    / Payment, terms & privacy](https://getfullstacksolutions.com/legal/index.html)/ Secure access handover   After you approve the ticket

# The 15-minute access handover You paid. Now the only thing left is access — and you only hand over what your specific rescue needs, over a secure channel, for the life of the job. This page is your checklist.  One-time link, no plain email Least privilege, temporary accounts Nothing card-related, ever Deleted or rotated after   Ask for my checklist See the 30 rescue tickets](https://getfullstacksolutions.com/index.html#catalog)        The handover flow

## Five steps, mostly on your side   01

### We send your checklist Right after approval you get the typed list for your rescue: what applies, what doesn't, and the one-time link for passwords.  02

### Prepare limited access Temporary accounts with limited roles beat sharing your everyday admin. Read-only beats read-write wherever the job allows.  03

### Handle IPs first Server-side work: add our egress IP to your allowlist, or share the server's public IP + SSH port. Scoped to the working session.  04

### Send passwords last, one time Passwords go through the one-time secret link only. If a password is not on your checklist, we will not ask for it.  05

### We finish, then you lock it down Fixed and delivered → credentials deleted or rotated (your call), temporary access revoked, rescue log stays with you.       What we ask for — by category

## Coherent with the rescue, nothing more Each list is scoped to the work. IP and password rules are stated per category so you always know when they apply.

### Security rescue

- Hosting panel, SFTP or SSH access (server IP + port)
- App/CMS admin — a temporary editor account works
- Database access, but only if the cleanup needs it
- Cloudflare or registrar access if DNS is involved **IP: Applies when SSH/SFTP or a panel limits access by IP — we give you our egress IP to allowlist. **Passwords: Applies for the panel, CMS admin, and database — sent over the one-time link, never in email.

### Performance rescue

- SSH to the server where the work happens
- Database credentials for the app in question
- App/CMS admin (read-only or temporary is fine)
- DNS provider access for email deliverability cases **IP: Applies for SSH work and any server-side profiling. Share the server IP + port, or allowlist us. **Passwords: Applies for SSH, database credentials, and the app/CMS admin account.

### Infrastructure rescue

- Hosting panel(s) for the sites involved
- SSH to the new — and old — server when migrating
- DNS provider access to move records safely
- Billing or subscription accounts for cost audits **IP: Applies for SSH on the old and new servers, and any firewall-scoped migration work. **Passwords: Applies for panels, DNS, and billing or subscription accounts you want audited.

### Due Diligence rescue

- Read-only source code access (the repo)
- Read access to the infrastructure, or a controlled handoff
- Our egress IP allowlisted, or a temporary role you revoke when done **IP: Applies — we give you our egress IP to allowlist, or you provision a scoped, temporary role. **Passwords: Applies only for scoped read-only handoffs; key-based access is preferred for code and infra.

### Raptor Pack rescue

- Hosting panel + SSH, with a rollback window
- WordPress/CMS admin for the pre-sale checklist
- DNS + CDN access for the load test
- The sale-date window, so the spike is tested and not guessed **IP: Applies for SSH and the CDN/edge configuration; allowlist the session so the load test is clean. **Passwords: Applies for hosting, CMS admin, DNS, and CDN accounts touched by the checklist.        What we never ask for

## The three "never sends"

- Your card number, bank access, or personal ID — never needed. Payment is a written USD invoice.
- Your everyday admin password when a temporary account would do.
- Anything that is not on the typed checklist — if it's not needed, we don't want it.      When the job is done

## Your access, back under your control

- Rotate any credential that was shared, or revoke the temporary accounts and allowlisted IPs.
- We delete what we held, or rotate at your request — confirmation is delivered with the rescue log.
- You keep the rescue log and the plain-English handover document forever; it's yours.      Copy and paste

## The email we send after payment Filled in, this is the exact message the client receives once a ticket is approved. It asks only for what the rescue needs — IP first, passwords last, everything through the one-time link.     See the post-payment email (copy it from here)
```
Subject: [Rescue name] — approved: access needed to start ([date])

Hi [First name],

[Rescue name] is approved at the locked price of [price] and scheduled to start within 48 hours of the go-ahead. Before I begin, I need a small, typed handover of access. Everything below matches exactly what this rescue does; if a line says "not needed", I won't ask for it.

1) IP (only if the rescue is server-side) — two options, whichever you prefer:
   • Add the session IP [our egress IP] to your allowlist / firewall for the working window, and confirm it's active — or
   • Send me the server's public IP and SSH port (e.g. 203.0.113.9:22) through the one-time link below.
   No IP is required if the rescue only touches the CMS, panel UI, or cloud accounts by URL.

2) Passwords (only where they apply to this rescue) — each through the one-time link attached, never in this email:
   • Hosting panel / SFTP: [user + URL or hostname]
   • CMS / app admin: [a temporary editor account is enough; main admin optional]
   • Database: [only if the rescue works directly on data]
   • DNS / CDN / billing: [only if it's on the diagnostics path]
   That one-time link burns after one read. When you're ready, paste what applies, nothing else.

3) What else helps (optional): [anything specific, e.g. a URL that reproduces the issue].

That's the whole list. If anything on it triggers a new cost, I'll pause and quote it flat — no open meters. When the rescue lands, credentials are deleted or rotated at your request, temporary accounts can be revoked the same day, and you keep the rescue log.

Reply with the link ready and we're off.
```
    Every rescue also has a printable Handover Card](https://getfullstacksolutions.com/handover/hack-cleanup/index.html) — the same checklist on paper, tickable, with lines for IP and the one-time link. Reach it from the card link on its rescue page.      Plain answers

## Handover questions, answered   How do I send passwords without putting them in email?Only through the one-time secret link that comes with your checklist. The link self-destructs once read, so nothing sensitive lives in inboxes.What is an "egress IP" and when does it apply?It is the public IP our working sessions come from. When a rescue is server-side (SSH, hosting panels, firewalls), we give you ours so you can allowlist exactly us — least privilege, and revocable the minute the rescue ends.Do you ever need my card details or personal ID?Never. Payment is a normal USD invoice you approve in writing (no fix, no fee if the rescue cannot be delivered). We never ask for card numbers, bank access, or personal IDs — if anyone does, it is not us.Can I hand over a temporary account instead of my main admin?Yes, and it is preferred. For CMS-based work a temporary editor account is enough; for servers, key-based access scoped to the session. Read-only access is used whenever the rescue allows it.What happens to my credentials after the rescue?They are deleted, or rotated at your request. Temporary accounts and allowlisted IPs can be revoked the moment delivery happens. You keep the rescue log and the handover document.

## Ticket approved? Let's get you moving. Reply to your quote email and we'll send the checklist for your rescue — typed, scoped, and secure. Ask for my checklist
