Secure access before anything else: the code repository, the domain, the hosting, the database, and any app store, email or payment accounts. On the ones you control, change the passwords and remove the developer. Ask for the rest in writing. Then check what you actually own, which depends on your contract, and get an honest assessment of what state the project is in before you pay anyone to carry on.
What's the problem
They've stopped replying. Maybe after a payment, maybe halfway through the hard part. You may have paid most of the budget, you may not know where the code is, and the accounts the app runs on may be in their name.
Why it happens
- The hard part is where projects stall. Deployment, payments, app store review and security are where a half-built app meets the real world. It's also where an overstretched freelancer quietly stops.
- Everything was set up in their name. For speed, developers often open the hosting, the domain, the app store account and the code repository under their own logins. When they go, so does your access.
- Nothing was written down. How to build it, where it runs, which keys it uses: all of it was in one person's head.
How to fix it
- List every account the app depends on: code (GitHub, GitLab or Bitbucket), hosting, domain registrar, database, email sending, payment provider, app store developer accounts, analytics, and any paid APIs.
- For each one, find out who owns it. Log in where you can. If it's yours, change the password, remove the developer's access, and turn on two-factor login.
- Replace any keys the developer had. API keys and passwords they could see should be regenerated.
- For anything in their name, ask in writing for it to be transferred to you. Code repositories can be transferred to your account or organisation in a few clicks, history included. Keep the message calm, specific, and dated.
- Check your contract for who owns the code. See who owns the code my developer wrote.
- Don't pay anyone to "just finish it" yet. First get an independent look at what's actually there: what works, what's missing, and what it would take.
Australian law
If the developer was a contractor rather than your employee, the copyright in their code stays with them unless it has been assigned to you. Under section 196(3) of the Copyright Act 1968 (Cth), an assignment has no effect unless it's in writing and signed by them or on their behalf. If money is at stake or they won't cooperate, get legal advice.
General information, not legal advice.
When to call Preventionlabs
When you have the code, or access to where it lives, and the right to authorise work on it. We can't recover code nobody can reach. Once we can see it, the assessment is free: a written diagnosis of what's there, what's broken and what it takes. If we take it on, we get it live, protected to MVP level and scalable, then hand it back with the code in a repository you own, every account we set up in your control, and plain-language docs. So the next time someone leaves, you aren't stuck.
Submit your project for a free assessmentFree assessment. $10,000 AUD flat to get it live, only if we take it on and you go ahead.
Sources
- GitHub: Transferring a repositoryofficial docs
When you transfer a repository to a new owner, they can immediately administer the repository's contents, issues, pull requests, releases, projects, and settings.
- GitHub: Roles in an organizationofficial docs
Organization owners have complete administrative access to your organization. This role should be limited, but to no less than two people, in your organization.
- Copyright Act 1968 (Cth): Section 196(3): assignments must be in writinglegislation, compilation No. 65
An assignment of copyright (whether total or partial) does not have effect unless it is in writing signed by or on behalf of the assignor.