Security is the job. Here’s how we do it.
Clients trust Macktez with the keys to their technology — identity, devices, servers, cloud, and data. We hold that access to a standard designed to align with NIST CSF, ISO 27001, and SOC 2. This page explains exactly how.
Last updated July 2026
Our Posture
A security program built for a firm that runs other people’s systems.
As a managed service provider, Macktez administers the infrastructure that organizations depend on every day. That responsibility sets the bar: the controls we recommend to clients are the controls we operate under ourselves. Since 1996 we have built and run infrastructure for finance, nonprofits, cultural institutions, media, and healthcare — environments where a lapse is not an option.
Our program is designed to align with the leading security frameworks. We are transparent about where that stands today, and about what we can share with clients and prospects under NDA.
Frameworks
Aligned to the standards that matter.
NIST Cybersecurity Framework 2.0
The National Institute of Standards and Technology's framework structures our program around six functions — Govern, Identify, Protect, Detect, Respond, and Recover. It's a voluntary standard you measure against, not a certification.
ISO/IEC 27001:2022
The international standard for an information security management system (ISMS). Our controls map to its four Annex A themes — organizational, people, physical, and technological. We run those building blocks; we are not certified against it.
SOC 2 Trust Services Criteria
System and Organization Controls, defined by the AICPA. We operate to its five criteria — Security, Availability, Processing Integrity, Confidentiality, and Privacy. SOC 2 is an attestation report from a CPA firm, not a certification.
A note on certification: Macktez is not currently the subject of a SOC 2 attestation and is not ISO 27001 certified — our program is designed and operated to align with these frameworks' controls, not audited against them. (A SOC 2 report is issued by a CPA firm and an ISO 27001 certification by an accredited auditor; neither is something a firm can self-declare.) We're glad to walk through our practices, complete a security questionnaire, or share documentation under NDA — and if your own organization needs to pass a vendor security review or a SOC 2 examination, helping you get audit-ready is work we do for clients.
Controls
How we protect your environment.
Privileged access to client systems
The access we hold to run your environment is the thing we guard most carefully.
- Every engineer uses a unique, named administrator identity — never shared logins
- Phishing-resistant multi-factor authentication on all administrative access
- Least-privilege, role-based access; elevated rights granted only when the work requires them
- Administrator credentials and secrets stored in a managed vault (1Password), never in plaintext or email
- Access reviewed regularly and revoked immediately when a team member's role changes
Identity & access management
Identity is the front door — for your organization and for ours.
- Single sign-on and MFA enforced across the platforms we manage
- Conditional access and device-trust policies where the platform supports them
- Joiner / mover / leaver workflows so access always matches current roles
- Built on JumpCloud, Microsoft Entra, and Okta — platforms we implement daily
Endpoint security
Every device we manage — and every device we work from — is hardened by default.
- Centrally managed via JumpCloud and Microsoft Intune
- Full-disk encryption enforced (FileVault, BitLocker)
- Endpoint detection and response (EDR) and managed antivirus
- Automated patching, screen-lock, and remote-wipe capability
Data protection & encryption
Client data is encrypted in transit and at rest, and we hold only what the work requires.
- TLS 1.2+ for data in transit; encryption at rest on the systems we manage
- Data minimization — we collect and retain only what an engagement needs
- Client environments and credentials kept logically separated
- Secure disposal and certified e-waste recycling for retired hardware
Network security
We design segmented, defensible networks and administer them the same way.
- Next-generation firewalls with segmentation between trust zones
- Zero-trust / VPN access for administration — no open inbound management ports
- Secured, monitored wireless; guest and corporate traffic separated
- Vendor-hardened configurations, documented and version-controlled
Email & phishing defense
Most incidents start in the inbox, so we close that door first.
- SPF, DKIM, and DMARC configured and enforced
- Advanced spam, malware, and link/attachment protection
- Impersonation and business-email-compromise safeguards
- Ongoing phishing awareness for our team and, on request, for yours
Monitoring, logging & alerting
We keep the records that let us see — and prove — what happened.
- Centralized logging across identity, endpoints, and infrastructure
- Alerting on anomalous authentication and administrative actions
- Log retention sufficient for investigation and review
- Regular review of security-relevant events
Vulnerability & patch management
Known problems get fixed on a schedule, not when they become incidents.
- Timely operating-system and application patching
- Vulnerability scanning with risk-based remediation
- End-of-life tracking so nothing runs unsupported unnoticed
- Hardened baselines applied at deployment
Incident response
When something does go wrong, we have a plan and we've practiced it.
- Documented incident-response plan with defined roles
- Clear client-notification expectations and communication paths
- Containment, eradication, and recovery procedures
- Post-incident review to close the underlying gap
Business continuity, backup & DR
Backups only count if they restore — so we test that they do.
- 3-2-1 backup strategy with encrypted, off-site copies
- Regular, verified restore testing — not just backup jobs that report success
- Documented recovery objectives (RTO/RPO) tuned to each client
- Redundancy designed into the infrastructure we build
Vendor & subprocessor management
We build on platforms that hold themselves to the standards we hold ourselves to.
- Primary platforms maintain their own SOC 2 and/or ISO 27001 attestations
- Integrations scoped to least privilege and reviewed periodically
- Representative subprocessor list published below
People & governance
Security is owned at the top and practiced by everyone.
- Background checks where permitted, and confidentiality agreements for all staff
- Structured onboarding and prompt offboarding of access
- Annual security-awareness training for the team
- Written policies, leadership ownership, and periodic risk assessment
Recognition
Recognized for identity and zero-trust expertise.
Macktez was named JumpCloud's MSP Partner of the Year for the Americas — a recognition of our work in identity, device management, and zero-trust implementation, the foundations of a strong security posture.

Subprocessors
The platforms we build on.
A representative list of the core platforms Macktez relies on to deliver its services. Each maintains its own security program and, in most cases, its own SOC 2 or ISO 27001 report — those audits belong to the vendor, not to Macktez. The exact set varies by engagement.
| Platform | Purpose |
|---|---|
| Microsoft 365 & Azure | Productivity, email, and cloud infrastructure |
| Google Workspace | Productivity and email |
| Amazon Web Services | Cloud infrastructure and storage |
| JumpCloud | Identity, SSO/MFA, and device management |
| Microsoft Entra & Okta | Identity and access management |
| 1Password | Credential and secrets management |
| NinjaOne | Remote monitoring and endpoint management |
| Freshservice | Service desk and ticketing |
Responsible Disclosure
Found something? Tell us.
If you believe you've found a security vulnerability in a Macktez system or a system we manage, we want to hear from you. Please reach out through our contact page with the details. We'll acknowledge your report, investigate promptly, and keep you informed. We ask that you give us reasonable time to remediate before any public disclosure, and that testing never disrupts service or accesses data that isn't yours.
Our machine-readable policy lives at /.well-known/security.txt.
Trust & Security
Need our security details for a review?
We're glad to complete a security questionnaire, walk your team through our controls, or share supporting documentation under NDA. Reach out and we'll get you what you need.