Client policies
Last updated: July 19, 2026
How to use this page
These client policies are the operating rules we hold ourselves to as your IT partner — when we do maintenance, how fast we patch, and what happens when people join or leave. Your service agreement is the contract; this page is the plain-English version of how the work actually runs.
Maintenance windows
Routine maintenance — updates, reboots, upgrades — happens outside business hours in a standing window: Tuesday and Thursday nights, 10:00 p.m. to 2:00 a.m. local time. Most of it you will never notice. Anything expected to cause noticeable downtime is announced at least two business days ahead. Emergency maintenance (an actively exploited vulnerability, a failing disk) can happen at any time; we notify you as soon as it is safe to do so and explain afterward.
Patching cadence
- Critical security patches: deployed within 72 hours of vendor release, faster if the flaw is being actively exploited.
- Operating system updates: monthly, tested on a pilot group before going wide.
- Third-party applications (browsers, PDF readers, and the like): updated continuously through our management tooling.
- Firmware for firewalls, switches, and other network gear: reviewed and applied at least quarterly, in the maintenance window.
Employee onboarding and offboarding
For new hires, give us at least three business days notice so accounts, hardware, and access are ready on day one. For departures, tell us before the person’s last day whenever possible: we disable sign-in the same hour you tell us to, preserve their mailbox and files for 90 days by default, and rotate any shared passwords they had access to. Offboarding requests must come from an authorized contact — that list is set during onboarding and can be changed by an owner at any time.
Acceptable use
Use of systems and services we provide is governed by our Acceptable Use Policy. The short version: no illegal activity, no attempting to defeat the security controls we deploy, and company accounts are for company business. The full policy is the authoritative text.
Data handling
We access your systems to do the work you hired us for, and nothing else. Administrative access is logged, credentials live in a vault, and our own staff use MFA everywhere — the same standards we enforce for you. We do not sell, mine, or share your data, and when we part ways, we hand back credentials and documentation and remove our access completely.
Changes to these client policies
When these policies change in a way that affects you, we tell you — in the quarterly review or by email for anything urgent. The current version always lives at this page. Questions about how a policy applies to your situation? Open a ticket in the HelpDesk portal.
CLIENT DOCS · POLICIES
Client policies FAQ.
How these client policies interact with your service agreement, how often they change, and who on your team can request exceptions.
Do these override my service agreement?
No. The agreement is the contract; these client policies explain how the day-to-day work actually runs. If the two ever seem to conflict, the agreement wins and we will fix the wording here.
How often are they reviewed?
At least annually, and immediately when a security framework we align to changes. Many of our controls map to guidance from NIST, which helps if your business faces CMMC requirements or cyber-insurance questionnaires.
Where should new staff start?
Point them at getting started and the support guide — the two docs that make these client policies feel routine instead of restrictive.
Who can request exceptions?
Only the authorized contacts set during onboarding. Exceptions are documented in a ticket so there is a record of who approved what and when — protection for you as much as for us.
Clear client policies keep both sides honest: you know exactly what to expect from us, and we know who can approve what on your side. If anything on this page is unclear, ask — we would rather explain a policy twice than surprise you once.
See billing and invoices →