Security and compliance posture

Security and compliance posture: how we run ourselves

  • 5.0 · 310+ Google reviews
  • Since 2014
  • 90-day money-back guarantee
  • English and Spanish
  • Answered in under 2 minutes on average
  • Published pricing

The controls we run on ourselves

We ask clients to meet a standard, so here is ours. Every employee signs in with multi-factor authentication; administrator access is separate from daily accounts and logged. Every company computer runs the same managed endpoint security we sell as IT Shield. Client credentials live in dedicated vaults, one client per vault, with access that is individually attributable. Our own systems are backed up with immutable copies and restore tests. Every suspected incident is reported, contained and recorded under a written incident process, with client notification within ten days of determining a breach that affects their data. Vendors that touch client data sign confidentiality and security terms. Staff complete security awareness training with phishing tests. We carry professional and cyber liability insurance. Our information security program is aligned to ISO/IEC 27001:2022 and the SOC 2 Trust Services Criteria; certification is in progress and we share status with clients and auditors on request. A Trust Center for the audit reports is planned.

Frameworks we follow

  • We follow SOC 2 security practices; certification in progress.
  • We follow ISO/IEC 27001:2022, NIST and CISA guidance in how we operate, and CMMC practices as far as they apply to commercial clients.

Access control

  • MFA everywhere supported, moving to passkeys.
  • Vault-managed credentials.

Endpoint security

  • Managed EDR on every device we manage.

Backup and restore testing

  • Restores tested every six months on managed plans; backup job history reviewed monthly by a technician.

Data handling

  • Client data is never used for marketing. We publish no client list, no logos and no named case studies, by design: correlating a company's clients increases their exposure. Clients leave reviews if they choose.
  • BAAs where required.

Insurance

  • General liability, professional liability (E&O), cyber liability, workers' compensation and umbrella coverage. Certificates available to clients on request.

The tools we trust

Our security and infrastructure stack includes SentinelOne and Huntress for endpoint and threat protection, Fortinet firewalls, Ubiquiti UniFi networks, Veeam backup, and Microsoft 365 with Entra ID and Intune for identity and devices.

Coverage area

Where we work

Same-day on site in Miami-Dade, Broward and Palm Beach. Managed IT and remote support nationwide, with next-business-day on-site visits for managed clients in most US metros through insured partner technicians.

  • Brickell 1395 Brickell Ave, Suite 917, Miami, FL 33131
  • Coral Gables 2525 Ponce de Leon Blvd, Suite 317, Coral Gables, FL 33134
  • Boca Raton 1200 N Federal Hwy, Suite 200A, Boca Raton, FL 33432

Tell us what is broken or what you are planning. We will tell you what it costs.