Security posture


Our engineers see pixels. Your data stays put.

Our service desk engineers are remotely based and work Australian business hours through Australian-hosted systems. That model only works if the security architecture behind it is airtight — so here it is, published, in the same detail we hand to every prospective client before they sign.

The architecture


No data leaves Australia to reach a technician.

Engineers never connect to your systems from their own devices. All work happens inside a company-controlled virtual environment hosted in Australia — the technician operates a screen, not a copy of your data. Nothing is transferred, stored, or cached on the device in front of them.

  • Every session runs through an Australian-hosted secure workspace
  • Client data is viewed remotely, never downloaded or synced
  • Clipboard, file transfer, and local printing are disabled by policy
  • Sessions are recorded; privileged actions carry keystroke-level audit
ENGINEER screen only pixels SECURE WORKSPACE hosted in Australia logged YOUR SYSTEMS REMOTE AUSTRALIA data does not cross this line

Access controls, in plain terms.

These controls are written into our contractor agreements and internal standards — and disclosed to our team, so they work as deterrence, not just detection.

Named accounts only

Every engineer works under their own identity with multi-factor authentication. No shared logins exist anywhere in our stack.

Least privilege, just in time

No standing admin rights. Elevated access is granted per task and expires automatically when the task is done.

Everything logged

Session recording on all client work, keystroke-level audit on privileged actions, and alerting on unusual data movement.

Kill switch under five minutes

A single documented offboarding action revokes every credential and access path when anyone leaves our team — completed and verified same day.

Bound by contract

Every engineer signs confidentiality and privacy obligations consistent with the Australian Privacy Principles, enforceable under their agreement with us.

Show-me auditing

Ask us for the access logs relating to your environment and we'll walk you through them. Controls you can't inspect aren't controls.

The bench


A published certification standard, not a claim.

Every engineer must meet this standard — it's written into their agreement, credentials are verified with the issuing vendor before they start, and progression certs are funded and deadlined. Ask us and we'll show you the credential IDs for the engineers assigned to your environment.

Level 1 — (Service Desk) Help Desk Support

Who answers your tickets

Certification standard
  • —CompTIA A+ — hardware, operating systems, structured troubleshooting
  • —Microsoft MS-900 — Microsoft 365 fundamentals
  • —ITIL 4 Foundation — ticket, escalation & change discipline (within first 6 months)
  • —CompTIA Network+ & Microsoft AZ-900 — networking and Azure fundamentals
Level 2 — (Escalation & Systems) Sys Admin

Who handles the hard ones

Certification standard
  • —Cisco CCNA — routing, switching & network security
  • —Microsoft AZ-104 & MS-102 — Azure and Microsoft 365 administration
  • —Microsoft MD-102 — endpoint administration: Intune, Autopilot, your device fleet
  • —CompTIA Security+ plus backup & firewall vendor certification matching your stack
Level 3 — (Architecture & engineering) Senior Sys Admin / Engineer

Who designs and secures it

Certification standard
  • —Microsoft AZ-305 — Azure solutions architecture & secure design
  • —Microsoft SC-300 — identity & access administration: Entra, Conditional Access, PIM
  • —Cisco CCNP or equivalent — advanced networking & segmentation design
  • —CISSP (or SC-100 cybersecurity architect) — governance, risk & whole-of-environment security ownership

Accreditation is a high priority — the certifications above are our hiring target, and we fund and deadline any an engineer hasn't yet completed. But paper alone never grants access: every engineer's skills are independently tested and verified through a live simulated-ticket assessment, and they complete internal training including the ACSC Essential Eight, before they touch a single client system.

Data locations


Where your data actually lives.

Engineers connect to your systems — your data doesn't move to them. Here's where the platforms we use to serve you hold data, stated per vendor. You receive this table, completed for your environment, before you sign.

SystemWhat it holdsHosted in
Your Microsoft 365 tenantYour email and filesAustralia — per your tenant's data location
Remote monitoring & managementDevice inventory, patch status, remote sessions[Region — confirmed in writing per vendor]
Ticketing & service deskSupport requests and correspondence[Region — confirmed in writing per vendor]
Documentation platformEnvironment documentation, configurations[Region — confirmed in writing per vendor]
Password managementCredential vault (zero-knowledge encrypted)[Region — confirmed in writing per vendor]
Backup platformEncrypted backups of covered systemsAustralia — [confirmed in writing per vendor]

Where an Australian data residency option exists, we use it. Where it doesn't, we tell you which region applies and what protects the data there — before onboarding, in writing.

When something goes wrong


Incident response you can hold us to.

Named contactA single Australian point of contact owns every incident to resolution — you're never routed to a queue.
Defined severitiesDocumented severity levels with response targets written into your agreement, measured against AEST/AEDT.
30-day assessmentSuspected eligible data breaches are assessed within the Privacy Act's notifiable data breach timeframes, with your obligations supported end to end.
72-hour reportingWe support Cyber Security Act 2024 obligations, including the 72-hour ransomware payment reporting window where it applies to you.

Straight answers


The questions worth asking any provider.

Can your engineers read our email?

Administrative access means the capability technically exists — that's true of any IT provider, onshore or offshore, including your current one. What protects you is controls, not geography: named and logged access, least privilege, binding contracts, and our willingness to show you the audit trail for your environment on request.

Where is your team based, exactly?

Our service desk engineers are remotely based and work Australian business hours under contracts governed by our Australian company. Before you sign, you receive our full security posture document, which names the countries involved, the systems used, and the controls around them. We'd rather you choose us knowing exactly how we work.

Are you Essential Eight, ISO 27001, or SOC 2 certified?

We build and measure client environments against the Australian Cyber Security Centre's Essential Eight, and we can evidence our own controls. We don't claim certification badges we don't hold — and we'd suggest asking any provider who does to show you the certificate.

What happens if your remote team is suddenly unavailable?

We maintain a documented business continuity plan with tiered fallbacks, and your environment documentation is complete enough that any credentialed engineer can pick it up cold. Monitoring, backups, and your systems themselves are unaffected — they run in your tenancy and in Australian-hosted platforms, not on our engineers' desks.

Can we see the detail behind this page?

Yes. Every prospective client receives our security posture document before signing — the same commitments as this page, completed with the specific vendors, regions, and contacts for your engagement. Bring your IT advisor or lawyer; we'll walk them through it.


Get the full security posture document.

The completed version of everything on this page — vendors, regions, controls, and contacts — sent with every proposal. Book a call and we'll prepare one for your environment.