// Trust

Security baseline


The minimum protections we expect in every managed environment, with additional controls applied where the business, data, or compliance requirements call for them.

Last updated: August 18, 2026

Security works better when the basics are consistent. Vulpine maintains a documented baseline for the systems we manage so common protections are not left to chance or applied differently from one device or client to another.

The exact controls vary by service package, licensing, platform, and regulatory requirements. During onboarding we document the current state, identify gaps, and build the work needed to bring the environment into alignment.

Our managed-security baseline

Managed endpoints


Supported operating systems, active monitoring and patch management, managed endpoint protection, and full-disk encryption where supported. Devices that can no longer be secured or reliably managed are documented for replacement or remediation.

Identity and MFA


Multi-factor authentication is enforced for administrative access, remote access, and supported cloud services. Administrative privileges are limited to people and systems that require them, and legacy authentication is disabled where supported.

Microsoft 365 and cloud security


Email and collaboration environments are configured with appropriate anti-phishing, anti-malware, access, sharing, forwarding, and audit controls based on the client's licensing and service package.

Network security


Business networks use managed firewalling, maintained firmware, secure remote-access methods, and separation of guest or untrusted devices where appropriate. Internet-facing services are not exposed unnecessarily.

Patching and vulnerability management


Operating systems and managed applications are kept current through automated patching and monitoring. Critical vulnerabilities are reviewed promptly, with remediation prioritized according to severity, exposure, and operational impact.

Backup and recovery


Covered systems and cloud data are backed up according to the client's service package. Backups are monitored, recovery procedures are documented, and scheduled restore testing is used to verify that protected data can actually be recovered where included in the service package.

Security awareness


Where included in the service package, users receive ongoing security-awareness training and phishing simulations. Security controls are reinforced with practical guidance instead of relying on training alone.

Incident response


Suspected compromises are investigated and contained as quickly as practical. Vulpine may isolate managed devices, disable access, reset credentials, or coordinate with other providers when necessary to protect the client environment.

Documentation and evidence

A security control is much more useful when you can prove it exists. We maintain documentation appropriate to the services we manage, including configuration records, security findings, backup and restore evidence, and other operational records used during reviews, insurance renewals, and compliance work.

Exceptions

Not every environment can meet every control immediately. Legacy applications, vendor requirements, unsupported hardware, and business constraints sometimes create exceptions. When that happens, we document the issue, explain the risk, and recommend a practical path forward rather than quietly treating the exception as normal.

Plain-English summary

This page is a plain-English summary of our general managed-security baseline, not a guarantee that every listed feature is included in every package. It is not a contract. The Master Services Agreement controls, followed by the Services Guide, and then the signed Quote for client-specific commercial terms.

Ask about your environment

Request an IT assessment


We will tell you plainly where your current setup stands against this baseline.

We respond within one business day to schedule the 30-minute discovery call.