Skip to content
Techimpace
Security & access policy

How we access your code and servers.

Six rules and a stage-by-stage access table, written to be handed to your IT reviewer or insurer before you share anything. It applies to every PHP & Laravel upgrade, Assessment and care plan we run.

Sheet 01Six rules

What we commit to before you share anything

  1. Rule 01

    Least privilege

    Each stage gets the minimum access it needs and no more; production only at cutover and only for the window.

  2. Rule 02

    Secrets never travel by chat or email

    Credentials arrive through a password manager share or your own secrets store. Anything sent another way is rotated on receipt.

  3. Rule 03

    Production data stays on your infrastructure

    Staging runs on servers you own or in your cloud account. Database copies used for testing stay there; personal data is masked when the data class calls for it.

  4. Rule 04

    MFA and encrypted devices

    Every account we use has multi-factor authentication; every device is full-disk encrypted with a screen lock.

  5. Rule 05

    Every access logged and revoked at handover

    The access log is a deliverable in the handover pack. Our users, keys and tokens are removed when the project ends.

  6. Rule 06

    Incidents reported in writing within 24 hours

    Anything that could affect your data or availability — ours or yours — is written up and sent to you within a day, with what happened and what we changed.

Sheet 02Access by stage

What we ask for, when, and what we do with it

Access policy · by stage
StageAccess we ask forWhat we doWhat you control
AssessmentRead-only repository access or a zip; environment description; test login; optional read-only server session.Read. Nothing is committed, deployed or changed. Copies are deleted at delivery unless you proceed.Grant and revoke at will; the report is yours.
Upgrade — stagingWrite access to a branch; a staging server you host (or one we provision in your cloud account); a staging copy of the database with production data masked where required.All work on staging. Tests, dry-runs and your UAT happen here. Secrets via your password manager or secrets store.Sign off on staging in writing before anything reaches production.
CutoverTime-boxed production access in your low-traffic window, with the rollback plan approved beforehand.Execute the rehearsed runbook; smoke-test; hand back. Access ends when the rollback window closes.Present or reachable during the window; you approve the go/no-go.
Warranty & handoverStaging access only, unless a regression requires a production fix — then as at cutover.Fix regressions; deliver the handover pack; rotate credentials we held; remove our users and keys.Receive the access log — who had what, from when to when.
Care planDeploy access to staging and production under a named user, MFA enforced, logged.Monthly updates through staging; production changes only after tests pass; monthly note; quarterly report.Revoke any time; the term ends with a clean handover.
Sheet 03At a glance

The six rules, for your reviewer's checklist

  • Least privilege

    Read-only for the Assessment; staging-only for the upgrade; production only at cutover.

  • Secrets never travel by chat or email

    Credentials are shared through a password manager or your own secrets store, and rotated at handover.

  • Production data stays on your infrastructure

    We work on staging copies you host. No production database leaves your servers.

  • MFA and encrypted devices

    Every account we use has MFA; every device is full-disk encrypted.

  • Every access logged and revoked at handover

    The access log is part of the handover pack — who had what, from when to when.

  • Incidents reported in writing within 24 hours

    Anything that could affect your data or availability is written up and sent to you within a day.

Legal entity
Techimpace Innovations Private Limited
Registered office
RBC Road, Lakurdi, Purba Barddhaman 713102, West Bengal, India
Company-wide policies
Security · Trust Center · Privacy
Next step

Start with a written Assessment.

3–5 working days. A fixed price for the upgrade, a list of what could break, and how we'll prevent it.

Request an Assessment — $950