Security

How We Secure Access.

Remote support means trusting someone inside your systems. Here is exactly how that access works, what limits it, and how you stay in control of it.

Most support providers ask for an admin account and a leap of faith. We built our access model the way we build client environments: least privilege, verified identity, and a full audit trail. Every control below is enforced by configuration, not by policy documents.

Control 01

No Standing Admin Access

We connect through Microsoft’s delegated access model (GDAP), scoped to only the roles a task requires. Privileged rights are elevated just in time, expire automatically, and are never held permanently.

Control 02

Verified People, Verified Devices

Every technician is background checked and signs in with phishing-resistant multi-factor authentication, from a company-managed device that must pass compliance checks before access is granted. Personal devices cannot connect. Ever.

Control 03

Your Data Stays in Your Tenant

All work happens inside your Microsoft 365 environment. We do not copy, export, or store your business data on our systems, and nothing about your environment leaves your tenant.

Control 04

Everything Is Logged, and You Hold the Keys

Every sign-in and every administrative action lands in your own audit logs, visible to you at any time. Our access can be reviewed on demand and revoked by you in one click. That is by design.

One Contract, US Accountability

Your agreement is with CoachToph LLC, a Maryland limited liability company, under US law and US insurance. Delivery is performed by our vetted global team operating under every control on this page, with escalation to our Maryland-based principal.

Want the details in writing? Request our security one-pager, or bring your IT or compliance questions to a call. We would rather answer them before you sign than after.