Delivery kit

Security checklist — [CLIENT] / [PROJECT]

Last changed 2026-08-17 · all documents · security & deployment

Copy this file into the project folder at kickoff. Tick as you go, and where the project differs from baseline-runbook.md, write the delta and the reason. An untick with a reason is fine; an untick with no reason is not.

Tier: 1 / 2 / 2.5 / self-hosted Client contact (security questions): Personal data involved: yes / no — if yes, DPA signed on: [DATE] Started: [DATE] Delivered: [DATE] Handed over: [DATE]

Kickoff

Build

Before delivery

Handover

Recorded values

ItemValue
Compute region (configured)
Storage region (configured)
Vault used
Credential owner (app registration / service account)
Repo location
Backup location
Restore test date

Deltas from the baseline

#Baseline itemWhat I did insteadWhyAgreed with

Open risks accepted by the client

RiskWhy not fixedAccepted byDate