Security & Delivery

Control should be visible, not implied.

The controls below are Méllon’s delivery baseline. The exact architecture, access model, monitoring, and support plan are agreed in proportion to each project’s data and operational risk.

Ownership and accounts

Client-owned accounts are used where practical. Ownership of delivered code, data, documentation, and agreed assets is defined before work begins.

Credentials and access

Access is granted for a defined purpose, kept to the minimum needed, and reviewed or revoked when the work ends. Secrets do not belong in source code.

Environments and releases

Development and production are separated where the project risk requires it. Production releases have an agreed owner, validation steps, and a rollback approach.

Testing and data

Acceptance criteria are agreed before implementation. Important paths, edge cases, permissions, integrations, and migrations are tested against representative examples.

Monitoring and support

Monitoring, error alerting, backups, response expectations, and support boundaries are agreed for the system being delivered rather than assumed.

AI-assisted work

AI may accelerate research, implementation, testing, and documentation. Client information is used only in approved tools and under the access rules agreed for the engagement.

Handover and continuity

Version-controlled code, operating documentation, training, and access records reduce dependency on one person and support a clean handover if the relationship ends.

Compliance claims stay precise.

Méllon only claims controls and certifications that can be evidenced. If an engagement requires specific legal, regulatory, insurance, residency, or procurement controls, those requirements are identified during discovery and included in scope.

Discuss project requirements