What we commit to in writing, how monitoring actually works, and what changes in your first 90 days
Most IT providers describe their service with adjectives. We would rather you could check ours. Everything on this page is specific, measurable, and something you can hold us to. Where we cannot evidence a claim yet, we say so rather than dress it up.
It is also here so you can read it before you talk to us, rather than receiving it at the end of a sales process.
Support hours and how to reach us. Monday to Friday, 08:00 to 18:00 AEST, excluding Victorian public holidays. One phone number, one email address, and a ticket link. Every request becomes a ticket, so nothing relies on someone remembering a conversation.
What we commit to. We commit to a response: a named person acknowledges your issue, tells you who is on it, and starts work. We do not commit to a fixed resolution time, because promising a repair window for an unknown fault is how providers end up breaking their own promises. Work continues until it is resolved or you agree to stop.
Every ticket records the time received, the time responded, and the time resolved. Your monthly report shows our performance against these targets, including the months we miss.
Patching and maintenance. Security patches are assessed as they are released and applied on a defined cadence: internet-facing and actively exploited issues within 72 hours, everything else within 14 days, with a change window agreed with you for anything disruptive. The monthly report lists what went out and what was deferred, with reasons.
Backup and recovery. Backups run daily and are monitored, with failures raised as P2. A restore is tested quarterly and the test result is included in your report, because an untested backup is not a backup. Retention is 30 days of daily restore points, longer where compliance requires.
Reporting and review. Monthly, a written report covering incidents, patching, backup status, monitoring highlights, and our response performance. Quarterly, a review with a written summary of what changed, what is at risk, and what to plan for. Annually, your IT roadmap and budget, so a refresh does not arrive as a surprise.
Escalation. If anything is not moving, it escalates to the person accountable, and we tell you who that is: the founder, by name, with a direct number. Nobody is asked to chase an account manager who has moved on.
Changes. We do not make unannounced changes to your systems. Material changes are described in plain language, scheduled with you, and reversible, with the rollback stated before we start.
Security incidents. If we suspect an incident we contact you within the P1 window, contain first where needed to protect your business, preserve what is needed for investigation, and tell you what we know and what we do not. We do not wait until an investigation is complete to tell you something is wrong.
Leaving, and what you take with you. Month to month, with no lock-in contract, no exit fee, and no notice period longer than 30 days. On exit you receive the full documentation set within 5 business days, in open formats, plus reasonable assistance handing over to whoever comes next. That assistance is included, not chargeable.
What is not included, so nobody discovers it later: hardware and licences are passed through at cost unless quoted otherwise; major projects are quoted separately; anything outside support hours other than P1 is next business day; and we are not your insurer, your legal adviser, or your compliance auditor.
Agents on your computers, servers and network report continuously. That telemetry is checked automatically, and anything suspicious is compared against current threat intelligence before a human sees it. An alert that matches something criminals are actively using today is treated differently from a first-time oddity, and that difference is decided by intelligence rather than by who happens to be on shift.
When something fires:
Every month you get a written report covering what was monitored, what alerted, what was investigated, what was closed, what we patched, and whether backups succeeded, along with our measured response performance.
What this is not. We do not operate a staffed 24/7 security operations centre: automated monitoring and alerting run continuously, and human triage runs in support hours plus the P1 on-call path. We do not publish an uptime percentage guarantee, because no small provider can honestly underwrite one. Monitoring is not insurance: it reduces the chance and the impact of an incident, and it does not transfer the risk.
The three things that actually make a business leave an IT provider are billing surprises, support that only appears when something breaks, and an environment nobody has written down. The third is the one that hurts quietly, because when the person who knew your network leaves, you find out how little of it was recorded. So this is a deliverable, not a chore, and it is yours whether you stay with us for ten years or ten weeks.
For every client we maintain:
You can request any of it at any time, and you receive the complete set within 5 business days on exit, in open formats, with no conditions attached to it.
Changing IT providers has a cost, and pretending otherwise would be dishonest. So nothing changes in your environment until three things exist: your environment is documented, the risks are written down with priorities, and you have approved in writing what we can access. That documentation is yours from day one, whatever you decide.
Days 1 to 30, stabilise. The top risks get fixed: unchecked backups, missing multi-factor authentication, unpatched internet-facing systems, departed staff who still have access. We verify your backups by restoring from them, not by reading a log that says they ran. Your ticket path goes live. Weekly check-ins. What deliberately does not change in month one: no migrations, no re-platforming, no changing your line-of-business software, and no removal of any existing tooling.
Days 31 to 60, standardise. Monitoring tuned to your environment so it alerts on what matters. A patch cadence agreed and running in a window that suits your business hours. Onboarding and offboarding runbooks tested with a real starter or leaver. First monthly report issued, including our measured response performance.
Days 61 to 90, improve. A costed roadmap for the year in plain business terms, a quarterly review scheduled, and anything your previous provider did well, kept. We are not going to change things just to look busy.
What we need from you. A named person with authority to approve changes, thirty minutes a week for the first month, and a current contact list for staff and key suppliers.
Stated deliberately, because you will hear the opposite elsewhere: