Current focus: Lovable + Supabase + Stripe Incident desk: Mon–Fri, 9 AM–6 PM ET

Access, Security & Data Handling

Careful access.
Controlled changes.
Customer-owned systems.

Production systems deserve more care than trial-and-error prompting. This page explains what access each service asks for, what we do with it, how a change is approved — and what we will never do.

Applies to All diagnosis, review, audit, assessment, implementation, migration, hypercare and managed-reliability engagements.
Last updated
July 22, 2026

The rules don't bend for urgency.

Same rules,
every engagement.

Every engagement runs under the same access rules. They do not change based on how urgent the work is or how large the system is.

  • Least privilege. We ask for the minimum access that can answer the agreed question — nothing broader, and nothing “just in case”.
  • No shared passwords. Access is granted through collaborator invitations, named role-based accounts or a supervised screen-sharing session.
  • No surprise changes. Nothing changes in production until you have approved the specific scope, its risk and its price.
  • You stay the owner. The application, the accounts, the source code and the data remain yours throughout and after the engagement.
  • Temporary access. Access is time-boxed to the engagement and removed at closure. It is not a standing key to your systems.
  • Access revocation. Temporary credentials, test accounts and engagement artifacts are cleaned up when the work ends.
  • No unnecessary data export. We do not copy or retain your production database. Real data seen while investigating is treated as incidental, not a dataset.

Never send us these

  • Passwords
  • API keys and access tokens
  • Database connection strings
  • Recovery or backup codes
  • Private keys and .env files
  • Database dumps or credential exports
  • Full customer datasets or payment-card data
  • Unredacted health or financial records

If you have already pasted a credential anywhere, treat it as exposed and rotate it. If a message appears to ask you for a password, assume it is not from us and email hello@apprescuedesk.com before responding — we do not need your passwords to do this work.

The least access that answers the question.

The question is different for each service, so the access is too. We begin with the minimum that can answer it — and production customer data is never the default input.

Least privilege,
per service.

Diagnosis

Read-level logs, configuration and recent-change evidence first.

RLS Review

Schema, policies, migrations, roles and synthetic test accounts. Production customer data is not the default input.

Readiness Audit

Repository, provider settings, architecture evidence, critical workflows and operational artifacts.

Independence Assessment

Ownership, repository, runtime, database, authentication, storage, provider and domain inventories.

Implementation or migration

Only the privileges required for the approved change, test, reconciliation and rollback.

How access becomes a change.

You approve
before we touch it.

Diagnosis and change are deliberately separated. Investigating your system does not authorise us to modify it.

  1. 1

    We investigate first

    Symptoms, recent changes, logs, configuration and connected services — at read level, before touching anything.

  2. 2

    You approve the change

    You receive the finding or root cause, the proposed change and a fixed or capped price. Work begins only after you say yes.

  3. 3

    We capture the current state

    Where it is possible and meaningful, we back up, duplicate or document the affected configuration, schema or code before a material change.

  4. 4

    We work in the safest environment

    Preview, staging or a branch where one exists; production only when there is no alternative and you have approved it.

  5. 5

    We record what changed

    You receive a short written summary of every change made and how the affected workflow was verified end to end.

  6. 6

    We hand back and revoke

    At closure we list the access to remove and the credentials to rotate, and we remove ourselves where the platform allows it.

Who does the work — and how AI fits.

Specialists & subcontractors

Where a specialist is needed, we disclose the role before access is granted. Specialists use named accounts, minimum privilege and the same confidentiality, approval, evidence and access-revocation rules.

App Rescue Desk stays accountable for engagement scope and QA. We do not subcontract where the customer agreement does not allow it.

AI-assisted work

AI may assist with redacted log summaries, test-case suggestions, finding normalization or report drafting. It does not approve or make production changes.

Customer secrets, production credentials, private repositories and personal data are not sent to external AI systems without an approved contractual basis and explicit handling controls. Final findings and production decisions are reviewed by a human.

Where our reviews stop.

Honest about
the edges.

A configuration or data-isolation review is not

  • a formal penetration test,
  • a compliance certification,
  • an active-breach or forensic investigation,
  • a guarantee that no vulnerability exists.

Regulated and high-risk data needs more

  • health data,
  • regulated financial systems,
  • children’s data,
  • government-critical systems,
  • surveillance systems,
  • high-volume payment systems.

These require enhanced contract, data-processing, insurance and specialist review. Where those conditions are not available, the engagement is declined.

App Rescue Desk is an independent service run at pilot scale — a working process, not a compliance programme.

  • We do not hold SOC 2, ISO 27001 or comparable certification.
  • We cannot secure or repair infrastructure controlled by a third-party provider such as Lovable, Supabase or Stripe.
  • We do not guarantee recovery of deleted or corrupted data; a potential data-loss event may need a separate scope before anything is changed.
  • We are an independent service and are not affiliated with or endorsed by any platform we work with.

Report a security issue

If you believe you have found a vulnerability in this website, or that an access grant related to your engagement has been misused, email hello@apprescuedesk.com with the details. We acknowledge reports during published desk hours and tell you what we intend to do. Please do not test against systems you do not own.

Choose the service that matches your situation.

Careful access and controlled change apply to every engagement. Start with the one that fits the decision you need to make.