Skip to content
TakeoverWork

Safety on TakeoverWork

On this page
  1. For project owners
  2. For developers and agencies
  3. Warning signs for both sides
  4. Reporting and blocking
  5. What the badges mean

TakeoverWork connects people who own unfinished software with developers and agencies who finish it. We do not take part in the work, set prices or hold payments, so most of your protection comes from how you set up the arrangement. The steps below help both sides.

TakeoverWork does not vet or guarantee providers. Make your own checks before you agree anything.

For project owners

Agree the scope in writing

Write down what will be done, what "done" means for each part, what is not included, the timeline and the price. A shared document or simple contract is enough for small jobs. The Project Handover Checklist Generator can help you list what needs to change hands.

Pay in milestones, never 100% upfront

Split the work into milestones with clear acceptance criteria and pay as each one is delivered. A partial deposit for the first milestone is common; paying the whole amount before any work is a risk. Use a payment method that leaves a record, and keep invoices and messages. Our guide on paying a developer safely goes into detail.

Give access with invites, not passwords

Never send passwords, API keys or one-time codes in a message. Instead, invite the developer as a collaborator or team member on GitHub, your hosting, database, app store and other services, with the lowest level of access they need. Keep the owner role yourself. See how to give a developer access without sharing passwords.

Rotate keys after the handover

When the work ends, or if you stop working with someone, remove their access and rotate any keys, tokens and passwords they could have seen. If a secret was ever pasted into a chat, file or repository, assume it is exposed and replace it. The Secret Leak Scanner can help you find secrets in code and config, and it runs entirely in your browser.

Check the person yourself

Look at portfolios and public code, ask how they would approach your specific problem, and ask for a short call. Consider a small paid first milestone, such as a code review, before committing to the whole project.

For developers and agencies

  • Get the scope in writing before you start, including what is out of scope and how change requests are handled.
  • Agree milestones and payment terms up front, and do not continue far beyond the current milestone without payment.
  • Ask for access through invites. If a customer offers to send passwords, ask them to invite you as a collaborator instead. It protects you too.
  • Review before you estimate. If you need to see the code before you can judge the effort, say so in your interest note.
  • Be careful with unusual requests. Requests to get into accounts the customer does not control, to bypass security, or to work on anything on the Prohibited Items list are not allowed, and you should report them.
  • Check who you are dealing with. Confirm the customer actually controls the repository, domain and accounts you will be working on.

Warning signs for both sides

  • Pressure to move to another messaging app or email straight away, before contact details are approved on the platform.
  • Requests for passwords, one-time codes, remote access to your computer, or personal documents.
  • Payment requests through unusual methods, overpayments followed by a request to send money back, or "fees" to unlock work.
  • Promises that sound too good: unrealistic timelines, prices far below the rest, or claims you cannot check.
  • Links to download files or "test tasks" that ask you to install software.

If something feels wrong, stop and take your time. You do not have to continue a conversation.

Reporting and blocking

  • Use Report on any listing, profile, message or review. Choose a reason such as scam, harassment or request for credentials. We aim to acknowledge reports within 24 hours.
  • Use Block to stop someone messaging you or sending you interest. Blocking and reporting are separate, so do both if someone breaks the rules.
  • For legal complaints, contact the Grievance Officer.
  • If you have lost money or been threatened, also contact your local police or cybercrime authority. In India you can report cybercrime at cybercrime.gov.in or by calling 1930.

What the badges mean

Badges describe one specific check each. They are not a rating, a recommendation or a statement about skill, honesty or work quality. Every badge on the site has a tooltip with the same explanation.

BadgeWhat was checkedWhat it does not tell you
Email verifiedThe person signed in using a link or code sent to that email address, so they control itWho they are or whether they are good at the work
GitHub connectedThe person connected a GitHub account by signing in with GitHub. The badge shows how old that GitHub account isWhether the code on that account is theirs or of good quality
Phone verifiedThe person confirmed a phone number with a code. This check is not switched on yetIdentity or skill
Business verifiedWe compared the business name, registration number and website the person submitted against public business registries. We do not collect documentsWhether the business does good work or will finish your project
Identity verifiedReserved for possible future use. It is not granted to anyone at present—
Founding providerThe developer was one of the first to complete a profile on TakeoverWorkAnything about skill or reliability

Profiles also show "takeovers continued via TakeoverWork", counted from customers who marked a project as continued with that provider, and a separate self-reported number of rescue projects. Reviews are interaction reviews: they reflect one customer's experience, and we do not supervise projects.

TakeoverWork does not vet or guarantee providers.

Frequently asked questions

Does TakeoverWork check developers before they can contact me?

No. TakeoverWork does not vet or guarantee providers. Badges show only the specific thing that was checked. Look at portfolios, ask questions, start with a small paid milestone and decide for yourself.

Can I pay a developer through TakeoverWork?

No. The platform never handles project money. You agree the price and payment method directly with the developer and pay them yourselves, so choose a method that leaves a clear record.

The other person wants to move to WhatsApp straight away. Is that a problem?

It is a warning sign if it comes with pressure. Keep talking on the platform until you are comfortable, then use Request contact details so both sides approve sharing.

What should I do after the handover is finished?

Remove access the developer no longer needs, rotate any keys or passwords they could have seen, and confirm you hold the owner role on every account and service.

Stuck with a half-built app?

Post your project free. Developers who finish and rescue projects can send you an interest note, and you decide who to talk to. You agree scope and payment directly with them.