Who can access your systems, and under what controls.
Attackers increasingly target IT providers to reach their clients. We hold ourselves to the same controls we implement for our customers, and we are transparent about how we work.
How we protect our access to you.
Hardware-key MFA
Every engineer signs in with a phishing-resistant FIDO2 security key. No shared admin accounts.
Time-limited admin
Nobody, human or automation, has standing global admin rights. Access is granted per task and expires.
Recorded sessions
Privileged work in your environment is recorded and logged.
Managed devices only
Engineers work only from company-owned, managed, encrypted laptops. Never personal devices.
Vetted people
Background checks and signed confidentiality and IP agreements for every employee.
Secrets in a vault
Credentials live in a vault, are rotated regularly, and never appear in tickets, scripts or AI prompts.
One accountable team, available 24/7.
Your environment is managed by IDrovance's own engineering and operations team. Administrative access is limited to named IDrovance engineers, and every specialist partner involved in delivering the service is listed in our subprocessor list.
Our service desk is available 24/7, 365 days a year, with a 15-minute response to critical issues. Threat monitoring and response run continuously, and planned maintenance is scheduled outside your business hours.
Your data
- Your data stays in your own Microsoft 365, Google and SaaS tenants
- We store only tickets, documentation and vaulted credentials
- No customer data on engineer laptops
- A data processing agreement (DPA) with every customer
- Breach notification to you within 72 hours
- A published list of our subprocessors
Specialized requirements, planned from day one.
Some environments carry specific requirements, such as regulated health data, government contracts or regular on-site work. We identify these in discovery and agree the right controls, people and partners before work begins.
Insurance certificates, our DPA and completed security questionnaires are available on request.
- Regulated data handling agreed in writing
- On-site support through vetted field partners
- Access and data-location terms set out in your contract
- Controls mapped to your compliance obligations
AI never holds the keys to your environment.
AI can read, summarize and suggest. Any change goes through our controlled gateway with scoped credentials, an allow-list, human approval for anything that matters and a full audit log. Password resets, MFA and access rights are handled only by people. One switch turns off all AI actions across every customer.
Need our security questionnaire answers?
We'll send our completed questionnaire, DPA and insurance details for your vendor review.