platform-specific invite features (e.g., adding a team member to your Meta Business Manager, Google Analytics property, or hosting panel) rather than sharing a master password. This gives you full control over what we can access and allows you to revoke access instantly.
5. Credential Deletion
Upon project completion, we delete or securely transfer all credentials you have shared with us. We do not retain access to your platforms after the engagement ends unless we have an ongoing maintenance agreement.
6. Breach Notification
In the unlikely event of a security breach that affects your credentials, we will notify you immediately and provide full details of the incident, what was affected, and the steps we are taking to remediate.
7. Your Responsibility
While we take every precaution to protect your credentials, we recommend that you:
- Change passwords or revoke access after the engagement ends
- Use strong, unique passwords for each platform
- Enable two-factor authentication (2FA) on all accounts
- Review platform access logs periodically
8. Questions?
If you have any concerns about how we handle credentials, please reach out to us at:
[email protected]