Project answersPlain scope, no hidden assumptions

Know what is built.
Know what happens next.

Use this page to understand scope, ownership, search foundations, software boundaries, security controls, and post-launch support before starting a project.

01 / Scope + ownership

The commercial boundary.

Who owns the website and domain?

The business keeps ownership of its domain. Code handoff and ownership of custom deliverables are defined in the written agreement, subject to payment and any licensed third-party assets.

When do I pay?

The first payment is requested only after the written scope is accepted. Milestones, revision rounds, outside costs, final payment, and launch or handoff conditions are stated before work begins.

Can the project grow beyond the first release?

Yes. A focused first release can expand after the original scope is delivered and verified. New pages, workflows, integrations, or software features receive a separate written scope instead of silently changing the agreement.

02 / Websites + search

The public experience.

What does a business website include?

The written plan can include custom responsive page types, clear service positioning, proof, accessibility-aware interaction, a guided enquiry backend, metadata, structured data, sitemap, performance basics, TLS deployment, and launch checks. The exact list depends on the approved scope.

Does the SEO foundation guarantee Google rankings?

No. It gives search engines a technically clear site through unique page titles and descriptions, semantic content, internal links, structured data, sitemap, and performance work. Competition, authority, location, reviews, links, and ongoing content still affect results.

Can you connect analytics and Search Console?

Yes, when included. GA4 is configured with the agreed consent behavior and useful conversion events, while Search Console is connected to a client-owned Google account. Collection and indexing are tested on the production hostname.

03 / Software + integrations

The operational layer.

Can you build accounts, dashboards, databases, or APIs?

Yes, as custom software scope. Technical discovery defines the users, permissions, data model, workflows, API contracts, integrations, hosting, monitoring, recovery needs, and acceptance tests before a quote is confirmed.

Can you integrate our current business software?

Only after confirming that the product offers a documented, permitted API or a reliable export. Integration feasibility, data rights, rate limits, authentication, vendor costs, and failure behavior are assessed before any promise is made.

Is every project built with PostgreSQL and row-level security?

No. A static marketing site may not need a database at all. PostgreSQL, migrations, constraints, and row-level security are used only where the selected application and data model benefit from them. When included, access policies are tested directly.

04 / Security + support

The production boundary.

Do I send you my domain, Cloudflare, or Google password?

No. Use limited authorization, invite appropriately scoped access, or add exact DNS records yourself during a guided session. Do not send account passwords or private API keys through email or a public form.

How is private application data protected?

When the product contains private data, the backend must enforce identity, role, ownership, and tenant boundaries on every protected request. Testing includes logged-out URL reuse, direct API access, changed IDs, expired sessions, and cross-user attempts.

What happens after launch?

The launch record identifies domain, analytics, source, deployment, backup, monitoring, and support responsibilities. Code handoff is available, and an optional care plan can be selected in writing. Continued service does not start as a surprise subscription.

Still deciding?

Answer six questions and get a clearer first scope.

Build the brief