How we work

  1. 01

    Access.

    Named accounts only, issued by you, MFA on, least privilege, revoked at the end. Health checks are read-only. We log what we do.

  2. 02

    Data.

    Everything stays in the client tenant. No log exports, no evidence on our machines, no screenshots with client data in reports unless you ask for them. Managed, encrypted devices.

  3. 03

    Brand.

    White label by default. Your logo on every deliverable. We never contact your end clients. 24-month non-solicitation in every SOW.

  4. 04

    Scope.

    Fixed scope and price in a one-page SOW. Changes are a new SOW. 50% at signature, 50% at delivery.

  5. 05

    Paperwork.

    We sign your NDA and DPA, answer your security questionnaire, and provide a certificate of insurance on request.

  6. 06

    What we do not do.

    No SOC or 24x7 monitoring. No CUI, ITAR or FedRAMP environments. No end-client relationships.

Book a 20-minute call