Security posture
Our service desk engineers are remotely based and work Australian business hours through Australian-hosted systems. That model only works if the security architecture behind it is airtight — so here it is, published, in the same detail we hand to every prospective client before they sign.
The architecture
Engineers never connect to your systems from their own devices. All work happens inside a company-controlled virtual environment hosted in Australia — the technician operates a screen, not a copy of your data. Nothing is transferred, stored, or cached on the device in front of them.
These controls are written into our contractor agreements and internal standards — and disclosed to our team, so they work as deterrence, not just detection.
Every engineer works under their own identity with multi-factor authentication. No shared logins exist anywhere in our stack.
No standing admin rights. Elevated access is granted per task and expires automatically when the task is done.
Session recording on all client work, keystroke-level audit on privileged actions, and alerting on unusual data movement.
A single documented offboarding action revokes every credential and access path when anyone leaves our team — completed and verified same day.
Every engineer signs confidentiality and privacy obligations consistent with the Australian Privacy Principles, enforceable under their agreement with us.
Ask us for the access logs relating to your environment and we'll walk you through them. Controls you can't inspect aren't controls.
The bench
Every engineer must meet this standard — it's written into their agreement, credentials are verified with the issuing vendor before they start, and progression certs are funded and deadlined. Ask us and we'll show you the credential IDs for the engineers assigned to your environment.
Accreditation is a high priority — the certifications above are our hiring target, and we fund and deadline any an engineer hasn't yet completed. But paper alone never grants access: every engineer's skills are independently tested and verified through a live simulated-ticket assessment, and they complete internal training including the ACSC Essential Eight, before they touch a single client system.
Data locations
Engineers connect to your systems — your data doesn't move to them. Here's where the platforms we use to serve you hold data, stated per vendor. You receive this table, completed for your environment, before you sign.
| System | What it holds | Hosted in |
|---|---|---|
| Your Microsoft 365 tenant | Your email and files | Australia — per your tenant's data location |
| Remote monitoring & management | Device inventory, patch status, remote sessions | [Region — confirmed in writing per vendor] |
| Ticketing & service desk | Support requests and correspondence | [Region — confirmed in writing per vendor] |
| Documentation platform | Environment documentation, configurations | [Region — confirmed in writing per vendor] |
| Password management | Credential vault (zero-knowledge encrypted) | [Region — confirmed in writing per vendor] |
| Backup platform | Encrypted backups of covered systems | Australia — [confirmed in writing per vendor] |
Where an Australian data residency option exists, we use it. Where it doesn't, we tell you which region applies and what protects the data there — before onboarding, in writing.
When something goes wrong
Straight answers
Administrative access means the capability technically exists — that's true of any IT provider, onshore or offshore, including your current one. What protects you is controls, not geography: named and logged access, least privilege, binding contracts, and our willingness to show you the audit trail for your environment on request.
Our service desk engineers are remotely based and work Australian business hours under contracts governed by our Australian company. Before you sign, you receive our full security posture document, which names the countries involved, the systems used, and the controls around them. We'd rather you choose us knowing exactly how we work.
We build and measure client environments against the Australian Cyber Security Centre's Essential Eight, and we can evidence our own controls. We don't claim certification badges we don't hold — and we'd suggest asking any provider who does to show you the certificate.
We maintain a documented business continuity plan with tiered fallbacks, and your environment documentation is complete enough that any credentialed engineer can pick it up cold. Monitoring, backups, and your systems themselves are unaffected — they run in your tenancy and in Australian-hosted platforms, not on our engineers' desks.
Yes. Every prospective client receives our security posture document before signing — the same commitments as this page, completed with the specific vendors, regions, and contacts for your engagement. Bring your IT advisor or lawyer; we'll walk them through it.
The completed version of everything on this page — vendors, regions, controls, and contacts — sent with every proposal. Book a call and we'll prepare one for your environment.