Trust and security
We hold the keys. Here is how we treat them.
A managed provider has privileged access to everything it protects, which makes the provider itself worth asking questions about. These are the answers, including the ones that are uncomfortable.
What access we actually hold
Being straightforward about this is more useful than being vague. To do the work, we hold administrative access to your endpoints through the management agent, administrative access to your Microsoft 365 or Google Workspace tenant, and access to your backup platform. We do not need, ask for, or hold access to your practice management or clinical records beyond what is required to protect and back up the systems they live on.
Our commitments
Six things you can hold us to.
Every technician account is individual
No shared logins into your environment. Every action is attributable to a named person, which is what makes an audit trail worth anything.
Multi-factor on every account that touches your systems
Ours as well as yours. A provider that enforces multi-factor on clients and not on itself is the weakest link in its own supply chain.
Least privilege, reviewed rather than accumulated
Access is granted for a reason and removed when the reason ends. Standing access that nobody can justify is how a provider becomes an attack path.
Your credentials are never stored in plain text
Secrets live in a password manager with access controls and an audit log, never in a spreadsheet, a ticket note or an email.
You are told about an incident affecting you
Promptly, in writing, with what we know and what we do not yet know. Not after we have worked out how to frame it.
Your data leaves with you
On request or on exit, in a usable format, along with the documentation. No hostage-taking of credentials or configuration, and no fee to be given back what is already yours.
Subprocessors
Who else touches your data
Delivering these services means client data passes through platforms we did not build. Naming them is the only honest way to answer the question, and your own compliance obligations may require you to know.
| Vendor | What they do | Data involved |
|---|---|---|
| Ironscales | Email security. Analyses message content and metadata inside your mailboxes. | Email content and metadata |
| Microsoft | Where your Microsoft 365 tenant and its data already live. | Email, files, identity |
This list changes when our tooling changes. If you need to be told when it does, say so and we will add you to the notice list.
Reporting something to us
If you believe you have found a security issue in this website, in ProphyPost or in ProphyCapture, we would rather hear about it than not. Email us with the details and give us reasonable time to respond before disclosing publicly. We will not pursue anyone acting in good faith who reports a genuine issue.
admin@minnovatenetworks.comStart with the assessment.
It is free, it is done remotely in about an hour, and it ends with a written picture of your environment and its risks that is yours to keep. No obligation and no contract attached.