Security & access model
Engagement access, designed the way your security team would design it
Least privilege, customer-controlled credentials, logged use and confirmed removal at handover. This page sets out the access model in full — the same terms your reviewers will find in the written scope and the evidence pack.
Equally, what we do not claim: no certification, no compliance attestation and no security guarantee. Overstated security claims are themselves a security problem.
Principles
The rules every engagement runs under
These are not aspirations; they are the working defaults of every engagement, from a single audit to an enterprise pilot, and they are reflected in the written scope before you pay.
Least privilege, always
We request the minimum access the agreed scope requires — typically repository read access for audits and branch-level write access for implementation work. Broad or standing access is never a prerequisite.
Customer-controlled credentials
Access is granted through credentials you issue, scope and can revoke at any time. We never ask you to hand over personal accounts, shared passwords or long-lived secrets.
No production access unless required and authorised
Our default is no production access. Where the written scope genuinely requires it, access must be explicitly authorised, time-bound, least-privilege and logged.
Secret handling
Audit inputs should have secrets redacted — we do not need live credentials to assess code and configuration. Any secret we do encounter is not copied, stored or transmitted, and we tell you so it can be rotated.
Logging and deletion
Engagement materials are kept only for the engagement and the agreed retention window for supporting deliverables. At handover, access is removed and working copies of your material are deleted on request, with confirmation.
Subcontractor disclosure
EcoCitizenz may use appropriately vetted specialists or subcontractors to support delivery. EcoCitizenz remains responsible for the agreed deliverables. Any specialist access to customer systems or confidential information is disclosed and governed by the engagement terms.
Responsible limitations
We do not provide certification, compliance attestation or security guarantees, and we say so rather than imply otherwise. Deliverables give your reviewers evidence to evaluate — they do not replace your own security judgement.
Access lifecycle
From first request to confirmed removal
Access follows the same five-step lifecycle in every engagement. At no point do we hold access you did not grant, and at no point does access outlive the engagement.
Request
We request the minimum access the agreed written scope requires — typically repository read access for audits, branch-level write access for implementation work. The request itself is part of the written scope, so you can review it before granting anything.
Customer grants
Access arrives through credentials you issue, you scope and you can revoke at any time. We never ask for personal accounts, shared passwords or long-lived secrets.
Use
Access is used for the engagement and nothing else. Where production access is genuinely required and authorised in writing, it is time-bound, least-privilege and logged.
Removal at handover
When the engagement ends, the access granted for it is removed — and because the credentials are yours, you can also revoke them yourself at any point without asking us.
Confirmation
Removal is confirmed to you and recorded in the security and access record of your Production Evidence Pack, so your reviewers can see what was granted, how it was used and when it ended.
Scanner privacy
The free scanner is built to the same standard
The readiness scanner analyses pasted configuration locally, in your browser. The privacy position is simple enough to state in three sentences — and we do.
- Configuration analysis runs locally in your browser. Pasted content is not transmitted, logged or retained by EcoCitizenz.
- Analytics records only that a scan ran and the count of findings by severity — never the content of what you scanned.
- If you download the report, the file is generated in your browser and saved directly to your device.
Run the free MCP scanner — no account, no upload, no sales gate.
System boundaries
Each EcoCitizenz system has one job — and stays inside it
Security reviews care as much about what a system cannot do as what it can. These boundaries are deliberate, published and consistent across the EcoCitizenz estate.
Websites explain. TrustOps operates. Backend truth decides. Resolver proves.
This website
Explains, compares and sells professional services. It never creates, amends or proves authoritative ECZ-ID state — no page, payment or badge here changes canonical records.
TrustOps
Handles checkout, intake and the customer lifecycle. TrustOps is authoritative for order and payment status — this site hands off to it and holds no payment state of its own.
ECZ-ID backend & Resolver
Canonical ECZ-ID state is written only by the ECZ-ID backend. The public Resolver is a read-only projection of proof — it verifies, it never creates.
This website explains and sells professional services. Checkout, intake and payment status are handled by TrustOps. Canonical ECZ-ID state is held by the ECZ-ID backend; the public Resolver is a read-only projection of proof. Nothing on this site — including payment — creates or amends authoritative ECZ-ID state.
Responsible limitations
What we deliberately do not claim
Overstated security claims are themselves a security problem. So we are explicit about the limits of what these services provide, and we would rather lose a sale than blur them.
We do not certify
An engagement does not certify your implementation, and no deliverable should be presented as a certificate. Microsoft operates an MCP server certification process for its own surfaces; EcoCitizenz is independent, does not act for Microsoft, and does not issue or decide Microsoft certification. We prepare you for it — Microsoft alone decides the outcome.
No compliance attestation
We do not attest to compliance with any regulation, standard or framework. Where deliverables are useful to a compliance process, they are inputs your own assessors evaluate.
No security guarantee
No review can guarantee the absence of vulnerabilities, and we do not pretend otherwise. Each deliverable states what was examined and what was not, so nobody relies on coverage that was never claimed.
What you do get is evidence — scope, findings, test records, access history and stated limitations — structured so your engineering, security and procurement reviewers can apply their own judgement to it. The judgement remains yours; our job is to make it well informed.
Subcontractor disclosure
EcoCitizenz may use appropriately vetted specialists or subcontractors to support delivery. EcoCitizenz remains responsible for the agreed deliverables. Any specialist access to customer systems or confidential information will be disclosed and governed by the engagement terms.
Put this model to work on your implementation
Tell us about your implementation and we will confirm — in writing — exactly what access a given service needs before you commit. The enterprise route asks for the security and procurement detail in one pass. Or go straight to the fixed-scope services and published prices.
Your delivery schedule is confirmed during intake.