How we keep your logins safe
Our strict internal security practices for handling, storing, and eventually removing your sensitive credentials.
We know that handing over the keys to your business systems requires a high level of trust. At Chykalophia, we treat your sensitive data with the same strict security protocols we use for our own agency infrastructure.
Quick summary
We never store passwords in plain text, emails, or spreadsheets. Your credentials are kept in Bitwarden — the open-source, end-to-end encrypted password manager — with access restricted to the team members actively working on your project. Every Chykalophia account is 2FA-hardened and fully enforced, and we use passkeys wherever the platform supports them.
Our internal security protocols
Beginner 3 minutesHere is exactly what happens behind the scenes when you grant us access to a platform or share a password with our team.
1. Bitwarden, end-to-end encrypted
When you share a credential with us, it immediately goes into Bitwarden — our team password manager. Bitwarden is open-source and uses end-to-end, zero-knowledge encryption: your data is encrypted on the device before it ever reaches the server, meaning even Bitwarden itself can't see your passwords. We don't store credentials in ClickUp, Google Docs, Slack, or email — only in Bitwarden.
2. Strict "need-to-know" access
We practice the principle of least privilege. Your credentials are only shared within a dedicated, secure vault created specifically for your project. Only the strategists, designers, or developers actively assigned to your account have access to this vault.
3. 2FA hardened and fully enforced
Every Chykalophia team account is protected by Two-Factor Authentication (2FA), and the policy is fully enforced — not optional, not "we should turn that on." Where the platform supports it (Google, Microsoft, GitHub, Bitwarden, and a growing list of others), we use passkeys in place of TOTP codes for an even stronger guarantee. Even if a team member's device or password were compromised, the second factor stays with us.
4. Access reviews when teams change
When a team member rotates off your project — or leaves the agency — we revoke their access to your project's shared credentials. The default is least-privilege: only the people actively on your account should be able to reach into it.
5. Secure offboarding
When our engagement concludes, we initiate a secure offboarding process. We will provide you with a checklist of systems where our access should be revoked (such as removing support@chykalophia.com from your WordPress or hosting accounts), and we securely delete your raw credentials from our password manager.
Why we prefer delegate access
Whenever a platform allows it, we will ask you to invite us as a "delegate" or "collaborator" rather than sharing your personal password.
Inviting support@chykalophia.com as a user on your account is the most secure method of collaboration because:
- You never have to reveal your personal password.
- You maintain total ownership of the account.
- You can revoke our access with a single click when the project ends.
To learn more about this, check out our guide on delegate access vs. sharing a password.
Questions about our security?
If your IT or compliance team needs more specific information about our security protocols, please reach out to support@chykalophia.com and we will gladly provide further documentation.
Related guides
- Why we ask for access (and why it's safe)
- Delegate access vs. sharing a password
- How we keep your logins safe
- How to revoke our access later
- Access checklist for a new project
Need a hand?