Trust
Security boundaries and delivery discipline.
How Blockchain Central handles sensitive systems, credentials, and infrastructure during engagements — without claiming certifications or guaranteed outcomes.
Security posture
Security is scoped and documented, not assumed.
Security considerations are part of engagement planning, not an afterthought. What that means in practice.
- 01
Security-aware scoping
Threat models and access boundaries are discussed during scope definition, not after build.
- 02
Least-privilege access during build
During delivery, access is limited to the minimum required for scoped work.
- 03
Documented handoff of credentials
All temporary credentials, API keys, and access tokens are rotated or transferred at handoff.
- 04
No standing production access
Production access is removed at sign-off unless a separate support scope is agreed.
Access control
Who has access, when, and for how long.
Access is granted for the engagement duration and removed at handoff. No standing permissions remain by default.
- 01
Engagement-scoped access
Access is granted only for the systems and environments needed for scoped delivery.
- 02
Time-bounded permissions
Temporary credentials are issued with expiration aligned to the engagement timeline.
- 03
Removal at handoff
Access is revoked at handoff. Re-instatement requires a new scope agreement.
- 04
Client visibility into access
Clients are informed of what access Blockchain Central holds during the engagement.
Secrets handling
How keys, passwords, and secrets are managed.
Secrets are handled according to client environment constraints and rotated at handoff.
- 01
Client-environment generation
Secrets are generated in client-controlled environments where applicable.
- 02
No long-lived retained secrets
Blockchain Central does not retain long-lived secrets after handoff.
- 03
Rotation at transfer
Temporary credentials are rotated or invalidated at handoff.
- 04
No shared vault assumption
Blockchain Central does not assume or require access to the client's secrets management infrastructure.
Infrastructure
Who owns the infrastructure before, during, and after.
Infrastructure is deployed to client-owned or client-designated environments where the engagement structure supports it.
- 01
Client-owned environments
Where scoped, infrastructure runs in client cloud accounts with client billing.
- 02
Build-time operation
Blockchain Central operates within the environment only during the scoped build and deploy phase.
- 03
Post-handoff control
After handoff, operational control rests with the client's designated team.
Delivery reliability
Reliability is planned through scope, review, and handoff readiness.
Reliability work is tied to the delivered system and client environment. It does not create uptime, performance, or outcome promises.
- 01
Deployment planning
Delivery reliability is handled through scoped deployment steps, release review, and operating notes rather than uptime promises.
- 02
Change visibility
Changes, access paths, and operator responsibilities are documented where they affect the delivered system.
- 03
Support boundaries
Monitoring, alerting, and escalation paths are included only when they are part of the agreed engagement.
Operational visibility
Clients should understand what runs, who controls it, and what changes.
Visibility is handled through scoped records, admin context, and handoff notes so operating responsibility is clear.
- 01
Operational context
Relevant logs, dashboards, records, and access paths are identified for client review where scoped.
- 02
Admin responsibilities
Administrator roles and operator responsibilities are clarified before handoff.
- 03
Handoff records
Transfer notes explain what was delivered, who controls it, and what remains outside scope.
Custody boundaries
Wallet, keys, and funds separation.
Unless explicitly scoped and documented, Blockchain Central does not custody, manage, or operate client wallets, keys, or treasury funds.
Audit and compliance
What Blockchain Central does and does not provide.
We coordinate with client-appointed auditors where scoped. We do not conduct audits ourselves or certify compliance.
- 01
Review coordination
Where scoped, Blockchain Central provides agreed documentation to client-appointed review teams.
- 02
No formal status claims
Blockchain Central does not claim formal security, privacy, or regulatory status.
- 03
No legal or compliance advice
Regulatory and compliance strategy remains with the client and their legal advisors.
Incident boundaries
What happens when something goes wrong.
Issues discovered during build are reported and remediated within scope. Post-handoff incidents are client responsibility unless support is separately scoped.
- 01
Build-time discovery
Issues found during build are reported to the client and remediated within scope.
- 02
Post-handoff responsibility
After handoff, operational incidents are the client's responsibility unless support is separately agreed.
- 03
No continuous operations
Blockchain Central does not provide continuous monitoring or incident response unless explicitly scoped.
What we do not claim
Hard boundaries that protect both sides.
These limitations exist to prevent procurement misunderstandings and to keep responsibility where it belongs.
Frequently asked
Common questions about security and delivery boundaries.
- 01
Do you perform independent security reviews?
No. We coordinate with client-appointed review teams where scoped, but independent review work remains outside Blockchain Central's role.
- 02
Do you publish formal compliance status?
No. Legal, privacy, and regulatory responsibility remains with the client and their advisors.
- 03
Who is responsible if there is a breach post-handoff?
After handoff, operational responsibility rests with the client's designated team unless support is separately scoped.
- 04
Do you encrypt everything?
Encryption practices follow client environment constraints and scoped requirements. We do not make universal encryption claims.
- 05
Is your infrastructure secure?
We follow security-aware delivery practices, clarify access boundaries, and avoid universal security outcome promises.
Book Infrastructure Strategy Call
Discuss security boundaries, access controls, and delivery discipline for your infrastructure engagement.