How we work
Before you sign anything, you'll know where your data lives, who can access your systems, and exactly what happens when something breaks. Here's the whole process.
Onboarding
Twenty minutes to understand your setup, your risks, and whether we're the right fit. You'll leave with at least one useful recommendation.
We audit your environment and hand you a written proposal — including the security posture document and data-locations table.
We take over from your current provider using a documented handover checklist: credentials, licensing, DNS, backups, vendor relationships.
Monitoring live on every device, helpdesk open to all staff, and your first monthly report scheduled.
These aren't marketing lines — they're written into our agreements and our security posture document, which every prospective client receives before signing.
A per-vendor table listing every platform we use to serve you and the region where its data is stored. Where an Australian data residency option exists, we use it.
Every technician works under a named account with multi-factor authentication and session logging. No shared credentials, ever.
When anyone leaves our team, a documented kill-list revokes every credential and access path — completed and verified within hours.
Response targets are defined against AEST and AEDT in the contract itself, so "business hours" always means your business hours.
We support your obligations under the Privacy Act and the Cyber Security Act 2024, including mandatory incident reporting timeframes.
Clear written notice before any contract renewal, no lock-in beyond the initial term, and no punitive exit fees.
Straight answers
Our service delivery team operates remotely and works Australian business hours — your 9am is their 9am. All access to your systems is logged, named, and governed by written security controls we share with every client. We publish a full security posture document, including a data-locations table, before you sign anything.
It depends on the platform, and we tell you exactly. Before onboarding, you receive a written table listing every tool we use to serve you and the region where its data is stored. Where an Australian data residency option exists, we use it.
No. Agreements run for an initial term, then continue month to month. We give you clear written notice before any renewal — nothing rolls over silently — and there are no punitive exit fees. If we're not earning the relationship, you shouldn't be trapped in it.
You get a documented incident response process with defined severity levels, response targets, and a named point of contact. For notifiable incidents, we support your obligations under the Australian Privacy Act and the Cyber Security Act 2024, including mandatory reporting timeframes.
Straightforward, and we do the heavy lifting. Our onboarding process includes a documented handover checklist covering credentials, licensing, DNS, backups, and vendor relationships. Most clients are fully transitioned within two to four weeks with no interruption to staff.
A short call to understand your setup, your risks, and whether we're the right fit. You'll leave with at least one useful recommendation — even if you never speak to us again.