Docs → Client policies

Security practices overview

The principles behind how we secure the environments we manage — and our own.

Last updated: August 2026

At a glance

The principles

Defense in layers
Perimeter, endpoint, identity, and monitoring each assume the others might fail. An attacker past one layer meets another.

Least privilege
People and systems get what their job requires, nothing more. Not about trust — about limiting how far any compromised account reaches.

Monitoring
Around the clock on managed environments. Monitoring turns “something strange at 2am” from a mystery into a timeline.

Patching discipline
On a schedule — faster when active exploitation makes waiting dangerous. See maintenance windows for how that reaches you.

Verified recovery
Backups exist to be restored, and restorability gets tested — quiet backup failure is an industry classic.

Our own house
An IT provider is a high-value target precisely because of the access clients grant it. We operate accordingly.

Note: security services and what they cover live on the Defend page. This doc describes practice, not a product.

Common questions

Are you certified in a specific framework?+

We align our practices with recognized frameworks and help clients meet their own compliance obligations — for what your contracts require, start with the CMMC readiness checklist or ask us directly.

Can you loosen a control that is slowing us down?+

Ask — sometimes the friction is fixable without touching the protection. What we will not do is quietly switch things off.

Do you monitor our staff?+

We monitor systems, not people. The trail exists to reconstruct events, not to grade anyone’s workday.

Related docs

Data handling
What we touch, why, and what we never do with it.

CMMC readiness
The stages toward a defense-supply-chain assessment.

Acceptable use
The plain-English rules that keep controls meaningful.

Want the posture read on your environment?
The free assessment tells you where you stand — in plain English, yours to keep.