Use a unique password
Choose credentials that are not reused on another service and protect access to the associated email account.
Protect account access, keep destination credentials private and treat devices, contributors and connected platforms as part of one shared-responsibility model.
Choose credentials that are not reused on another service and protect access to the associated email account.
Remove people, devices or platform connections that no longer belong in the production workflow.
Password-reset and verification links should be opened only by their intended recipient.
Redact credentials from screenshots, recordings, support tickets and shared production documents.
Give contributors and operators only the permissions their role needs for the current production.
Keep operating systems and browsers current and prevent unauthorized physical access during live work.
Include the affected surface, impact and safe reproduction steps without accessing other people’s data.
Give the team a reasonable opportunity to investigate and reduce risk before sharing technical details publicly.
Use redacted examples and ask for a protected transfer method if sensitive evidence is required.
Protect account access, review destination permissions and report concerns with enough detail to investigate.