Your access,
handled with care.

To configure your DNS, your website or your tools, a specialist needs temporary access. Here is how we ask for it, protect it and erase it, and what you can do to keep full control.

Four principles

Minimal, encrypted, need-to-know, erased

Temporary and minimal

We ask for an invitation with the most limited role that allows the change, never your own password, never billing or domain transfer rights.

Encrypted

Everything you enter for your order is encrypted (AES-256-GCM) with a key kept outside the database: a database leak alone reveals nothing.

Need-to-know

Only the specialist on your mission and the Stanza team can open your access, one at a time, and each viewing is logged.

Erased

Access is erased automatically when the order is closed or cancelled. 30 days after closing, all the order's data is deleted.

Your part

How to give access the right way

Your client area comes with step-by-step guides for the main DNS hosts, website platforms and tools.

  1. Invite, do not share

    Add your specialist as a delegated account, team member or user. You keep your password and can remove the access in one click.

  2. Choose the smallest role

    The lowest level that allows the change described in your order: for DNS, editing records, never billing or transferring the domain.

  3. Use your client area only

    Enter access in the dedicated, encrypted fields of your order. Never by email, never in a message.

  4. Remove it at the end

    Once the order is closed, revoke the invitation at your provider. Each guide shows you how, in a few clicks.

Behind the scenes

What happens to what you send

  • Application-level encryption. Every answer to your order's prerequisites is encrypted with AES-256-GCM. Each value is bound to its order and its field: copied elsewhere, it cannot be decrypted.
  • Revealed on demand. Confidential access is never sent with the page: it is revealed one item at a time, on click, every reveal is logged, and the display closes after a minute.
  • Files kept private. Private storage, random names, 25 MB maximum, an allowlist of file types checked on the content itself, downloads through links valid 60 seconds, each download logged.
  • Discreet notifications. The emails we send you contain only a title and a link to your client area, never the content of your order.
  • Automatic erasure. Access is erased when the order closes or is cancelled, and can also be erased earlier, on request. 30 days after closing, everything is permanently deleted: download your reports before then.

Who sees what

Rules enforced by the database, not just the screen

Access rights are checked inside the database itself: a forged request, even with a valid session, gets nothing more.

DataYour specialist, during the missionYour specialist, after closingStanza team
Your identity and email addressNoNoYes
Your price and paymentNoNoYes
Your answers and filesYes, what the work requiresNoYes
Confidential accessOn demand, loggedErasedOn demand, logged

Your account

A client area built to be hard to break into

Strong sign-in

Passwords of at least 12 characters, a confirmed email address, and attempts limited to stop guessing.

Two-factor authentication

Turn on a code from an authenticator app in your account settings: once enabled, it is required at every sign-in.

Payment by Stripe

Your card details are entered on Stripe Checkout: Stanza never sees or stores your card number.

Good to know. Messages in your client area are encrypted at rest by our hosting provider, but not with the dedicated encryption used for access: never write a password in a message. Uploaded files are checked for type and size, not scanned by an antivirus. And Stanza handles technical implementation, not legal advice.

Security questions

Can my specialist keep my access after the mission?

Not through Stanza: access stored in your order is erased at closing, and your specialist loses sight of your order's details. On your provider's side, revoke the invitation you created: it is the only way to be sure, and each guide shows you how.

My provider has no invitation system. What should I do?

Create a dedicated, temporary account if possible, or change the password before and after the mission. Enter it only in the encrypted field of your order, and tell us in the conversation: we will adapt.

How long do you keep my order data?

Temporary access you give us is erased as soon as the order is closed. 30 days after closing, all the order data is permanently deleted: the items you sent us and the deliverables we sent you. Download and save your reports on your side; we remind you before the deletion.

How do I report a vulnerability?

Write to us privately through the contact page with the steps to reproduce it. Please do not test on real customer data and do not disclose it publicly before we have fixed it.

Temporary access, encrypted,
then erased.