If we're checking whether you truly control your systems, the least we can do is model good access hygiene ourselves. Here's exactly how we work.
We ask for a named viewer account created just for us — never a shared login. Where a service genuinely needs more, we tell you why before you grant it.
Ever. If a step needs credentials, you keep them — you run it and send us the output. If anyone asks you to paste a password into a form or email, that alone is a red flag worth heeding.
When a check needs an admin-level command, we give you the exact command to run and you paste back the result. You see everything that happens on your systems, because you're the one doing it.
Working copies of anything you send are kept for 30 days after delivery, then deleted. Your finished deliverables we keep indefinitely so we can help you later — and you can ask us to delete those too, at any time.
At delivery, you revoke our access. We'll send you a reminder to do exactly that — a good habit, and one we'd rather prompt than skip.