Security, data ownership and what happens if we part ways
Written so your compliance reviewer can sign it off without a phone call. If something here does not meet your policy, tell us and we will tell you honestly whether we can meet it.
You own everything, from day one
- Source code is yours, delivered to a repository you control.
- The database and all data in it are yours. We hold no copy after handover unless you ask us to for support purposes.
- Hosting, domain, DNS and email credentials are registered in your name, not ours.
- Brand vector files, design sources and documentation are handed over as standard.
- No licence keys, no per-seat fees on your own system, and nothing withheld to create leverage at renewal.
Access control
- Least privilege by default. Every role is scoped to the records it needs and no others.
- Named accounts only. No shared logins, no generic admin account passed around a team.
- Our access to your production environment is time-limited and removable by you at any point.
- Administrative and financial writes are logged with the user, timestamp and before/after state.
How systems are built
- Server-side validation on every input. Client-side checks are treated as a convenience, never as a control.
- Parameterised queries throughout. No string-concatenated SQL.
- CSRF protection on every state-changing request, and rate limiting on public endpoints.
- Secrets in environment configuration, never committed to the repository.
- Dependencies pinned, and reviewed before an update reaches production.
Backups and recovery
- Automated daily database backups with a defined retention window.
- Backups are verified by performing an actual restore, not by confirming a file exists. An untested backup is not a backup.
- Restore procedure documented in the runbook and rehearsed before go-live.
- Recovery point and recovery time objectives agreed in writing as part of the support agreement.
AI and your data
- We do not send personal or commercially sensitive data to a third-party model without your explicit, documented consent.
- Where an AI feature processes customer records, the data flow is documented and you approve it before launch.
- Every agent has an audit trail of what it did, a defined failure behaviour, and a hard cost ceiling.
- Anything that commits money, sends an external message or changes a record requires human approval by default.
Data residency and sub-processors
- Your data lives on infrastructure you own and can inspect. We can work within existing hosting and residency constraints.
- Any third-party service in the data path - email delivery, payment gateway, model provider - is named and disclosed before it is introduced.
- We will not add a sub-processor to a live system without telling you first.
Incidents
- You get a named engineer and a defined response target, agreed in the support agreement rather than implied.
- If we cause an outage we say so, in writing, with what happened and what changed as a result.
- Post-incident notes are shared with you rather than kept internal.
If you leave
- A documented handover: repository access, database export, credentials, architecture notes and runbook.
- A paid transition period if your incoming team wants one, at standard rates and with no exit penalty.
- We remove our access on request and confirm in writing when it is done.
Support service levels
Response targets under an active support agreement, measured in business hours from acknowledgement. These are the targets we commit to in writing rather than the ones we hope for.
| Severity | Definition | Response target | Update cadence |
|---|---|---|---|
| S1 - Down | System unavailable, or financial data at risk. No workaround. | 1 business hour | Hourly until resolved |
| S2 - Degraded | A core function is broken but the business can continue with a workaround. | 4 business hours | Daily |
| S3 - Defect | Something is wrong but not blocking. Cosmetic or edge-case. | 2 business days | Weekly |
| S4 - Change | New functionality or an enhancement request. | 5 business days to scope | At scoping |
Response target means a named engineer has picked it up and told you what is happening. It is not a resolution time, because promising a fix time before diagnosis is not a commitment anyone can keep honestly.
Editor note, visible only to you: Read every line above against what you actually do today, and delete anything you cannot evidence. A security page that overstates practice is worse than no security page, because it is the document a client will hold you to. Where a line is aspirational, make it true first.
The questions that decide the deal
Cost, timeline, ownership and what happens when something breaks. Answered here so the first call can be about your business instead.
What does a custom ERP or CRM build actually cost?
Cost tracks scope, not seats. A focused CRM or a single-department system starts materially lower than a multi-module ERP with a double-entry ledger and multi-branch reporting. After a 30-minute scoping call we send a written fixed price range with the module breakdown behind it, and that range does not move unless the scope moves.
We will also tell you when off-the-shelf software is the cheaper answer. Recommending a custom build that should not exist is the most expensive mistake in this category, and it is ours to avoid rather than yours to discover.
How long before we have something we can use?
You get working software you can log into early, not at the end. Discovery and design usually take one to two weeks, after which delivery runs module by module so each piece can be tested and accepted as it lands.
A focused system is typically live in six to twelve weeks. A full multi-module ERP runs three to nine months to complete, but the first usable modules arrive long before that. There is no six-week silence where you wonder what is happening.
We already have a system. Do we have to replace it?
Usually not, and we have no incentive to say otherwise. The first step is an architecture and code review that tells you whether what you have can carry another two years of growth, what the security exposure is, and what the previous vendor left undocumented.
You get a written risk register with costs attached to each option: fix, replace or retain. Where the existing system is worth keeping, we say so and quote for the remediation instead of the rebuild.
Do we own the code and the data?
Yes, entirely, from day one. Source code, database, hosting credentials, brand vector files and documentation are handed over as a matter of course, not negotiated at the end.
There are no hostage licences, no per-seat fees on your own system, and nothing held back to create leverage at renewal. If you want to move the system to another provider, everything needed to do that is already in your possession.
What happens after launch?
Support is a defined agreement rather than goodwill. It covers monitoring, backups that are verified by actually performing a restore, response-time targets, and a named engineer who already knows your stack.
We also run quarterly reviews to look at what the system is doing in practice versus what it was designed to do, because usage patterns after twelve months are rarely the ones assumed at design time.
How do you handle security and our data?
Least-privilege roles, server-side input validation, complete audit trails on financial and administrative writes, and backups tested by restore rather than assumed to work. These are built in during development, not sold afterwards as a hardening phase.
Your data stays on infrastructure you control and own. We can work within your existing hosting, compliance requirements and data-residency constraints, and we will document exactly who has access to what.
Can you work alongside our in-house developers?
Regularly. That arrangement works best when the boundary is explicit: we take specific modules or the architecture, your team takes the rest, and the API contract between them is agreed and written down before either side starts building.
We document to the standard of someone else maintaining the code, because in this arrangement someone else does.
What if the project goes wrong, or you disappear?
Three structural answers rather than a reassurance. First, each stage has a written exit condition, so a project cannot drift quietly for months. Second, you hold the code, credentials and documentation throughout, so another team could pick it up. Third, every system ships with an ERD, a permission matrix and a runbook written for an engineer who has never seen it.
We also run systems of our own in production, which means we are not a project shop that can quietly stop answering the phone.
Ready to build your next digital solution?
Send the brief and you get a scoped response with approach, milestones and a fixed price range. Not a sales call.
A 30-minute call with the engineer who would run your project
Within 2 business daysA written scope: approach, module breakdown, milestones, fixed price range
Within 5 business daysYou decide. No retainer, no obligation, and the scope document is yours to keep either way
Your timelineSend your brief
Three fields to start. Add project details if you have them.
