How we work
- 01
Access.
Named accounts only, issued by you, MFA on, least privilege, revoked at the end. Health checks are read-only. We log what we do.
- 02
Data.
Everything stays in the client tenant. No log exports, no evidence on our machines, no screenshots with client data in reports unless you ask for them. Managed, encrypted devices.
- 03
Brand.
White label by default. Your logo on every deliverable. We never contact your end clients. 24-month non-solicitation in every SOW.
- 04
Scope.
Fixed scope and price in a one-page SOW. Changes are a new SOW. 50% at signature, 50% at delivery.
- 05
Paperwork.
We sign your NDA and DPA, answer your security questionnaire, and provide a certificate of insurance on request.
- 06
What we do not do.
No SOC or 24x7 monitoring. No CUI, ITAR or FedRAMP environments. No end-client relationships.
https://gardiensecurity.com/how-we-work