Web Migration & Security Clean-up

via Freelancer ·

Budget / Salary£250–750
TypeFreelance project
LocationRemote
Posted5 hours ago
Summary

# Migration & Security Handover Brief
**Prepared for:** MetaNet

---

## 1. Summary of what I need

I want to migrate my web estate from Exoscale to MetaNet **and** perform a security
clean-up at the same time, following a parting of ways with the previous contractor
who built and had administrative access to these systems. I am not technical, so I
need this handled end-to-end, but with **ownership of all accounts remaining under my
control** (see section 3).

Please treat this as: (a) a **clean migration** of 17 sites, and (b) a **security
hardening / access reset** so no prior access survives the move.
---

## 2. The estate

- **2 dynamic sites:** RedMontMed (www.redmontmed.ch) and RedMontActive
(www.redmontactive.ch) — near-identical builds. **No traditional database**; their
search is powered **live by the Anthropic (Claude) API** over the internet.
- **15 static sites:** (I can move there") all domains are already registered with MetaNet.
- **Payments:** Stripe is used on RedmontMed and RedmontActive.
on an Exoscale instance or
handled entirely by Brevo. This needs to be established before DNS is changed. We could, of course, just set up emails on the MetaNet service?
- **Current hosting:** Exoscale, spread across multiple zones
(hr-zag-1, ch-dk-2, de-fra-1, de-muc-1, at-vie-1). Security group `b02fd963-…`
currently has inbound ports 25, 465, 587, 993, 995 open to 0.0.0.0/0.

---

## 3. Ground rule: I keep ownership of the accounts

Please configure and operate within these accounts, but they must be registered under
**my** email/login with **my** payment card, and access I grant you should be under
**your own named logins** (not shared passwords), to be revoked when work completes:

- Domain / DNS for all sites
- Stripe
- Anthropic (Claude) API account
- The new MetaNet hosting account

If any of these are currently registered under the previous contractor's login rather
than mine, please flag it — transferring or recreating them under my control is part of
the job.

---

## 4. Migration requirements

1. **Clean rebuild, not a raw clone.** Please build fresh server environments and move
only my website files and data across — do **not** image/clone the existing Exoscale
servers, so that no leftover SSH keys, extra user accounts, or scheduled tasks are
carried over.
2. I can do the 15 static sites first (quick wins), then MetaNet does the two dynamic sites
carefully.
3. **DNS:** plan cut-overs to minimise downtime and account for propagation time.
4. **Test before cut-over** for every site — confirm each loads and functions before
pointing its domain at MetaNet.
5. **Decommission the old Exoscale resources only after** everything is confirmed
working on MetaNet (this also stops the Exoscale billing).
---

## 5. Per-service checklist

**Anthropic (Claude) API — powers search on the two dynamic sites**
- Confirm the Anthropic account/organisation is under my control; check its billing and
which card is attached.
- Rotate the API key **during** migration in safe order: create a new key → update the
site code → test search works → then revoke the old key (no search downtime).
- If the account is the contractor's, create a **new** Anthropic organisation under my
email/card and point both sites at a fresh key from it.

**Stripe — payments**
- Verify the payout **bank account** on file is mine and unchanged.
- Rotate the API key in safe order (new key → update site → test a live payment →
revoke old).
- Remove any dashboard access held by the previous contractor.

**Firewall (Exoscale, pre-move)**
- The five inbound mail rules (ports 25/465/587/993/995, source 0.0.0.0/0) on security
group `b02fd963-…` should be reviewed against the email finding above and tightened or
removed as appropriate.

**Servers**
- Audit the server for unknown SSH keys, unknown user accounts, and unknown
scheduled tasks (cron) before decommissioning.
- Set fresh root/admin passwords on the new servers.

---
## 6. Evidence to preserve before decommissioning

Before any old Exoscale server is deleted, please **pull and provide the server login
logs** (`/var/log/auth.log` or `/var/log/secure`), and note website file-modification
dates and any Git history. I need these to reconcile a billing/hours matter with the
previous contractor. This is time-sensitive — please capture it before anything is wiped.

---
## 7. Compliance

RedMontMed / RedMontActive are Swiss and medical in nature. Please ensure the migration and data handling meet Swiss data-
protection expectations (data location, secure transfer, access control). The sites hold no personal information save for email addresses.

---
## 8. What I'd like back from you

1. A short **discovery** step to inspect the current setup and answer
the open questions above , and are the
Anthropic/Stripe/domain accounts under my control?
2. Following discovery, a **fixed written estimate** (cost and timescale) for the full
migration + security clean-up.
3. Confirmation of how you'll keep me as the account owner throughout.

Please raise anything unclear with me directly rather than assuming. Thank you.
cloud computing website management web development api integration security auditing
Apply on Freelancer →

Project sourced from Freelancer.com. Applications happen directly on the original platform — we never collect your data.