Trust

Security boundaries and delivery discipline.

How Blockchain Central handles sensitive systems, credentials, and infrastructure during engagements — without claiming certifications or guaranteed outcomes.

Security posture

Security is scoped and documented, not assumed.

Security considerations are part of engagement planning, not an afterthought. What that means in practice.

  • 01

    Security-aware scoping

    Threat models and access boundaries are discussed during scope definition, not after build.

  • 02

    Least-privilege access during build

    During delivery, access is limited to the minimum required for scoped work.

  • 03

    Documented handoff of credentials

    All temporary credentials, API keys, and access tokens are rotated or transferred at handoff.

  • 04

    No standing production access

    Production access is removed at sign-off unless a separate support scope is agreed.

Access control

Who has access, when, and for how long.

Access is granted for the engagement duration and removed at handoff. No standing permissions remain by default.

  • 01

    Engagement-scoped access

    Access is granted only for the systems and environments needed for scoped delivery.

  • 02

    Time-bounded permissions

    Temporary credentials are issued with expiration aligned to the engagement timeline.

  • 03

    Removal at handoff

    Access is revoked at handoff. Re-instatement requires a new scope agreement.

  • 04

    Client visibility into access

    Clients are informed of what access Blockchain Central holds during the engagement.

Secrets handling

How keys, passwords, and secrets are managed.

Secrets are handled according to client environment constraints and rotated at handoff.

  • 01

    Client-environment generation

    Secrets are generated in client-controlled environments where applicable.

  • 02

    No long-lived retained secrets

    Blockchain Central does not retain long-lived secrets after handoff.

  • 03

    Rotation at transfer

    Temporary credentials are rotated or invalidated at handoff.

  • 04

    No shared vault assumption

    Blockchain Central does not assume or require access to the client's secrets management infrastructure.

Infrastructure

Who owns the infrastructure before, during, and after.

Infrastructure is deployed to client-owned or client-designated environments where the engagement structure supports it.

  • 01

    Client-owned environments

    Where scoped, infrastructure runs in client cloud accounts with client billing.

  • 02

    Build-time operation

    Blockchain Central operates within the environment only during the scoped build and deploy phase.

  • 03

    Post-handoff control

    After handoff, operational control rests with the client's designated team.

Delivery reliability

Reliability is planned through scope, review, and handoff readiness.

Reliability work is tied to the delivered system and client environment. It does not create uptime, performance, or outcome promises.

  • 01

    Deployment planning

    Delivery reliability is handled through scoped deployment steps, release review, and operating notes rather than uptime promises.

  • 02

    Change visibility

    Changes, access paths, and operator responsibilities are documented where they affect the delivered system.

  • 03

    Support boundaries

    Monitoring, alerting, and escalation paths are included only when they are part of the agreed engagement.

Operational visibility

Clients should understand what runs, who controls it, and what changes.

Visibility is handled through scoped records, admin context, and handoff notes so operating responsibility is clear.

  • 01

    Operational context

    Relevant logs, dashboards, records, and access paths are identified for client review where scoped.

  • 02

    Admin responsibilities

    Administrator roles and operator responsibilities are clarified before handoff.

  • 03

    Handoff records

    Transfer notes explain what was delivered, who controls it, and what remains outside scope.

Custody boundaries

Wallet, keys, and funds separation.

Unless explicitly scoped and documented, Blockchain Central does not custody, manage, or operate client wallets, keys, or treasury funds.

Audit and compliance

What Blockchain Central does and does not provide.

We coordinate with client-appointed auditors where scoped. We do not conduct audits ourselves or certify compliance.

  • 01

    Review coordination

    Where scoped, Blockchain Central provides agreed documentation to client-appointed review teams.

  • 02

    No formal status claims

    Blockchain Central does not claim formal security, privacy, or regulatory status.

  • 03

    No legal or compliance advice

    Regulatory and compliance strategy remains with the client and their legal advisors.

Incident boundaries

What happens when something goes wrong.

Issues discovered during build are reported and remediated within scope. Post-handoff incidents are client responsibility unless support is separately scoped.

  • 01

    Build-time discovery

    Issues found during build are reported to the client and remediated within scope.

  • 02

    Post-handoff responsibility

    After handoff, operational incidents are the client's responsibility unless support is separately agreed.

  • 03

    No continuous operations

    Blockchain Central does not provide continuous monitoring or incident response unless explicitly scoped.

What we do not claim

Hard boundaries that protect both sides.

These limitations exist to prevent procurement misunderstandings and to keep responsibility where it belongs.

Not claimed

  • Formal security status We do not present engagement work as externally verified unless that review is separately confirmed and approved.
  • Regulatory approval We do not claim regulatory approval, licensing, or compliance status.
  • Insurance We do not insure outcomes, systems, or assets.
  • Review status We do not present code or processes as independently reviewed unless that review is separately verified and approved.
  • Security boundary We do not promise protection against all threats.

Frequently asked

Common questions about security and delivery boundaries.

  • 01

    Do you perform independent security reviews?

    No. We coordinate with client-appointed review teams where scoped, but independent review work remains outside Blockchain Central's role.

  • 02

    Do you publish formal compliance status?

    No. Legal, privacy, and regulatory responsibility remains with the client and their advisors.

  • 03

    Who is responsible if there is a breach post-handoff?

    After handoff, operational responsibility rests with the client's designated team unless support is separately scoped.

  • 04

    Do you encrypt everything?

    Encryption practices follow client environment constraints and scoped requirements. We do not make universal encryption claims.

  • 05

    Is your infrastructure secure?

    We follow security-aware delivery practices, clarify access boundaries, and avoid universal security outcome promises.

Book Infrastructure Strategy Call

Discuss security boundaries, access controls, and delivery discipline for your infrastructure engagement.