This page lays out how we actually protect client environments and data — the platform stack running behind every account we manage, the industry framework we benchmark our own program against, and how we handle an incident if one ever happens. If you're evaluating us as a vendor, an auditor, or a cyber-insurance carrier, this is the page to start with.
Not opt-in add-ons. These are baseline for every environment we manage.
Datto EDR watches every endpoint, backed by Kaseya's around-the-clock security operations team — a person, not just an alert sitting in an inbox.
Multi-factor authentication is a baseline requirement across accounts we manage, not an option we leave up to individual users.
Veeam backs up to Wasabi object storage that can't be altered or deleted once written, so a compromised account can't reach into your recovery point.
INKY flags suspicious mail with plain-English warning banners right in Outlook, while BullPhish ID runs ongoing phishing simulations and short training your staff actually finishes.
Dark Web ID continuously scans for your company's credentials showing up where they shouldn't, so a leaked password gets caught before it gets used.
Every environment we manage is documented in IT Glue and kept current, so security configuration is a known, auditable state, not tribal knowledge in one engineer's head.
We don't just say "we take security seriously" and leave it there. Internally, and for clients who want it, we track posture against CIS Controls v8.1 — a widely recognized, vendor-neutral framework maintained by the Center for Internet Security, organized into 18 control families. It's the same framework auditors and cyber-insurance carriers already recognize, which is the point: a common language for "how secure," not just our word for it.
Know what's on the network before you can protect it.
Know what's installed and running, and catch what shouldn't be.
Classify, encrypt, and control access to sensitive data.
Harden devices and infrastructure away from risky defaults.
Every account tracked, every dormant one disabled promptly.
MFA and least-privilege access, granted and revoked deliberately.
Ongoing patching and scanning, not a once-a-year scramble.
Centralized logs, kept long enough to actually investigate something.
Filtering and hardening at the two doors attackers use most.
Behavior-based detection, not signature lists alone.
Backups that are isolated, protected, and actually restorable.
Firewalls, segmentation, and secure management of the network itself.
Watching traffic for what shouldn't be there, not just endpoints.
Your people trained to recognize what technology alone can't stop.
The vendors touching your data held to the same bar we hold ourselves to.
Secure defaults and vetted components for anything we build or deploy.
A documented plan and named owners, decided before an incident, not during one.
Periodically testing our own assumptions, not just trusting the checklist.
Where we are today: as of September 2026, we've completed a self-assessment against IG1 — the foundational safeguard set every organization should have in place — and currently have 43 of 53 scored safeguards implemented (about 81%), with every remaining gap documented and dated for remediation. This is a self-assessment, not an independent audit, and it's a living number: we're continuing to build out IG2 and IG3 coverage, and we're happy to walk any client, auditor, or carrier through our current posture and supporting evidence directly.
Every environment we manage has a documented incident response process behind it, so if something does happen, we're executing a plan, not improvising one under pressure.
As your managed IT provider, we necessarily have administrative access to the systems we support. We treat that access as a responsibility, not a convenience: it's used to deliver the service you're paying for — monitoring, patching, support, security — and nothing else. We don't sell client data, share it with unrelated third parties, or use it to train anything.
Prospective clients evaluating us as a vendor, current clients who want the specifics behind "we take security seriously," and auditors or cyber-insurance carriers doing vendor due diligence. Every control area on this page is backed by a written internal policy — configuration baselines, account management, data recovery, incident response, and more — available for review under NDA. If you need something in writing beyond what's here — a security questionnaire, a specific attestation, one of those policies — reach out and we'll work through it directly.
CIS Controls is a practical, widely recognized framework that maps directly onto the day-to-day work of actually securing an environment, and it's what we use to benchmark both our own posture and the clients we manage. We haven't pursued a formal SOC 2 or ISO 27001 certification for our own company at this time; if your organization requires one of those specifically from a vendor, tell us and we'll talk through what that would take.
Veeam runs the backup jobs, and the data lands on Wasabi object storage that's immutable once written — meaning even a fully compromised admin account can't reach in and delete or alter a backup. Backups are kept offsite from the systems they protect, so a single incident can't take out both the environment and its recovery point at once.
Yes, we do. That's a fair question for any vendor with the level of access we have — we just keep policy specifics (carrier, limits, certificate) off a public page. Reach out through Contact and we'll get you documentation directly.
Access is limited to the engineers assigned to support your account, through named, MFA-protected accounts — not a shared login. Every session is logged.
Yes. We just handle these through a conversation first rather than an inbound form with no context — reach out, tell us who's asking and what it's for, and we'll take it from there.
The full detail on endpoint protection, detection and response, and email security as a standalone service.
See the service →How we help you answer a cyber-insurance renewal questionnaire or a client's vendor risk assessment.
See the service →Who we are, why clients stay, and the full platform stack behind everything we run.
Read more →Send it over and we'll work through it directly — no need to guess from this page alone.