Skip to main content
WordPress

Website Ownership Is a Stack You Can Move, Not a Login

IDFS AI
Website Ownership Is a Stack You Can Move, Not a Login

Opening answer

Website ownership is not a login. It is a stack of assets you can move: the domain at the registrar, the DNS records that point it, the source files and media, the copy, the form leads, and the analytics and Search Console properties that prove how the site performed. A monthly invoice that only buys a dashboard on someone else's template is a rental. A clean exit is a portable export you can host elsewhere, plus the logins that still work after the vendor is gone.[1][2]

A login is not ownership

Most small businesses pay every month for "a website" and walk away with a username. That username opens a CMS, a page builder, a plugin stack, and a support inbox. It does not, by itself, mean you can take the site with you.

The difference is practical. If the relationship ends tomorrow, what arrives on a drive or in a repository? HTML, templates, images, a database dump, and DNS you control is an exit. A ZIP of blog posts that will not render without the same paid theme and a dozen extensions is not. The Federal Trade Commission's 2020 Data To Go workshop put the same idea in plainer language: data portability is the ability to move data from one service to another, or back to yourself.[1]

Privacy law uses that test too. GDPR Article 20 gives a person the right to receive personal data they provided in a structured, commonly used, machine-readable format, and to transmit it to another controller without hindrance.[2] California's Consumer Privacy Act gives consumers a right to know what personal information a business collected, including specific pieces of that information, and to receive it in a form they can actually use.[3] Your website is not identical to a consumer privacy request. The standard is still useful. If you cannot take your own content, leads, and history in a format another host can load, you do not own the thing you are paying for.

We treat website ownership as an operations problem, not a slogan.

The ownership checklist

Run this list against whoever currently "has the site." If you cannot name a person, an account, and a recovery path for each row, that layer is rented.

  1. Domain registrar. Who is the registrant of record? Whose email receives renewal notices and transfer codes? Is it a company address, or a contractor's Gmail?
  2. DNS. Who can change A, CNAME, MX, and TXT records? Registrar DNS, a separate DNS host, and email are often three different vendors.
  3. CMS or admin login. A WordPress, Wix, or Squarespace user account is access. It is not the source.
  4. Theme, child theme, and custom code. Can you download every file that makes the live pages look the way they look?
  5. Media library. Original photos, logos, PDFs, and video, not compressed copies trapped in a CDN you cannot log into.
  6. Content. Pages, blog posts, and legal copy in a format that is not locked to one editor.
  7. Form leads. Who holds the submissions? A plugin mailbox, a third-party form SaaS, or an export you can open in a spreadsheet?
  8. Analytics and Search Console. Which Google account is the verified owner of GA4 and GSC? Are you a user someone else can delete?
  9. Billing and renewals. Cards on file at the registrar, host, CDN, and plugin vendors.
  10. The exit. What you receive, in writing, if you leave or if the vendor stops operating.

The UK National Cyber Security Centre's domain guidance is blunt on the first two rows: if a web hosting company registered the domain, move management to your organisation so you own and secure the name that represents your brand.[4] That sentence is from 2019. It has not aged out. We still see agencies listed as registrant, auto-renew on a personal card, and DNS living in a host account the client cannot open.

Domain registrar and DNS are the real keys

Your domain is not "the website." It is the name. Everything else hangs off it: the site, email, SSL, Search Console verification, and most SaaS tools that check a TXT record.

ICANN's registrant FAQs state the baseline. You have the right to transfer a domain between ICANN-accredited registrars. Your current registrar must provide an Auth-Code (also called an EPP or transfer code) within five calendar days of your request.[5] Transfers can still be blocked: a 60-day lock after registration, after a prior transfer, or after a change of registrant name, organization, or email.[5] If the agency is the registrant, or if the only recovery email is theirs, that lock is their lock, not yours. ICANN also says you are entitled to know who your registrar is and how to register, manage, transfer, renew, and restore the name. Those rights only help if you can log in.[6]

CISA's 2021 DNS-tampering guidance is the security version of the same checklist. Attackers who steal credentials for a registrar or DNS panel can rewrite A, MX, and NS records, intercept web and email traffic, and obtain valid certificates for your domain.[7] CISA told organizations to inventory every domain they own, change those passwords, and enforce multi-factor authentication on registrar accounts, third-party DNS panels, and anything else that can edit public records.[7] If you cannot name the registrar, you cannot put MFA on it.

Practical rules: the company is the registrant (not the founder, the agency, or the freelancer who built v1). Two people inside the company can reach the registrar. MFA is on. Auto-renew is on, paid with a company method. If your designer also "handles the domain," split that. Designers should not be the only people who can move your name.

Source files versus a CMS dashboard

A CMS login lets you change a headline. It rarely lets you rebuild the site somewhere else.

Typical rental looks like this. You pay monthly. You get an admin user. The theme is licensed to the agency's account. Page layouts live in a proprietary builder. Forms, SEO, backups, and caching are plugins with their own renewals. The "export" dumps posts and pages into XML that another WordPress install might import, while templates, plugin settings, and paid extensions stay behind. You can log in. You cannot leave cleanly.

An owned site is the opposite shape. The pages are files. The design is in those files, not in a plugin database. There is no third-party theme store in the critical path. When the term ends, you should receive the full working site: code, assets, configuration, and enough documentation to run it on ordinary hosting.

That is how we define Forged Sites. During the initial term you hold a license to use the live, hosted site. Once the term completes, or you pay it off early, you receive a full Dockerized export so you can host the site anywhere you like. The AI services that run with the plan (the director, blogging, voice capture, compliance scanning, citations, and support) stay on our infrastructure while the plan is active. If you move the site off our servers, some of those features may be limited or unavailable. The site itself, including code, design, and content, is what the export is for.[8]

A client portal is convenient. An export is portable.

Content, media, and the leads you paid to generate

Copy and images are easy to forget because they feel like "already on the site." They are not, if you cannot download them.

Ask for:

  • A full copy of every page and post, not a screenshot.
  • Original media, at the resolution you supplied, plus any licenses that came with stock.
  • Form and chat transcripts, as CSV or JSON, with timestamps and source pages.
  • Redirect maps, so old URLs still land after a move.

Leads are the sharp edge. If every quote request lands only in a plugin inbox or a vendor CRM you do not own, the vendor holds your pipeline. GDPR's "without hindrance" test is written for personal data, which form leads usually are.[2] California's right to know exists so people can see, and move, the information a business holds about them.[3] You should be able to do at least as well with your own customer list.

We keep form submissions in the client dashboard so you can see them without asking us to forward a mailbox. The exit still has to include an export of those records, not just a promise that they existed.

Analytics and Search Console: who is the verified owner?

Traffic history is an asset. If the only GA4 property sits in a former contractor's Google account, you will lose it when they leave.

Google Search Console is explicit. A verified owner has the highest permissions. Verification means proving you control the site, because owners can see sensitive Search data and take actions that affect how the site appears in Google.[9] If every verified owner loses access, every other user loses access to that property.[9] Delegated users are not a substitute. You want your company Google account as a verified owner, with DNS or HTML-file proof that you control, and a second verified owner so one departure does not lock the property.

GA4 has the same pattern. A user with Editor access is not the account holder. Google's own BigQuery export documentation draws the line we care about: when you export Analytics data to BigQuery, you own that data, and you manage permissions on the project.[10] The default UI is a view. The export is the copy that still exists if the property is later closed or transferred.

Checklist for this layer:

  • Company-owned Google account is a verified GSC owner (domain property if you can).
  • Company-owned Google account is GA4 Administrator, not a guest.
  • Measurement ID and GSC verification tokens are documented.
  • You know how to export reports, and, if the volume justifies it, how to send GA4 to BigQuery so the raw events are yours.[10]

If an agency "set up Analytics," ask them to add you as owner this week.

What you get if you leave

A clean exit is a deliverable. It should be in the contract before anyone designs a homepage.

Minimum package:

  • Domain stays in your registrar account. If it is not there today, transfer it before you argue about files. Remember the 60-day locks.[5]
  • DNS you can edit without the old host.
  • Source of the live site, not a Figma file that no longer matches production.
  • Content and media archives.
  • Form lead export.
  • List of third-party accounts (CDN, email, booking, chat) with owner transfers completed.
  • GSC and GA4 with you as verified owner / administrator.
  • Redirect map and SSL notes.
  • Written confirmation of what is not included (SaaS features that die when billing stops).

U.S. law already expects simple cancellation of recurring internet charges. The Restore Online Shoppers' Confidence Act makes it unlawful to bill a consumer through a negative-option feature on the internet unless the seller discloses material terms, gets express informed consent, and provides simple mechanisms to stop the recurring charges.[11] That statute is about stopping the card, not handing you Docker. Do not confuse "I cancelled the subscription" with "I have the site." You need both.

The EU Data Act, which entered application on 12 September 2025, goes further for cloud and data-processing services: customers should be able to switch providers and take their data, and unfair contracts that block sharing are in scope.[12] U.S. small businesses do not automatically get those cloud-switching rights. Treat them as a specification. If a vendor cannot describe the export, the format, and the timeline, you are negotiating a rental.

NIST's October 2024 Cybersecurity Framework 2.0 supply-chain guide says to put supplier requirements into contracts, using the CSF GV.SC category, rather than hoping a vendor will be kind later.[13] Website vendors are suppliers. Export, MFA on the registrar, and named owners belong in the agreement.

We write the Forged exit the same way. At term-end or early payoff, the Dockerized export is the site. If we ever had to cease operations, that clause is written to survive: a working copy of content, design, and what you need to run it, on a stated timeline.[8] Ongoing AI operations are a separate service. Mixing those two things is how owners get stuck.

CMS rental versus an owned, plugin-free site

We are not going to restage the full Forged versus WordPress comparison here. The ownership cut is shorter.

A CMS rental sells a dashboard: log in, edit a block, hope the plugin still works. Themes, builders, and extensions can be relicensed, abandoned, or tied to the agency's account. The monthly fee is easy to understand. The switching cost is not. An owned, plugin-free site is the pages you need, as code, with hosting you can change. You may still pay someone to operate it. Operation is not custody. Custody is whether the files, the name, the leads, and the search properties are yours when the invoices stop.

We built Forged Sites around that split. No CMS login required to run the business. A human technician and an AI director make the changes. At the end of the term, or when you buy the remaining labor out, you get the full export rather than another year of template rent.[8] If you need a heavy plugin ecosystem (full WooCommerce, a membership LMS, a booking platform that only exists as a CMS add-on), say so early. That is a different product.

Practical takeaways

  • Ask who is the domain registrant, and log in yourself. If you cannot, you do not own the name.[4][5]
  • Turn on MFA for the registrar and DNS, keep an inventory of every domain, and put auto-renew on a company payment method.[4][7]
  • Treat "you have a login" and "you have a portable export" as different sentences. Only the second is website ownership.[1][2]
  • Make your company a verified Search Console owner and a GA4 administrator. Users can be removed. Verified owners cannot be faked with a shared password.[9][10]
  • Export form leads on a schedule. If the only copy lives in a vendor inbox, the vendor holds the pipeline.[2][3]
  • Put the exit in the contract: format, timeline, what is included, what SaaS dies, and who pays for the transfer Auth-Code dance.[5][11][12][13]
  • Prefer a site that is files you can host, not a plugin graph you have to recreate.

How we can help

Have more questions or want to get in touch? We will walk your current stack against the checklist above and tell you what is still rented. If you want a site built as files you can take with you, Forged Sites ship with a Dockerized export at term-end or early payoff. Write us through our contact page. We will start with the registrar, the DNS, and the export, not with a mood board.

Citations

  1. Federal Trade Commission, "Data To Go: An FTC Workshop on Data Portability" (2020-09-22)
  2. EUR-Lex, "Regulation (EU) 2016/679 (GDPR), Article 20, Right to data portability" (2016)
  3. State of California Department of Justice, "California Consumer Privacy Act (CCPA)" (accessed 2026-09-08)
  4. UK National Cyber Security Centre, "Managing Public Domain Names" (2019-09-25)
  5. ICANN, "FAQs for Registrants: Transferring Your Domain Name" (2017, current)
  6. ICANN, "Registrants' Benefits and Responsibilities" (2013, current)
  7. Cybersecurity and Infrastructure Security Agency, "Mitigate DNS Infrastructure Tampering" (2021-02-04)
  8. IDFS AI, "Forged Sites" (accessed 2026-09-08)
  9. Google Search Console Help, "Verify your site ownership" (accessed 2026-09-08)
  10. Google Analytics Help, "[GA4] BigQuery Export" (accessed 2026-09-08)
  11. U.S. Congress, "Restore Online Shoppers' Confidence Act, Public Law 111-345, 15 U.S.C. 8403" (2010-12-29)
  12. European Commission, "Data Act" (application from 2025-09-12; page updated 2026-07-02)
  13. National Institute of Standards and Technology, "NIST Cybersecurity Framework 2.0: Quick-Start Guide for Cybersecurity Supply Chain Risk Management (C-SCRM), SP 1305" (2024-10-21)