ETTIKAR
Trust Center

How We Work.
What You Can Expect.

Thirteen commitments every Ettikar client can hold us to — from the first discovery call through final handover and beyond.

Core Practice— a normal part of how we work on every project.
Available by Agreement— requires discussion and inclusion in the signed scope before it applies.

Discovery & Scoping

Every project starts with a discovery session — a structured conversation about your business goals, technical constraints, and what success looks like. Before any code is written, we produce a scoping document outlining what is being built, the technology approach, the delivery timeline, and the project phases.

This document becomes the reference point for the contract. Changes to scope after sign-off are handled through a transparent change-request process — revised cost and timeline estimates are provided and agreed before any additional work begins. Nothing proceeds without your approval.

Project Governance & Milestones

Projects are divided into milestones — distinct, reviewable stages with defined deliverables. Each milestone requires client sign-off before the next begins. Progress is communicated at agreed intervals throughout.

There is no black-box development phase. What is being built, what has been completed, and what is coming next are always visible to you. If a milestone is at risk of slipping, you are told before it slips.

Technical Architecture

Technology decisions are made based on your project's specific requirements: traffic profile, integration needs, long-term maintenance burden, and your team's technical capacity. We do not apply a single stack to every project.

Where a choice trades short-term build speed for long-term maintenance cost, we disclose that before the decision is made. Major architectural decisions are documented before implementation begins. You always know why a technical choice was made.

Code Quality & Review

All code follows consistent naming conventions, is structured for readability, and is written to be maintained by an external developer. We do not write clever code. We write clear code.

Third-party libraries are used deliberately — dependencies are kept to what is necessary and documented. Code is reviewed internally before delivery. The goal is a codebase that a developer who was not on the project can pick up without difficulty.

QA & Device Testing

Every deliverable is tested across the devices and browsers agreed in the project scope. Standard testing covers Chrome, Safari, Firefox (current versions), iOS Safari, and Android Chrome.

Additional device coverage — older browser versions, specific screen sizes, or non-standard environments — is defined in the scoping document. Edge cases and error states are tested, not just the expected path. QA is performed before each milestone sign-off, not only at launch.

Performance

We optimize production websites for performance and treat Core Web Vitals — LCP, CLS, and INP — as delivery criteria. Specific performance targets depend on the project's scope, approved media, hosting environment, third-party integrations, and feature requirements. Benchmarks are agreed during scoping and reflect what is achievable within the approved design and feature set.

Standard practices include image optimization, code splitting, lazy loading, server response monitoring, and pre-launch performance auditing. Where a design decision or approved feature introduces a measurable performance cost, that trade-off is disclosed before implementation.

Security Practices

Standard security practices applied to every project: HTTPS on all environments, secrets stored as environment variables (never in source code), input sanitization on all user-facing forms, database access controlled through Row-Level Security or equivalent, and dependency auditing before production launch. These practices reflect responsible software development — they reduce risk meaningfully, but no software system can guarantee complete security against all threats.

We do not make penetration testing claims, formal compliance certifications, or absolute security guarantees. Independent security testing, vulnerability assessments, or formally contracted security hardening are available as a defined scope item, treated as separate contracted work with its own deliverable.

Source-Code Ownership

Ownership of all original work developed by Ettikar for your project transfers to you according to the terms of the signed agreement and upon completion of applicable payment obligations. This is written into every contract.

Third-party libraries, open-source components, fonts, licensed stock media, APIs, and other externally sourced assets remain governed by their original licences — we cannot transfer ownership of intellectual property we do not own. As part of handover, we document key third-party dependencies so your team understands what those licence terms cover. Your existing brand assets, content, and IP contributed to the project remain yours throughout.

IP & Asset Handover

Handover includes: source code repository access, environment configuration documentation (production secrets transferred separately and securely), design source files in editable format, and access credentials for third-party accounts created specifically for the project. The exact handover package is defined in the signed scope.

Third-party libraries, open-source frameworks, and external services included in the project remain subject to their own licence terms. We identify and document significant dependencies during handover so you understand what your team inherits and what obligations those licences may carry.

Documentation

Documentation is proportional to the project and defined in the signed scope. It may include any combination of: setup and installation instructions, deployment procedures, environment-variable reference (without secret values), admin panel guidance, architecture notes, API integration summaries, handover checklist, and post-launch support instructions.

We do not guarantee the same documentation package for every project. A single-page admin guide and a multi-section technical reference are both appropriate outputs depending on scope. Where a system is complex, we provide a recorded walkthrough alongside written documentation.

Warranty & Support

A 30-day post-launch defect warranty covers reproducible bugs and broken functionality that demonstrably deviates from the agreed, signed specification. The warranty period begins on the date the deliverable is accepted by the client.

The warranty does not cover: new features, design modifications, new integrations, content updates, third-party service failures, hosting-provider issues, problems introduced by client modifications after delivery, or any work outside the signed scope. After the warranty period, ongoing support and maintenance are available under a separate support agreement with defined response times and scope.

Confidentiality & NDA

All client information shared during a project — business logic, unreleased products, customer data, financial information, or anything a reasonable person would consider sensitive — is treated with discretion by default, regardless of whether a formal agreement is in place.

A Non-Disclosure Agreement is available on request before discovery begins. We do not share client information with third parties, subcontractors, or any external party without written consent.

No-Lock-In Policy

You are not locked in to Ettikar after handover. We do not build systems that only we can maintain, and we do not use proprietary tools that create a forced vendor relationship — unless a tool is genuinely the right choice for your project, in which case the dependency is disclosed and agreed upfront.

After handover, you can continue working with us, switch to another team, or maintain the system internally. Clean documentation and readable code make all three options viable. This commitment is made to every client from the first conversation.