The Standard / Security

The system should fail in contained, recoverable ways.

Access, payments, secrets, and backups each need a boundary you can understand without a glossary.

Most small-business sites are not attacked by anyone sophisticated. They are compromised through an abandoned plugin, a password in an email thread, or a shared login that three former contractors still have. The defences that matter are boring and operational rather than clever.

Access

You own every account. I hold the access needed to do the work and no more. Credentials live in a password manager rather than in email, notes, or a spreadsheet, and secrets never enter the code repository. When someone stops needing access, it gets removed rather than forgotten.

Anything with a login

Sessions are signed and verified on the server. A cookie is never trusted just because it names a user, which is the specific mistake behind a large share of real breaches in small applications. Every application table enforces access rules at the database level, so one customer cannot reach another customer's records even if a bug in the application would otherwise allow it.

Administrative areas are blocked from search engines and are not linked from public pages.

Payments

Card details never touch your site or mine. Stripe collects and stores them on its own PCI compliant systems, and payouts go directly to your bank account from an account in your name. If my systems were compromised tomorrow, no customer card data would be in them, because none of it was ever there.

Recovery

Your database is backed up and your content is recoverable. The site is hosted on infrastructure that fails over rather than sitting on one machine under someone's desk. Deployments can be rolled back, so a bad change is minutes of disruption rather than a rebuild.

The part most plans leave out is who does it. That is me, and the monthly report says when something happened and what I did about it.

excerpt from a real client artifact, redacted

Security review

Customer table | Row-level security enabled | Policies tested by role

Sessions | Signed and server-verified | Tampered token rejected

Payments | Processor-hosted collection | No card data stored

Secrets | Vaulted environment values | Repository scan clean

Recovery | Backup present | Rollback owner named