In our 21 years in business, we have never had a security breach. We do not rest on that record. We are always working to stay ahead of the latest threats, because our access to client systems means our own security directly affects yours.
Here is what that looks like in practice.
Our own access is tightly controlled
Every technician who touches your systems does so through managed, multi factor protected accounts. Access is granted based on what a person’s role actually requires, not given broadly by default. These accounts can only be used from approved devices and from approved IP addresses, so a stolen password (even paired with a stolen 2FA code) is not enough to get in. When someone leaves our company, their access is removed immediately.
Our credentials and secrets are never left exposed
Passwords, API keys, and client specific credentials are stored in dedicated, encrypted systems built for that purpose. Nothing sensitive is saved in spreadsheets, email, or sticky notes. Access to these systems is logged.
Our documentation is protected
We keep detailed records of client environments so that our team can work efficiently and consistently. That documentation platform is access controlled and encrypted.
Remote access to your systems is monitored and auditable
When we connect into a client environment, we use tools that log the connection and the actions taken. We do not use unmonitored or ad hoc remote access methods.
Our own devices and accounts are managed the same way we manage yours
Company laptops and accounts used by our team are enrolled in the same device management and endpoint protection we deploy for clients.
Any outside party we rely on is vetted first
If we ever bring in back end support for a specialized function, that relationship is evaluated for security and reliability before it touches any client data, and it is reviewed on an ongoing basis afterward.
We have a plan for when something goes wrong
Backups of our own internal systems are maintained and tested. We have documented steps for responding to an incident.
If you would like more detail on any part of this, or if you want to talk through what our security posture means for your specific environment, ask us.
