The questions people actually ask.

Straight answers on pricing, transitions, coverage, and what we will and won’t claim — including the ones most providers prefer to leave until the second call.

01
Pricing and agreements
02
Switching providers
03
Coverage and response
04
Compliance and security
FAQ

Pricing & Agreements

Money questions first.

Why isn’t pricing on the website?

Because two fifty-person companies can differ threefold in what they need. A published number would be either meaningless or misleading, and you’d find out which after signing.

What drives the cost?

Headcount and device count first, then service level, compliance obligations, infrastructure complexity, and number of locations.

Are there hidden costs?

Additional charges are defined in the agreement rather than discovered on an invoice. Out-of-scope work is raised before it happens.

Can we start with one service?

Yes. Email security and backup are common entry points, and plenty of clients expand from there.

Switching & Onboarding

Changing providers.

Will there be downtime?

Onboarding is designed to avoid it. Anything carrying risk is staged into agreed windows and communicated in advance.

How long does it take?

Typically a few weeks. Documentation and discovery take the most time, and rushing that is what causes problems later.

What if our provider won’t cooperate?

It happens. Access and documentation can usually be rebuilt through ownership verification with vendors directly.

Do we keep our data?

Always. Your documentation, data, and administrative access remain yours throughout and on exit.

Coverage & Response

What happens when something breaks.

Do we get the same person each time?

You have a named lead who knows your account. Others provide coverage, but they work from real documentation rather than guesswork.

What are your response times?

They vary by service level and priority and are written into the agreement rather than described vaguely.

Is coverage really around the clock?

Yes — detection, response, and escalation run every day of the year, not a voicemail box after five.

Compliance & Security

What we will and won’t claim.

Can you certify us?

No. Certification comes from an independent auditor. We implement the controls and produce the evidence, and we’ll say plainly where our role ends.

Will you sign a BAA?

Yes, where we handle systems touching protected health information.

Which frameworks do you handle?

HIPAA, SOC 2, ISO 27001, NY DFS Part 500, PCI DSS, and the education-sector rules including FERPA and Ed Law § 2-d.

What if we’re breached?

Containment first, then recovery on a documented order, then a written report of what happened and what changed as a result.

Something we didn’t cover?

Ask directly. You’ll get a straight answer, including when the answer is that we’re not the right fit.