You own it. This is the architecture that makes that true.
Every provider tells you that you own your systems. Almost none can show you the structure behind the sentence, because most of them do not work that way. Here is the structure, in enough detail that you could check it yourself.
Most businesses find out how this works at the worst possible moment
Not through malice, usually. Someone built the website years ago and registered the web address on their own account because it was quicker. The hosting went on their card. The email system was set up under their personal login. Everything worked, so nobody looked.
They stop answering
Not always deliberately. People move overseas, change careers, get sick, or simply lose interest in a job they finished four years ago. The domain renewal notice goes to an inbox nobody reads.
Nothing can be changed
You cannot point the domain somewhere new, cannot add a staff mailbox, cannot move the hosting. Every path forward runs through one person who is not replying, and no amount of paying someone else fixes it.
The rebuild is the cheap option
Eventually it is less painful to buy a new domain and start again than to recover the old one. That is the point at which the business pays twice for something it thought it already owned.
What happens the day you want Leapfrog gone
This is the only question worth asking a provider, and the answer should be boring. Everything is registered to you. Leapfrog is attached by a single line of delegated access. Cut it and nothing else moves — because nothing else was ever attached to us.
Seven decisions, made once, at the start of every engagement
None of this is expensive or clever. It is just decided deliberately at the beginning, when it costs nothing, rather than discovered later when it costs everything.
Every account in your company's name
The web address, the email system — Microsoft or Google, whichever you run — the hosting, the code. Registered to your business, billed to you, at cost. Not resold through Leapfrog, so there is no account of ours for them to sit behind.
A role address, never a person's
Accounts are registered to something like it@yourdomain, not to you personally and not to Leapfrog. People leave and roles do not. Verification mail reaches both parties, so you are not interrupted for every signup — and the account is still unambiguously yours.
You remain the top administrator
Always, on every system. Two reasons: if Leapfrog loses access you can restore it, and a client who cannot remove their provider is in exactly the position they hired one to fix.
Leapfrog's access is named, never shared
Leapfrog works under its own named account with its own credentials, so the audit trail shows who changed what and when. It also means revoking that access is disabling one account, not rotating a password everybody knew.
Break-glass credentials stay in your safe
Your master password and recovery codes go on paper, in your office, in your possession. Not in a file, not in a Leapfrog vault, not anywhere we can reach. If Leapfrog vanishes tomorrow you can still get into everything.
A register of what exists — never of what unlocks it
You get a written record of every service, who it is registered to, and where its password lives. The register never contains the password itself. It is the map, not the keys.
Your own vault, not a folder in ours
Your passwords live in a vault account your business owns, and Leapfrog is invited in. The alternative — one provider vault with a folder per client — makes that provider the highest-value target in their own industry, and means no client truly holds their own keys.
A map of what you own. Never a set of keys
Every engagement produces a register: each service, who it is registered to, and where its password lives. It is the document you would hand the next developer if Leapfrog stopped answering the phone tomorrow. Here is a specimen — and the part that matters is what is missing from it.
| Service | Registered to | Where the password lives | Leapfrog access |
|---|---|---|---|
| Your web addressdomain registrar | Your company | Your password vault | Admin, named |
| Email & documentsmicrosoft 365 · google workspace | Your company | Your password vault | Admin, named |
| The servers it runs oncloud hosting | Your company | Your password vault | Admin, named |
| Passwords & keyspassword vault | Your company | Break-glass: your safe, on paper | Invited member |
| The code itselfsource repository | Your company | Your password vault | Contributor |
| Visitor statisticsanalytics | Your company | Your password vault | Viewer |
Administrative access is a serious power. Here is exactly what it means.
To do this work Leapfrog usually needs administrator rights on your email system — Microsoft 365 or Google Workspace alike. That role can reset any password, which means it can reach any mailbox and any file in your organisation. You deserve to hear that from us rather than work it out later. So: the account carries two-factor sign-in from the moment it is created, it is recorded in your register, removing it is step one of offboarding, and the boundary is administration rather than correspondence. Leapfrog is there to configure the system, not to read your mail.
Removing Leapfrog is one action, on your side.
Disable the Leapfrog account in your directory and the access is gone. Every account stays live because it was always registered to you, the code is already in your repository, and your data exports in open formats whenever you ask, at no charge. There is no handover ceremony, because there is nothing to hand over. That is the whole design.
Ask your current provider the same question.
"If I wanted to remove you tomorrow, what would I have to do?" You will learn more from the answer than from any proposal. And if you would like to talk about what you actually own right now, the first conversation is free.