How we handle access to your systems
We ask for privileged access to the systems your business runs on. This page explains exactly what that access is, what limits it, and what we do with it — in enough detail to answer a procurement questionnaire.
The short version
Automation runs through Microsoft's official Graph API using scoped, least-privilege permissions you grant and can revoke yourself at any time, from your own admin centre, without contacting us. Every action is logged to an audit trail you can read and export. Destructive operations always require human approval — the automation proposes, a person confirms. Your data is never used to train any model, and if you leave, you keep everything and our access is gone within 24 hours.
Access model
What we can and cannot reach
The most common question we get is what stops an automated system doing something catastrophic. The answer is four separate limits, not one.
Scoped permissions
We request specific Microsoft Graph permission scopes for the functions in your tier — user management, device management, licence assignment. We do not request tenant-wide read of mail, files or Teams content, and the automation cannot reach anything outside its granted scopes. You can see the exact list in your Entra admin centre under Enterprise Applications.
Human approval on destruction
Deleting an account, altering conditional access, changing a security policy, removing data or wiping a device requires explicit human approval before it runs. The automation surfaces what it intends to do and waits. This applies on every tier including the $29 one.
Confidence handoff
When the automation isn't confident, it stops and escalates to a named engineer rather than improvising on your production environment. It does not guess, and it never reports something as fixed when it isn't.
Your revocation switch
You can revoke our delegated access yourself, immediately, without asking us or waiting for a support ticket. That's deliberate: access you can't withdraw unilaterally isn't really access you control.
Data handling
What we store, where, and for how long
| Data | Where | Retention |
|---|---|---|
| Support request content | Ticketing system, encrypted at rest | Contract term + 12 months |
| Device telemetry & patch state | Management platform | 13 months rolling |
| Environment documentation | Documentation platform | Contract term; exportable any time |
| Audit logs of automated actions | Append-only log store | 24 months |
| Backups (if you buy the add-on) | Encrypted object storage | 1 year, or 7 with extended retention |
| Billing records | Accounting system | 7 years (legal requirement) |
| Your mail, files and documents | Stay in your tenant. We do not copy them out. | |
On AI processing specifically
Your tenant contents, tickets and documentation are never used to train any model. AI processing runs under a commercial agreement with zero data retention for training. This is worth asking every AI-enabled provider to put in writing — consumer-tier AI services routinely do retain and train on what you submit, and the distinction matters.
Our own posture
How we secure ourselves
A provider with weak internal security is a supply-chain risk to every client it serves. Managed service providers are a favoured ransomware target precisely because they hold privileged access to many environments at once.
Phishing-resistant MFA
Hardware security keys on every administrative identity. No SMS codes, no push-approval fatigue.
Separated admin identities
Day-to-day accounts cannot administer client environments. Privileged access is separate, time-bound and logged.
Vendor-hosted management plane
Our remote management platform is vendor-hosted and vendor-patched, not self-hosted. Every major RMM mass-exploitation event since 2021 hit self-hosted instances while vendor clouds were patched within 48 hours. We're not taking that risk with your estate.
Least privilege internally
Engineers hold access to the clients they work on, reviewed quarterly, revoked on role change or departure the same day.
Managed EDR on our own infrastructure
Commercial managed detection and response with 24/7 monitoring on the systems that hold privileged access — the highest-value target we own.
Insured
Cyber liability and errors & omissions cover. Certificates available on request for your procurement file.
Subprocessors
Who else touches your data
We use third-party platforms to deliver the service. All are bound by confidentiality and data-protection terms. Categories below; the current named list is available on request and to customers on 30 days' notice of any change.
| Category | Purpose | Data reached |
|---|---|---|
| Cloud hosting & edge | Site, application and API hosting | Contact and lead data |
| Microsoft | The platform we manage on your behalf | Your tenant — under your own agreement with Microsoft |
| Remote monitoring & management | Device monitoring, patching, remote access | Device telemetry, configuration |
| Ticketing & documentation | Support requests, environment records | Request content, documentation |
| AI processing | Automated request handling | Request text, under zero-retention terms |
| Backup (if purchased) | Microsoft 365 and endpoint backup | Backed-up content, encrypted |
| On-site partners | Physical work at your site | Site access, under confidentiality terms |
| Payments | Card processing and billing | Billing details — card data never reaches us |
Incidents
If something goes wrong
Notification
Affected customers are notified without undue delay and within 72 hours of us becoming aware of a personal data breach — including when the cause was us.
Our errors are not billable
If our automation or an engineer breaks something, we fix it at our cost, and we tell you what happened rather than quietly correcting it.
Response support
Managed Plus includes an incident response retainer with a named responder and guaranteed availability. Lower tiers get best-effort support plus escalation to specialists.
Responsible disclosure
Found a vulnerability in something we run? Email [email protected]. We'll acknowledge within two business days and won't pursue researchers acting in good faith.
Compliance
Where we stand, honestly
We are not SOC 2 certified
We'd rather say that plainly than imply otherwise with vague "enterprise-grade" language. We operate SOC 2 aligned controls and can document our practices in detail for your procurement process, and we support customers going through their own SOC 2, HIPAA or PIPEDA work on the Managed Plus tier. If your procurement requires a provider SOC 2 Type II report today, we are not yet the right fit — and we'll tell you that on the first call rather than after you've invested time.
What we can provide for a vendor review:
- Written description of controls, mapped to NIST CSF 2.0 and CIS v8
- Insurance certificates — cyber liability and errors & omissions
- Subprocessor list with data categories
- Data processing agreement, GDPR and PIPEDA aware
- Completed vendor security questionnaires — send us yours
- Evidence of our own MFA, EDR and access review practices
Questions we haven't answered here?
Send them. Security questions get a direct technical answer from someone who understands the stack, not a sales response.