All insights

AERIX GUIDE · 04

Process & engagement

Domain, hosting, code and assets — what should the client control after launch?

August 26, 202611 min read

After launch, a client should know more than where the publish button lives. The organisation needs to understand who formally controls the domain, whose account runs the infrastructure, where the code is stored and which rights cover photography, fonts and third-party tools. These are separate assets with different legal and operational statuses. Each should be named in the agreement, proposal and handover. This guide is general information, not legal advice; the signed contract controls and uncertain cases should be reviewed by a qualified lawyer.

Separate control, ownership and licensing first

Administrator access does not always equal ownership, and paying an invoice does not automatically transfer every copyright. A company may control its hosting account while using software under licence. It may own rights to a bespoke interface without owning the open-source framework, a commercial font or a stock image underneath it.

A professional handover lists every class of asset separately: domain, infrastructure, code, design, content, media, data, third-party accounts and licences. Both parties can then see what the client receives, what it may modify and which elements remain subject to a vendor's terms.

Domain: the client as registrant and account owner

The safest pattern is to register the domain with the client's legal details, an organisation-controlled email and its own payment method. For .pl names, NASK describes the subscriber's rights around registrar changes and the authinfo code. For global domains, accurate registrant information and access to the registrar account remain equally important.

A supplier may receive technical DNS access, but it should not be the only party able to renew or transfer the name. Automatic renewal, multi-factor authentication and at least two organisational recovery contacts reduce avoidable risk.

Hosting: two valid models when the rules are explicit

In the first model, the client owns the cloud, server or platform account and grants AERIX working access. In the second, AERIX provides managed hosting and assumes responsibility for the operational elements listed in the service scope.

Managed hosting is not a loss of control when the proposal defines fees, backups, updates, monitoring, support, any SLA, notice period and migration route. The client should know from day one what it receives at termination and how quickly the service can be moved.

Code and repository: technical access is only part of the answer

A repository provides change history and supports future development, so a client should receive agreed access or a transfer after the project is settled. GitHub supports formal repository transfers with history and project data, although integrations and deployment secrets usually require separate configuration.

Rights in bespoke code should follow the signed agreement and commonly transfer only after full payment. Open-source libraries, vendor components and SaaS products keep their own licences: a supplier cannot transfer rights it never owned.

Design, content, images and fonts do not share one licence

Bespoke layouts, copy and commissioned assets may be assigned or licensed under the project agreement. Client-supplied photography remains the client's, while stock, fonts, icons or music may restrict domains, advertising use or onward transfer.

The handover should include a dependency and licence register: asset name, source, account owner, usage scope and renewal date. This prevents a future team from discovering that nobody knows whether the hero image remains licensed or where the typeface was purchased.

Business data and analytics accounts should survive any supplier

Customer records, enquiries, CMS content, analytics, Search Console, map profiles and advertising accounts are business assets. They should normally be created inside the client's organisation, with the supplier invited under the least privileged suitable role.

Changing partner then preserves measurement history and access. The client removes the outgoing supplier rather than recovering an account tied to somebody's private inbox.

A practical handover checklist

A complete package covers the registrar and DNS, hosting, repository and runbook, environment values delivered through a secure channel, a data export, CMS, analytics, Search Console, integrations, licences and the access list. Passwords should not live in an ordinary document or email.

Record runtime versions, backup and restoration procedures, vendor contacts and renewal dates as well. This operational map allows another qualified team to assume responsibility without digital archaeology.

A clear exit path is part of good managed care

A client may deliberately choose managed hosting for years and still remain independent. It needs a defined export procedure, delivery times for data and code, settlement rules and the scope of any paid migration assistance.

AERIX supports both patterns: client-owned infrastructure or managed care. We build retention through service quality, documentation and predictable rules agreed before production — not through technical captivity.

Key takeaway

A client does not need to administer every server to retain control of a digital asset. It should be the domain registrant, understand the hosting model, have contractual access to the agreed code and data, and receive a clear map of licences and migration. The strongest relationship does not need a technical lock-in.

Frequently asked questions

Can AERIX host and maintain the website from the start?

Yes. This is managed hosting. The proposal should specify the recurring fee, maintenance scope, backups, monitoring, updates, support rules, notice period and migration procedure.

Does paying for a website automatically transfer all source-code rights?

Do not assume so. The contract should state the scope, timing and permitted uses. Third-party libraries, fonts and services remain under their suppliers' licences.

Should a client receive the Git repository?

For a bespoke build, access or transfer after settlement is good practice. A repository alone does not replace documentation, data, secrets, licences and infrastructure access.

What if an agency registered the domain in its own name?

Identify the registrant and the registrar's process, then formally move control to the client. NASK rules and authinfo apply to .pl domains; seek legal assistance if ownership is disputed.

Sources & documentation

Authoritative references used to verify the factual and technical parts of this guide.

Want results like these for your brand?

Let's design a website that gets you found and wins clients. The first consultation is free.

Book a free consultation

Ecosystem

AERIX is part of the nex-IT ecosystem — a family of complementary technology brands.

AERIX

A hub for modern digital experiences, AI and advanced interactive systems.

You are here
nex-IT

End-to-end IT services for businesses. Outsourcing, cybersecurity, server administration and 24/7 monitoring.

Visit nex-it.pl
N3X

Next-generation IT tools: network, security, DNS, SSL, domain audits, generators and automation in one place.

Visit n3x.pl
AERIX

Premium digital studio crafting exceptional web experiences with cutting-edge technology.

Working with clients worldwide

A remote-first studio based in Poland, building websites, apps and marketing for businesses globally

EuropeUnited KingdomGermanyScandinaviaUnited StatesCanadaUAEAustraliaRemote — worldwide
Explore locations

© 2026 AERIX. All rights reserved.

Ecosystem crafted by Jakuba Potocznego