The Account-Ownership Rule

What You Own, Always

Where it's practical, you own the infrastructure and data. We get controlled access appropriate to our responsibilities, not ownership of the underlying account.

  • Domains
  • Cloud accounts
  • Primary software subscriptions
  • Code repositories
  • Production data
  • Analytics accounts
  • Certificates and keys
  • Administrative identities

Governance

What We Put in Place for Every Long-Term Engagement

  • A named executive sponsor on your side and a named engagement owner on ours
  • Clear decision rights and change control for the scope of work
  • Approved vendors and access reviewed on a set cadence
  • Confidentiality obligations that survive the end of the engagement
  • A defined incident and escalation path
  • Documentation requirements and acceptance criteria agreed upfront
  • Named benefit owners and measurement, tied back to the audit baseline
  • Termination and transition support, including handover of access and documentation

Confidentiality

Anything we see during an audit or engagement, your processes, your systems, your numbers, stays confidential, and that obligation doesn't end when the engagement does. If we ever want to reference an engagement publicly, as a case study or example, we ask first and only use what's been approved. For how we handle personal information specifically, see our Privacy Policy.