Home/Security

Trust & security

How we handle access to your systems

We ask for privileged access to the systems your business runs on. This page explains exactly what that access is, what limits it, and what we do with it — in enough detail to answer a procurement questionnaire.

The short version

Automation runs through Microsoft's official Graph API using scoped, least-privilege permissions you grant and can revoke yourself at any time, from your own admin centre, without contacting us. Every action is logged to an audit trail you can read and export. Destructive operations always require human approval — the automation proposes, a person confirms. Your data is never used to train any model, and if you leave, you keep everything and our access is gone within 24 hours.

Access model

What we can and cannot reach

The most common question we get is what stops an automated system doing something catastrophic. The answer is four separate limits, not one.

LIMIT 1

Scoped permissions

We request specific Microsoft Graph permission scopes for the functions in your tier — user management, device management, licence assignment. We do not request tenant-wide read of mail, files or Teams content, and the automation cannot reach anything outside its granted scopes. You can see the exact list in your Entra admin centre under Enterprise Applications.

LIMIT 2

Human approval on destruction

Deleting an account, altering conditional access, changing a security policy, removing data or wiping a device requires explicit human approval before it runs. The automation surfaces what it intends to do and waits. This applies on every tier including the $29 one.

LIMIT 3

Confidence handoff

When the automation isn't confident, it stops and escalates to a named engineer rather than improvising on your production environment. It does not guess, and it never reports something as fixed when it isn't.

LIMIT 4

Your revocation switch

You can revoke our delegated access yourself, immediately, without asking us or waiting for a support ticket. That's deliberate: access you can't withdraw unilaterally isn't really access you control.

Data handling

What we store, where, and for how long

DataWhereRetention
Support request contentTicketing system, encrypted at restContract term + 12 months
Device telemetry & patch stateManagement platform13 months rolling
Environment documentationDocumentation platformContract term; exportable any time
Audit logs of automated actionsAppend-only log store24 months
Backups (if you buy the add-on)Encrypted object storage1 year, or 7 with extended retention
Billing recordsAccounting system7 years (legal requirement)
Your mail, files and documentsStay in your tenant. We do not copy them out.

On AI processing specifically

Your tenant contents, tickets and documentation are never used to train any model. AI processing runs under a commercial agreement with zero data retention for training. This is worth asking every AI-enabled provider to put in writing — consumer-tier AI services routinely do retain and train on what you submit, and the distinction matters.

Our own posture

How we secure ourselves

A provider with weak internal security is a supply-chain risk to every client it serves. Managed service providers are a favoured ransomware target precisely because they hold privileged access to many environments at once.

Phishing-resistant MFA

Hardware security keys on every administrative identity. No SMS codes, no push-approval fatigue.

Separated admin identities

Day-to-day accounts cannot administer client environments. Privileged access is separate, time-bound and logged.

Vendor-hosted management plane

Our remote management platform is vendor-hosted and vendor-patched, not self-hosted. Every major RMM mass-exploitation event since 2021 hit self-hosted instances while vendor clouds were patched within 48 hours. We're not taking that risk with your estate.

Least privilege internally

Engineers hold access to the clients they work on, reviewed quarterly, revoked on role change or departure the same day.

Managed EDR on our own infrastructure

Commercial managed detection and response with 24/7 monitoring on the systems that hold privileged access — the highest-value target we own.

Insured

Cyber liability and errors & omissions cover. Certificates available on request for your procurement file.

Subprocessors

Who else touches your data

We use third-party platforms to deliver the service. All are bound by confidentiality and data-protection terms. Categories below; the current named list is available on request and to customers on 30 days' notice of any change.

CategoryPurposeData reached
Cloud hosting & edgeSite, application and API hostingContact and lead data
MicrosoftThe platform we manage on your behalfYour tenant — under your own agreement with Microsoft
Remote monitoring & managementDevice monitoring, patching, remote accessDevice telemetry, configuration
Ticketing & documentationSupport requests, environment recordsRequest content, documentation
AI processingAutomated request handlingRequest text, under zero-retention terms
Backup (if purchased)Microsoft 365 and endpoint backupBacked-up content, encrypted
On-site partnersPhysical work at your siteSite access, under confidentiality terms
PaymentsCard processing and billingBilling details — card data never reaches us

Incidents

If something goes wrong

Notification

Affected customers are notified without undue delay and within 72 hours of us becoming aware of a personal data breach — including when the cause was us.

Our errors are not billable

If our automation or an engineer breaks something, we fix it at our cost, and we tell you what happened rather than quietly correcting it.

Response support

Managed Plus includes an incident response retainer with a named responder and guaranteed availability. Lower tiers get best-effort support plus escalation to specialists.

Responsible disclosure

Found a vulnerability in something we run? Email [email protected]. We'll acknowledge within two business days and won't pursue researchers acting in good faith.

Compliance

Where we stand, honestly

We are not SOC 2 certified

We'd rather say that plainly than imply otherwise with vague "enterprise-grade" language. We operate SOC 2 aligned controls and can document our practices in detail for your procurement process, and we support customers going through their own SOC 2, HIPAA or PIPEDA work on the Managed Plus tier. If your procurement requires a provider SOC 2 Type II report today, we are not yet the right fit — and we'll tell you that on the first call rather than after you've invested time.

What we can provide for a vendor review:

  • Written description of controls, mapped to NIST CSF 2.0 and CIS v8
  • Insurance certificates — cyber liability and errors & omissions
  • Subprocessor list with data categories
  • Data processing agreement, GDPR and PIPEDA aware
  • Completed vendor security questionnaires — send us yours
  • Evidence of our own MFA, EDR and access review practices

Request the security pack

Questions we haven't answered here?

Send them. Security questions get a direct technical answer from someone who understands the stack, not a sales response.

From $29/user/monthMinimum 5 users · no bundled licences
See your price