Trust & Security

How we protect the environments we manage

An IT provider holds keys to your business. This page describes the controls we actually apply — and is deliberately clear about what we do not claim.

This page is maintained by Nickel City Tech Solutions to answer common security and privacy questions about our services. It describes current practices — it is not an independent audit, a certification, or a legal guarantee.

Security controls we apply

Multi-factor authentication on management tools

Every administrative tool we use to reach client environments — remote monitoring, remote access, Microsoft 365 and Google Workspace administration, and our documentation platform — requires multi-factor authentication. There are no shared logins without MFA, and no exceptions for convenience.

Least-privilege access

Technicians hold the access their role requires and no more. Elevated and administrative access is granted for the work at hand rather than kept permanently open, and access is reviewed when roles change.

Encrypted credential storage

Client credentials are stored in an encrypted password management system with access controls and audit history. Credentials are never kept in spreadsheets, email, chat messages, or personal notes.

Monitored endpoints and logged remote sessions

Devices under management report health and security state continuously. Remote control sessions are consent-based on managed devices and are logged with the time, the technician, and the work performed.

Backup verification

Backup jobs on managed systems are monitored, and failures are treated as alerts rather than being quietly retried. Restore testing is performed for clients whose plan includes it, and results are reported.

Documented offboarding

When a staff member leaves your organization, we follow a documented offboarding process: account disable, session revocation, MFA method removal, mailbox handling, device retrieval or wipe, and licence reclamation — with a record of what was done.

Segmentation and firewall standards

Where we design or manage the network, guest, payment, operational, and staff traffic are separated, firewall rules are documented, and management interfaces are not exposed to the public internet.

Incident handling

Security incidents follow a defined path: contain, investigate, communicate, recover, and review. Clients receive a written summary of what happened and what changed afterwards.

Shared responsibility

Security is not delivered by one party alone. Here is how responsibility is split between us, the platforms we manage, and your organization.

What Nickel City Tech Solutions does

  • Applies and maintains the technical controls described on this page across managed environments
  • Monitors managed devices, patches them on schedule, and surfaces failures
  • Maintains documentation of your environment and the changes we make to it
  • Reports monthly on device health, patching, security posture, and backups
  • Coordinates with your other vendors on security-relevant issues

What the platforms and vendors do

  • Microsoft, Google, and other cloud providers operate their own platform security and availability
  • Security vendors maintain detection content and threat intelligence in their products
  • Hardware vendors supply firmware and security updates for their devices
  • Certifications held by those vendors belong to those vendors, not to us

What your organization is responsible for

  • Deciding who should have access to what, and telling us when that changes
  • Approving security recommendations and funding the controls you accept
  • Staff behaviour — reporting suspicious email, not sharing credentials, following your own policies
  • Regulatory and contractual compliance obligations that apply to your business

What we do not claim

We are not SOC 2, ISO 27001, PCI, or HIPAA certified, and we do not certify your business either.

We do not guarantee that a breach, outage, or data loss will never occur. No provider honestly can.

Vendor certifications belong to those vendors — using a certified platform does not make us certified.

Compliance obligations under PHIPA, PIPEDA, or your industry regulator remain with your organization. We build and document the technical controls that support them.

Security questions we get asked

Are you SOC 2 or ISO 27001 certified?

No. Nickel City Tech Solutions does not hold SOC 2, ISO 27001, or any equivalent certification, and we will not imply otherwise. We apply the security practices described on this page, and we help clients prepare for their own audits through our SOC 2 readiness support service. Any certification claims you see about the platforms we use belong to those vendors.

Who at your company can access our systems?

Access is limited to technicians working on your environment, through managed tooling that requires multi-factor authentication and records session activity. Administrative access is granted for the task and reviewed as roles change.

Where are our credentials kept?

In an encrypted password management platform with role-based access and an audit trail. They are not stored in email, chat, spreadsheets, or documents.

Do you keep copies of our data?

We do not take our own copies of your business data. We configure and monitor backup systems that store your data under your own retention settings, and we hold documentation about your environment — configurations, inventory, and procedures — rather than your files.

What happens if you are breached?

We would contain the incident, determine which client environments were affected, notify affected clients directly with what we know, take remediation steps including credential rotation, and follow up with a written review. No provider can promise a breach will never happen; what we can commit to is honest, prompt communication if one does.

Can you complete our security questionnaire?

Yes. We regularly complete client and insurer security questionnaires covering access control, MFA, backup, patching, and incident handling. Ask us and we will work through yours.

Have a security or privacy question?

Ask directly. We will give you a straight answer, including when the answer is "we don't do that."

Related

Security services and platforms

Services

Helpful resources