Privacy Policy

We manage systems, identities, and data on behalf of our clients. We hold ourselves to the standard we recommend to them.

Governance

Firm leadership approves security policy, owns the risk register, and reviews the control environment at least annually. Our policies rest on four principles.

01. Access is limited to a legitimate business need and granted on least privilege.

02. Controls are layered rather than relied on individually.

03. The same standard applies to our corporate systems and our client delivery tooling.

04. Controls mature iteratively, measured by effectiveness, auditability, and friction.

Our control environment is aligned to CIS Critical Security Controls v8 and mapped to the NIST Cybersecurity Framework.

Client Environment Access

Our access to client systems is the control that matters most, and it is governed more tightly than our own.

Named credentials. Every technician holds unique named credentials in each client environment. Shared administrative logins are not used.

Ticket-bound provisioning. Access is requested and approved in ConnectWise, tied to a ticket and a named requester, and revoked at engagement close, role change, or separation.

Vaulted credentials. Client credentials sit in an access-controlled vault segmented by client, limited to the assigned delivery team. Credentials are never sent by email, chat, or ticket text.

Data Protection

Data in transit. TLS 1.2 or higher everywhere data crosses an untrusted network.

Data at rest. Platform-native encryption in Microsoft 365, Google Workspace, our hosting environments, and our backup service. Endpoints use enforced full-disk encryption with recovery keys escrowed centrally.

Secret management. Credentials and API keys are held in an enterprise password manager or platform secret store, scoped by role. Repositories are scanned for committed secrets.

Retention. Retention follows the governing agreement. At engagement close, client data is returned or destroyed on request, and devices are sanitized before reuse or disposal.

Enterprise Security

Identity and access. We run Microsoft 365 with Entra ID and Google Workspace, each user assigned to one as their identity provider. Multifactor authentication is required on every account, legacy authentication is blocked, privileged roles are reviewed quarterly, and accounts are deprovisioned the day a person separates.

Endpoint protection. Windows devices are managed through Microsoft Intune and Apple devices through Apple Business Manager, enrolled before issue and not removable by the user. Managed detection and response with 24/7 monitoring runs on every endpoint.

Secure remote access. Remote access runs over Tailscale, an identity-aware network built on WireGuard, scoped to the systems each role needs. Nothing is published to the public internet. Perimeter security uses centrally managed Fortinet firewalls.

Email security. A secure email gateway provides attachment sandboxing, link inspection, and impersonation protection. SPF, DKIM, and DMARC are enforced on all sending domains.

Security education. Training at onboarding and annually, with simulated phishing. Staff with administrative access to client environments are background screened.

Vendor security. Vendors are assessed on their access to data, their integration with production, and the exposure they create. Delivery partners work under written agreements, use Facet-managed identities, and meet the same access requirements as employees.

Monitoring And Response

Detection. Endpoint and identity telemetry is monitored continuously by a security operations center with escalation to our on-call engineer. Audit and sign-in logging is retained on both cloud platforms.

Vulnerability management. Findings are prioritized by exploitability and exposure. Fixes that miss the standard window are documented with a compensating control and a target date.

Incident response. We maintain a documented plan with defined severity levels and escalation paths. Clients affected by an incident are notified within the timeframe set by their agreement, or within 72 hours of confirmation where it is silent.

Backup and recovery. Both cloud platforms are backed up to an independent service with point-in-time recovery. Client backups are monitored per contract and restores are tested.

Documentation

Available to clients and prospective clients under mutual NDA:

  • Security policies and standards
  • Network and identity architecture diagrams
  • Certificate of cyber liability insurance
  • Completed CAIQ Lite or SIG Lite questionnaire
  • Incident response plan summary

We complete client security questionnaires and accept contractual security terms, including data processing addenda and breach notification. Where regulated data is in scope, we execute a business associate agreement or equivalent. For personal information, see our privacy policy.

Reporting A Security Concern

Report a suspected vulnerability in any Facet Interactive system, or a system we manage, to [email protected]. We acknowledge reports within one business day. Please give us reasonable time to remediate before public disclosure.

Last updated: August 27, 2026