Skip to main content

Security & access model

Engagement access, designed the way your security team would design it

Least privilege, customer-controlled credentials, logged use and confirmed removal at handover. This page sets out the access model in full — the same terms your reviewers will find in the written scope and the evidence pack.

Equally, what we do not claim: no certification, no compliance attestation and no security guarantee. Overstated security claims are themselves a security problem.

Principles

The rules every engagement runs under

These are not aspirations; they are the working defaults of every engagement, from a single audit to an enterprise pilot, and they are reflected in the written scope before you pay.

Least privilege, always

We request the minimum access the agreed scope requires — typically repository read access for audits and branch-level write access for implementation work. Broad or standing access is never a prerequisite.

Customer-controlled credentials

Access is granted through credentials you issue, scope and can revoke at any time. We never ask you to hand over personal accounts, shared passwords or long-lived secrets.

No production access unless required and authorised

Our default is no production access. Where the written scope genuinely requires it, access must be explicitly authorised, time-bound, least-privilege and logged.

Secret handling

Audit inputs should have secrets redacted — we do not need live credentials to assess code and configuration. Any secret we do encounter is not copied, stored or transmitted, and we tell you so it can be rotated.

Logging and deletion

Engagement materials are kept only for the engagement and the agreed retention window for supporting deliverables. At handover, access is removed and working copies of your material are deleted on request, with confirmation.

Subcontractor disclosure

EcoCitizenz may use appropriately vetted specialists or subcontractors to support delivery. EcoCitizenz remains responsible for the agreed deliverables. Any specialist access to customer systems or confidential information is disclosed and governed by the engagement terms.

Responsible limitations

We do not provide certification, compliance attestation or security guarantees, and we say so rather than imply otherwise. Deliverables give your reviewers evidence to evaluate — they do not replace your own security judgement.

Access lifecycle

From first request to confirmed removal

Access follows the same five-step lifecycle in every engagement. At no point do we hold access you did not grant, and at no point does access outlive the engagement.

  1. Request

    We request the minimum access the agreed written scope requires — typically repository read access for audits, branch-level write access for implementation work. The request itself is part of the written scope, so you can review it before granting anything.

  2. Customer grants

    Access arrives through credentials you issue, you scope and you can revoke at any time. We never ask for personal accounts, shared passwords or long-lived secrets.

  3. Use

    Access is used for the engagement and nothing else. Where production access is genuinely required and authorised in writing, it is time-bound, least-privilege and logged.

  4. Removal at handover

    When the engagement ends, the access granted for it is removed — and because the credentials are yours, you can also revoke them yourself at any point without asking us.

  5. Confirmation

    Removal is confirmed to you and recorded in the security and access record of your Production Evidence Pack, so your reviewers can see what was granted, how it was used and when it ended.

Scanner privacy

The free scanner is built to the same standard

The readiness scanner analyses pasted configuration locally, in your browser. The privacy position is simple enough to state in three sentences — and we do.

  • Configuration analysis runs locally in your browser. Pasted content is not transmitted, logged or retained by EcoCitizenz.
  • Analytics records only that a scan ran and the count of findings by severity — never the content of what you scanned.
  • If you download the report, the file is generated in your browser and saved directly to your device.

Run the free MCP scanner — no account, no upload, no sales gate.

System boundaries

Each EcoCitizenz system has one job — and stays inside it

Security reviews care as much about what a system cannot do as what it can. These boundaries are deliberate, published and consistent across the EcoCitizenz estate.

Websites explain. TrustOps operates. Backend truth decides. Resolver proves.

This website

Explains, compares and sells professional services. It never creates, amends or proves authoritative ECZ-ID state — no page, payment or badge here changes canonical records.

TrustOps

Handles checkout, intake and the customer lifecycle. TrustOps is authoritative for order and payment status — this site hands off to it and holds no payment state of its own.

ECZ-ID backend & Resolver

Canonical ECZ-ID state is written only by the ECZ-ID backend. The public Resolver is a read-only projection of proof — it verifies, it never creates.

This website explains and sells professional services. Checkout, intake and payment status are handled by TrustOps. Canonical ECZ-ID state is held by the ECZ-ID backend; the public Resolver is a read-only projection of proof. Nothing on this site — including payment — creates or amends authoritative ECZ-ID state.

Responsible limitations

What we deliberately do not claim

Overstated security claims are themselves a security problem. So we are explicit about the limits of what these services provide, and we would rather lose a sale than blur them.

We do not certify

An engagement does not certify your implementation, and no deliverable should be presented as a certificate. Microsoft operates an MCP server certification process for its own surfaces; EcoCitizenz is independent, does not act for Microsoft, and does not issue or decide Microsoft certification. We prepare you for it — Microsoft alone decides the outcome.

No compliance attestation

We do not attest to compliance with any regulation, standard or framework. Where deliverables are useful to a compliance process, they are inputs your own assessors evaluate.

No security guarantee

No review can guarantee the absence of vulnerabilities, and we do not pretend otherwise. Each deliverable states what was examined and what was not, so nobody relies on coverage that was never claimed.

What you do get is evidence — scope, findings, test records, access history and stated limitations — structured so your engineering, security and procurement reviewers can apply their own judgement to it. The judgement remains yours; our job is to make it well informed.

Subcontractor disclosure

EcoCitizenz may use appropriately vetted specialists or subcontractors to support delivery. EcoCitizenz remains responsible for the agreed deliverables. Any specialist access to customer systems or confidential information will be disclosed and governed by the engagement terms.

Put this model to work on your implementation

Tell us about your implementation and we will confirm — in writing — exactly what access a given service needs before you commit. The enterprise route asks for the security and procurement detail in one pass. Or go straight to the fixed-scope services and published prices.

Your delivery schedule is confirmed during intake.