These are the working documents behind the security & deployment page — the runbook I apply on every engagement, the annex for each delivery shape, and the templates you actually receive and countersign.
They are published for one reason: with no client list to point at, a claim about process is worth very little unless you can read the process. Every client-specific field is a placeholder. No real client data appears anywhere in them.
If something here is weaker than your own standard, that is worth a conversation before we start rather than after — and if you need a certified supplier, I am not one, and I would rather say so here.
The posture
- Security baseline runbookWhat I do on every engagement, mapped loosely to the ISO 27001 Annex A themes so you can cross-reference it.
Per delivery shape
- Annex — Tier 1: self-contained HTML dashboardsThe self-contained file: what goes inside it, escaping, bundled dependencies, and what the file reader changes.
- Annex — Tier 2 / 2.5: hosted pipelinesScheduled pipelines on Microsoft — where the code runs, scopes, vault, backup and restore, monitoring.
- Annex — Tier 2 on Google WorkspaceThe same on Google Workspace: one shared folder rather than domain-wide delegation, Secret Manager, Apps Script or Cloud Run.
- Annex — Self-hosted: VPS hardeningVPS hardening for the case I argue against needing: SSH keys only, a firewall, automatic patching, fail2ban, and who owns patching after handover.
What you receive
- Security checklist — [CLIENT] / [PROJECT]Copied into every project at kickoff. An untick with a reason is fine; an untick with no reason is not.
- Access register — [CLIENT] / [PROJECT]Every credential I hold on a client project, and the date each one was revoked and verified locked out. An open row at handover blocks sign-off.
- Data flow — [CLIENT] / [PROJECT]One picture of source, processing, storage and viewers, agreed before anything is built — with filled examples on Microsoft and Google Workspace.
- Incident plan — [CLIENT] / [PROJECT]Filled in per project, walked through once at kickoff — not read for the first time during an incident.
- Handover — [CLIENT] / [PROJECT]The engagement is not finished when the dashboard works. It is finished when you own everything and I hold nothing.
- DPA notes — what a data processing agreement needsHow I read a DPA you hand me: the clauses an EU controller-to-processor agreement needs, and the red flags. Contains no legal text on purpose.
- Article 30 registerMy own GDPR Article 30 record of processing, published in full: each data category, purpose, location, retention, legal basis, subprocessor and transfer.