Security practices · How I handle access
What I do with access to your systems, and how you check it.
A one-person practice asks for logins to the tools your business runs on. This page says what happens with them. Every statement is either something you can check yourself or a commitment with the mechanism that enforces it written next to it.
- Person
- Nick Donatelli
- Legal entity
- Pending: Legal entity
- Business licence
- Pending: Business licence
- Professional liability (E&O)
- Pending: Professional liability (E&O)
- Cyber liability
- Pending: Cyber liability
- Background check
- Pending: Background check
01 Access model
01 No shared passwords
CommitmentI do not accept a password to an account that already exists.
MechanismYou create a user for me in each system. If a password arrives by email or chat anyway, I ask you to change it before I touch anything, and I say so in writing.
Check itOpen the user list in the system's admin console. My user is there under my name. No login is shared with me.
02 Named seat in your tenant
CommitmentEvery change I make is made by a user that belongs to your account, not to mine.
MechanismThe user is [email protected] invited into your workspace, or an address you issue on your own domain. Either way, you administer it: you can suspend it, reset it, and read its activity.
Check itOpen the audit log or activity history of the system. Each change shows my user and a timestamp.
03 Least privilege per system
CommitmentI ask for the lowest role that lets the agreed scope happen, and nothing outside the scope.
MechanismThe proposal carries an access table: one row per system with the role requested, why that role, who grants it, and the date it ends. A role not in the table needs a written OK from you before it is granted.
Check itCompare the role on my user with the row in the table. They match, or you have an email from me asking for the change.
04 You provision, you revoke
CommitmentNo access of mine outlives the engagement.
MechanismYou create every user and you remove every user. The handoff checklist has one line per system. When you have removed the last one, I reply with the date and the list, so both of us hold the record.
Check itThe user list after handoff, and the dated email.
The access table
Every proposal carries one. The rows below are an example, not a record of any engagement.
| System | Role requested | Why this role | Granted by | Ends |
|---|---|---|---|---|
| Work-management tool | Admin during build, then Member | Board structure and automations need admin; daily use does not | You, the workspace owner | Handoff date |
| Automation platform | Editor on one named workspace | Build and test the connectors in scope | You | Handoff date |
| Email / calendar | None | Not in scope | — | — |
| File storage | Viewer on one named folder | Read the documents the knowledge base is built from | You | Handoff date |
| AI assistant account | Builder role on your organisation's account | Configure the assistant on the account you own | You | Handoff date |
02 My accounts and my device
Second factor on every account
CommitmentEvery account of mine that supports a second factor has one turned on: email, password manager, hosting, scheduling, and any account of yours I am invited into.
MechanismPendingSecond factor
Check itOn the intro call, ask. I share my screen and open the security settings page of the account you name.
One password manager, nothing outside it
CommitmentAny credential I hold lives in a password manager and nowhere else: not in a spreadsheet, a note, a chat thread, or a browser's saved passwords.
MechanismPendingPassword manager
Check itOn the intro call, ask for the vault settings page: second factor on, the entry for your system dated the day you created it.
One work device
CommitmentClient work happens on one device, and that device is encrypted, locked, and current.
MechanismPendingWork device
Check itOn the intro call, ask for the disk-encryption and screen-lock settings pages.
03 Your data
Before an engagementThe booking form collects your name, your email, and the time of the call. That is all the site collects from you. Scheduling runs on Cal.com.
DuringThe proposal lists what I will read and what I will copy. Most work happens inside your accounts, in the browser, so most of your data never leaves them. Where I do take a working copy — an export to map before a migration, a document set to build a knowledge base from — the proposal names it.
AfterWorking copies on my device and in my accounts are deleted within Pending: Working copies deleted within days of handoff. You get a dated email listing what was deleted and what was kept. Kept: the signed proposal, the invoices, and the access-removal email.
Who else sees itNo one. There are no subcontractors, no assistants, no shared inbox. The services behind the practice itself: this site on Cloudflare Pages, static, with a strict Content-Security-Policy and HSTS, and Cal.com for booking.
04 AI systems built for you
The assistant runs on your account
CommitmentAn assistant I build for you runs on an account your company owns, under your company's terms with that vendor — never on mine, and never on a consumer plan.
MechanismThe proposal names the vendor, the plan, the account owner, and the workspace. You create the account; I am invited into it under the access table.
Check itThe billing owner on the vendor's admin page is you.
It reads only what the proposal names
CommitmentThe assistant's sources are the documents and systems listed in the proposal, and no others.
MechanismEach source is connected under your account, so the connection list is yours to read and yours to cut.
Check itCompare the assistant's connected sources with the list in the proposal.
Your data does not train anyone's model without your say
CommitmentI set the vendor's training and retention controls to the most restrictive setting the plan offers, and I write down which setting that is.
MechanismThe handoff document records the setting, the page it lives on, and the date it was set.
Check itOpen that page in your admin console.
My own use of AI tools
CommitmentWhile working for you, I do not paste your data into an AI account you do not own.
MechanismDrafting and analysis with an AI tool happens either inside the account you own, or with your data replaced by placeholders.
Check itThis is a commitment, and it is a term in the proposal. If you want it in your NDA as well, say so.
05 If something goes wrong
An incident means any of these: my device is lost or stolen; I suspect an account of mine or a user of mine in your systems has been used by someone else; I send your data to the wrong place; I make a change that exposes data to people who should not see it.
NoticeYou hear from me within Pending: Incident notice within hours of my knowing, by phone and by email, to the contact named in the proposal.
ContainmentI ask you to suspend my user in the affected system while we look. You can do that yourself, at once, because you own the user.
ReportA written report within Pending: Written incident report within business days: what happened, what was touched, what changed, and what I am changing in how I work.
RecordBoth figures are terms in the proposal. If we never need them, they still stand.
06 In the contract
Everything on this page that is a commitment appears in the proposal as a term, so it binds me whether or not you ever read this page.
| Term | Where it lives | How you check it |
|---|---|---|
| Mutual NDA | Yours, or mine at Pending: Mutual NDA | The signed copy |
| Access table | The proposal, one row per system | Compare with the user list |
| Named users, no shared passwords | The proposal | Your admin console |
| Incident notice within Pending: Incident notice within hours; written report within Pending: Written incident report within business days | The proposal | The proposal |
| Working copies deleted within Pending: Working copies deleted within days of handoff | The proposal | The dated deletion email |
| No subcontractors without written OK | The proposal | The access table has one name on it |
| Certificate of insurance on request within Pending: Certificate of insurance delivered within business days | Standing offer | Ask for one |
| Written answers to your security questionnaire within Pending: Security questionnaire answered within business days | Standing offer | Send one |
What I do not have
No SOC 2 report. No ISO 27001 certificate. No penetration test of my own systems. Those audits examine an organisation's controls over a period; here the controls are the settings on one person's accounts and one device, and you can look at those directly: ask on the intro call and I share the screen. If your procurement rules require one of those reports from every vendor, this practice is not the right vendor for that scope, and I say so on the intro call rather than after the proposal.
07 Credentials
Each row names how you check it. A row marked pending is not yet true or not yet confirmed; it stays a marker until it is.
| Item | Value | How you check it |
|---|---|---|
| Person | Nick Donatelli Verified 2026-09-14 | Same name on the intro call, on the proposal, and on every invoice. |
| Based in | San Marcos, California Verified 2026-09-14 | Matches the Person record in the site's structured data (view source on any page). |
| Pending: LinkedIn | Public profile URL. Work history on the profile should match the practice history stated on this page. | |
| Contact | [email protected] Verified 2026-09-14 | Domain matches the site. Send a message; the reply comes from the same domain. |
| Item | Value | How you check it |
|---|---|---|
| Legal entity | Pending: Legal entity | Entity name and type as registered. For an LLC or corporation: California Secretary of State business search (bizfileonline.sos.ca.gov). For a sole proprietorship: the fictitious business name filing with the San Diego County Recorder. |
| Business licence | Pending: Business licence | Licence number and issuing city. Check with the issuing city's business licence lookup or by phone to its finance department. |
| Issued by | Pending: Issued by | Named issuing authority. |
| Licence valid through | Pending: Licence valid through | Expiry date printed on the licence. |
| Practice since | Pending: Practice since | Year the practice first invoiced under this name. Should agree with the entity filing date and the LinkedIn history. |
| Item | Value | How you check it |
|---|---|---|
| Carrier | Pending: Carrier | Carrier name and AM Best rating are printed on the certificate of insurance. |
| General liability | Pending: General liability | Per-occurrence and aggregate limits on the certificate of insurance. |
| Professional liability (E&O) | Pending: Professional liability (E&O) | Per-claim and aggregate limits on the certificate of insurance. |
| Cyber liability | Pending: Cyber liability | Limit and whether third-party (client) losses are covered, on the certificate of insurance. |
| Policy period | Pending: Policy period | Effective and expiry dates on the certificate of insurance. |
| Certificate of insurance delivered within | Pending: Certificate of insurance delivered within | Ask for one. The date on the certificate and the date of your request are the check. |
| Item | Value | How you check it |
|---|---|---|
| Background check provider | Pending: Background check provider | Provider name. The client can ask for the report summary, or run its own check through its own provider at its own cost; consent is given in writing. |
| Background check | Pending: Background check | Report date printed on the summary. |
| Background check scope | Pending: Background check scope | Listed on the report summary. |
| Item | Value | How you check it |
|---|---|---|
| References available | Pending: References available | Ask. Each reference is a named person at a past client, introduced by email, who agreed in advance to take the call. |
| Engagements completed | Pending: Engagements completed | Count of fixed-price engagements delivered and closed. Each has a signed proposal and a dated access-removal confirmation on file; a prospect can ask to see a redacted one. |
| Mutual NDA | Pending: Mutual NDA | Read it before the intro call. Send redlines by email; the signed copy is the one that governs. |
| Item | Value | How you check it |
|---|---|---|
| Password manager | Pending: Password manager | On the intro call, on request: a screen-share of the vault settings page showing the second factor enabled. |
| Second factor | Pending: Second factor | On the intro call, on request: a screen-share of the security page of the practice's email and password-manager accounts. |
| Work device | Pending: Work device | On the intro call, on request: a screen-share of the disk-encryption and screen-lock settings. |
| This site | Cloudflare Pages, static, with a strict Content-Security-Policy and HSTS Verified 2026-09-14 | Run curl -I https://donatelli.tech and read the content-security-policy and strict-transport-security headers. |
| Scheduling | Cal.com Verified 2026-09-14 | The booking page at /book/ frames cal.com/donatelli.tech. |
| Item | Value | How you check it |
|---|---|---|
| Security questionnaire answered within | Pending: Security questionnaire answered within | Send one. The dates on the email thread are the check. |
| Incident notice within | Pending: Incident notice within | Written into the proposal as a term. The proposal is the check. |
| Written incident report within | Pending: Written incident report within | Written into the proposal as a term. |
| Working copies deleted within | Pending: Working copies deleted within | You get a dated email listing what was deleted and what was kept (the signed proposal, the invoices, and the access-removal email). That email is the check. |
| Item | Value | How you check it |
|---|---|---|
| Last reviewed | Verified 2026-09-14 | Printed at the foot of the page. Every change to a row in this table is a dated entry in the registry file behind the page; ask by email and I send the change log. |
08 The questions people do not ask out loud
Why would I let a one-person shop into my systems?
Because the access is yours, not mine. You create the user, you set its role, you remove it. One named person appears in your audit log, not a rotating team you have never met. What you give up compared with a firm is redundancy, and the next answer covers that.
What happens if you disappear mid-engagement?
Nothing stops working. The build lives in your accounts under your logins from the first day, and every stage ends with written documentation and a fix-it guide. To check this, remove my user the day after handoff and run the system for a week. Nothing should change.
Do you have a SOC 2 report or ISO 27001 certificate?
No. Those audits examine an organisation's controls over a period; here the controls are the settings on one person's accounts and one device, and you can look at those directly. Instead: written answers to your security questionnaire within Pending: Security questionnaire answered within business days, a screen-share of the actual settings on the intro call if you ask, and the terms in the contract section below.
Are you insured?
Pending: Professional liability (E&O) professional liability, Pending: Cyber liability cyber liability, carried with Pending: Carrier. A certificate of insurance naming your company arrives within Pending: Certificate of insurance delivered within business days of your request.
Will you sign our NDA?
Yes, yours. If you do not have one, mine is at Pending: Mutual NDA. Redlines by email; the signed copy is the one that governs.
What of our data do you keep, and for how long?
As little as the work needs. The proposal lists it. Working copies on my device and accounts are deleted within Pending: Working copies deleted within days after handoff, and you get a dated email listing what was deleted and what was kept. What is kept: the signed proposal, invoices, and the access-removal email.
Do you put our data into AI tools?
Only into an assistant that runs on an account your company owns, under your company's terms with that vendor, and only the data the proposal names. Nothing goes into a personal or consumer account. To check: the assistant's account owner is you, and its data-source list matches the proposal.
Who else touches the work?
No one. There are no subcontractors. If a task ever needs a second person, that person gets their own named user under the same access table, and only after your written OK.
What happens if something goes wrong?
You hear from me within Pending: Incident notice within hours of my knowing, by phone and email to the contact named in the proposal. A written report follows within Pending: Written incident report within business days: what happened, what was touched, what changed. Both figures are terms in the proposal, not intentions on a web page.
Can we run our own background check?
Yes. Consent in writing, through your provider, at your cost. My own check was completed on Pending: Background check through Pending: Background check provider; the summary is available on request.
Can we talk to someone you have worked with?
Yes. Pending: References available past clients have agreed in advance to take a reference call. The introduction is by email, so you can see that the person is who I say they are.
Last reviewed . Every figure on this page comes from one data file; when a figure changes, the file changes, then the page.