How we access your code and servers.
Six rules and a stage-by-stage access table, written to be handed to your IT reviewer or insurer before you share anything. It applies to every PHP & Laravel upgrade, Assessment and care plan we run.
What we commit to before you share anything
- Rule 01
Least privilege
Each stage gets the minimum access it needs and no more; production only at cutover and only for the window.
- Rule 02
Secrets never travel by chat or email
Credentials arrive through a password manager share or your own secrets store. Anything sent another way is rotated on receipt.
- Rule 03
Production data stays on your infrastructure
Staging runs on servers you own or in your cloud account. Database copies used for testing stay there; personal data is masked when the data class calls for it.
- Rule 04
MFA and encrypted devices
Every account we use has multi-factor authentication; every device is full-disk encrypted with a screen lock.
- Rule 05
Every access logged and revoked at handover
The access log is a deliverable in the handover pack. Our users, keys and tokens are removed when the project ends.
- Rule 06
Incidents reported in writing within 24 hours
Anything that could affect your data or availability — ours or yours — is written up and sent to you within a day, with what happened and what we changed.
What we ask for, when, and what we do with it
| Stage | Access we ask for | What we do | What you control |
|---|---|---|---|
| Assessment | Read-only repository access or a zip; environment description; test login; optional read-only server session. | Read. Nothing is committed, deployed or changed. Copies are deleted at delivery unless you proceed. | Grant and revoke at will; the report is yours. |
| Upgrade — staging | Write access to a branch; a staging server you host (or one we provision in your cloud account); a staging copy of the database with production data masked where required. | All work on staging. Tests, dry-runs and your UAT happen here. Secrets via your password manager or secrets store. | Sign off on staging in writing before anything reaches production. |
| Cutover | Time-boxed production access in your low-traffic window, with the rollback plan approved beforehand. | Execute the rehearsed runbook; smoke-test; hand back. Access ends when the rollback window closes. | Present or reachable during the window; you approve the go/no-go. |
| Warranty & handover | Staging access only, unless a regression requires a production fix — then as at cutover. | Fix regressions; deliver the handover pack; rotate credentials we held; remove our users and keys. | Receive the access log — who had what, from when to when. |
| Care plan | Deploy access to staging and production under a named user, MFA enforced, logged. | Monthly updates through staging; production changes only after tests pass; monthly note; quarterly report. | Revoke any time; the term ends with a clean handover. |
The six rules, for your reviewer's checklist
Least privilege
Read-only for the Assessment; staging-only for the upgrade; production only at cutover.
Secrets never travel by chat or email
Credentials are shared through a password manager or your own secrets store, and rotated at handover.
Production data stays on your infrastructure
We work on staging copies you host. No production database leaves your servers.
MFA and encrypted devices
Every account we use has MFA; every device is full-disk encrypted.
Every access logged and revoked at handover
The access log is part of the handover pack — who had what, from when to when.
Incidents reported in writing within 24 hours
Anything that could affect your data or availability is written up and sent to you within a day.
- Legal entity
- Techimpace Innovations Private Limited
- Registered office
- RBC Road, Lakurdi, Purba Barddhaman 713102, West Bengal, India
- Company-wide policies
- Security · Trust Center · Privacy
Start with a written Assessment.
3–5 working days. A fixed price for the upgrade, a list of what could break, and how we'll prevent it.