How it works

From first look to handover, in writing.

How an engagement runs, what access it needs, and how that access is kept small and taken away again at the end.

The engagement, step by step

  1. Free check or enquiry

    A free check of your app’s public surface, a question sent from this site, or a booked call.

  2. Discovery call

    Thirty minutes on your product, your business goals, your stack and your constraints.

  3. Proposal

    A fixed price and a written scope. Nothing starts until you accept it.

  4. Access granted

    You give a dedicated Anyfront account the access the proposal names: at arm's length, the default, or delegated, if you chose it. Below is how.

  5. Audit and readout

    The written report, ranked by business impact, and a 60-minute call to go through it.

  6. Next proposal, if needed

    A sprint, a retainer or a project, based on the findings, and only if they call for one.

  7. Delivery

    Changes as pull requests you merge, or, under delegated access, merged and deployed by Aaron within the agreed scope, with a change log. Written handover notes either way.

  8. Access removed

    At the end of the engagement, unless a retainer continues, and confirmed in writing.

Access, in one of two modes

Arm's length is the default. Delegated access applies only if you choose it in the proposal, which sets its scope. In both, you own every repository and every account, and you can see and remove Anyfront's access at any time.

The default

Arm's length

For audits, sprints, retainers and projects, unless the proposal says otherwise. Aaron proposes every change, and you decide what reaches production.

  • A dedicated Anyfront account. Access goes to a dedicated Anyfront account kept only for client work, never to a personal one, so it is easy to see in your settings and easy to remove.
  • Read-only for audits. An audit never changes your code.
  • Pull requests you merge. For sprints, retainers and projects, write access, and every change arrives as a pull request that you merge. Nothing is pushed to your default branch.
  • No production secrets, ever. They are never requested. Where a task needs a credential, it is a staging or scoped one, shared through your secret manager or a one-time share.
  • Removed at the end. Access is removed when the engagement ends, unless a retainer continues, and the removal is confirmed in writing.

Only if you choose it

Delegated

For a takeover or a clean-up, when you want the work done rather than proposed. You choose it in the proposal, and the proposal sets its scope.

  • Within the agreed scope. Aaron may merge, deploy, and change infrastructure and architecture without asking you to approve each change. The proposal lists what is in scope, and what still needs your written approval first, such as deleting production data or adding a recurring cost.
  • You stay the owner. You remain the owner of every account. Access is a role or an invitation on your own accounts that you can remove at any time, never shared root or owner credentials.
  • Everything in version control. Code, configuration and infrastructure all change through version control, with a full history, and every change goes into a change log the proposal defines. You get a regular summary of it, and the whole log at handover.
  • Secrets stay with you. No secret is sent by email or chat. Secrets stay in your secret manager or platform settings, where the delegated role reaches them only as far as the scope needs.
  • Yours to end at any time. Remove the role, or say so in writing, and the rest of the engagement continues at arm's length. At the end, access is removed as it is at arm's length.

How access is given, by platform

GitHub
Invite the dedicated Anyfront account as a collaborator on each repository in scope: Read for an audit, Write for a sprint, a retainer or a quoted project, and Admin only for delegated access. The access request names the account.
GitLab and Bitbucket
The same collaborator invite, to the Anyfront account on that platform, at the same levels.
Lovable, Bolt and Replit
GitHub sync is preferred, so the code can be reviewed and changed in a repository like any other. Otherwise, a project invite.
Hosting and cloud accounts
Only for delegated access: an invitation or a role for the Anyfront account in your own team or account, at the lowest level that covers the agreed scope.

Security practices

Every credential Anyfront holds is a risk to you, so the aim is to hold as few as possible, for as short a time as possible.

  • Least privilege. The lowest access level the work needs, on the repositories (and, under delegated access, the accounts) that the proposal names, and nothing else.
  • Scoped credentials, by one-time share. Through your secret manager or a one-time link that expires, never pasted into chat or email.
  • Encrypted local copies, deleted at the end. Any local copy of your code or data is kept on encrypted storage and deleted when the engagement ends.
  • Revocation confirmed in writing. You get a written confirmation that access has been removed and local copies deleted.
  • Critical exposures reported immediately. A leaked key or an open database found during the work is reported to you straight away, not saved for the report.

AI-assisted delivery

Delivery is AI-assisted. Aaron uses AI tools in reviews and in writing code, under his own direction, and reviews everything before it reaches you. Your code and data are processed by AI tools only under business terms that exclude training on inputs.

You can opt out of AI-assisted processing of your code and data in the proposal. The terms have the detail.

What you receive at the end

  • After an audit: the written report, ranked by business impact, with the remediation plan and a fixed-price sprint quote, and the readout call.
  • After a sprint or a project: the pull requests, merged by you or, under delegated access, by Aaron, with the change log, and written handover notes on what changed and why.
  • On a retainer: a pull request or a written answer for each request, and the hours used against the month's cap.
  • Always: written confirmation that access has been removed and local copies deleted, unless a retainer continues.

Start with the free check.

The free check is step one, and it costs nothing. If you would rather start with a conversation, book a 30-minute call.