1. Purpose and Applicability
These policies apply to Compudile Managed IT / MSP Services.
They supplement applicable signed agreements. They do not replace those agreements.
They describe operational procedures and service-administration practices for support, security operations, access, maintenance, and related MSP operations.
Client-specific terms remain in the applicable MSA, Schedule, SOW, Order, quote, or amendment.
These policies are intended for Client executives, office managers, IT contacts, technical staff, and compliance reviewers.
2. Approved Support Channels
Clients should use Compudile-approved support channels, such as:
- the Compudile support portal
- the ticketing system
- support email
- telephone
- approved remote-assistance tools
Do not send privileged credentials through unapproved channels.
Emergency communication methods may differ depending on the Client's service plan and the contacts designated for that engagement.
Telephone (public): +1 (813) 444-0110
3. Business Hours and After-Hours Services
Routine support is delivered during Compudile's regular business hours unless a signed agreement provides otherwise.
After-hours and emergency services are excluded unless they are specifically included in the Client's plan or separately authorized in writing.
After-hours work may be separately quoted or billed under the applicable signed agreement. This page does not publish a universal after-hours rate.
4. Ticket Submission and Priority Classification
Clients should submit requests through an approved channel and include enough information for Compudile to assess impact: who is affected, what changed, when it started, and any security concern.
Compudile classifies tickets using the following operational categories:
P1 - Critical
Examples: a business-stopping outage; multiple users unable to work; active ransomware indicators; a major production outage.
P2 - High
Examples: a critical single-user or single-system issue; a degraded core business service.
P3 - Normal
Examples: a standard workstation issue; a printer issue; a mail issue; a supported application issue.
P4 - Low
Examples: non-urgent moves or adds; planning questions; other low-impact requests.
Priority is assigned or adjusted by Compudile based on business impact, security implications, users affected, operational severity, and the information available.
This page does not create guaranteed resolution times. Any response targets in a signed SLA, if present, are commercially reasonable goals unless that signed instrument expressly provides otherwise.
5. Remote-First Support
Where reasonable, Compudile normally attempts remote diagnosis and remediation first.
Remote-first support is intended to reduce downtime and speed resolution.
On-site dispatch is used when Compudile reasonably determines that remote resolution is insufficient for a covered incident.
6. On-Site Support Procedures
On-site service is dispatched based on technical need and the Client's contracted scope.
Included visit quantities and hours, if any, are determined only by the Client-specific Schedule or other signed instrument.
Projects, infrastructure installation, structured cabling, office moves, physical hardware repair, mass deployments, and similar work are not ordinary on-site support unless expressly included.
This page does not publish Client-specific visit counts or on-site rates.
7. Managed Endpoint Enrollment
A device becomes a managed endpoint when it is placed under Compudile management and enrolled in the applicable management or security platform.
Enrollment may include installation or activation of tools such as:
- RMM
- EDR / XDR
- a management agent
- monitoring
- remote-support tooling
- device policy enrollment (for example MDM)
Billing and coverage begin according to the applicable signed Schedule or Order.
Removal from management may require proper agent removal, decommissioning, license release, and other administrative steps.
8. Patch Management and Maintenance
For covered systems, Compudile may perform commercially reasonable maintenance, including:
- routine operating-system patching
- security updates
- scheduled maintenance
- reboots where necessary
- emergency security remediation
- maintenance windows
Compudile may perform reasonable maintenance necessary to protect or maintain covered systems.
Where practical, Compudile will coordinate material interruptions with the Client's designated contacts.
9. Cybersecurity Operations
Where included in the Client's Services, Compudile may perform cybersecurity operations such as:
- EDR / XDR operation
- security monitoring
- security-alert review
- malware / ransomware response
- compromised-account response
- device isolation or containment where appropriate
- MFA administration
- account lockout and credential reset
- endpoint-agent health monitoring
- response to suspicious activity
No security control guarantees absolute protection. Compudile does not guarantee that all threats will be prevented or detected, and does not guarantee the Client's overall regulatory or HIPAA compliance.
Client cooperation and sound security practices remain required.
10. Privileged and Administrative Access
During the Managed Services relationship, Compudile requires and maintains the privileged or global administrative access reasonably necessary to secure, manage, monitor, and support the Managed Environment, as authorized under the applicable signed MSA.
As applicable to the Services, that access may include:
- Microsoft 365
- Entra ID
- Google Workspace
- Active Directory
- servers
- endpoints
- firewalls
- switches
- access points
- network-management platforms
- RMM
- MDM
- EDR / XDR
- backup platforms
- cloud environments
- DNS
- managed SaaS / vendor portals
Least privilege may be used. Privileged access may be restricted. Ordinary users and unauthorized third parties may not receive unrestricted administrative access.
This operational access does not transfer ownership of Client data, tenants, accounts, domains, or assets.
These policies do not weaken, limit, or replace the privileged / Global Admin provision in the signed MSA. That contractual authorization controls.
11. Client-Requested Administrative Access
If a Client requests privileged access contrary to Compudile's security recommendations, Compudile may require:
- written authorization
- a risk acknowledgment
- identification of the requesting party
- documentation of the exception
Compudile may refuse access where granting it would expose other clients, Compudile systems, multi-tenant systems, master credentials, internal API secrets, or other protected infrastructure.
12. User Onboarding and Offboarding Requests
For user onboarding or offboarding, Compudile may require information such as:
- employee / user name
- start or end date
- department / role
- manager
- systems and applications required
- mailbox access
- shared mailbox or group membership
- security-group access
- file / resource permissions
- device assignment
Client management is responsible for authorization and timely notice.
13. Access Changes and Terminated Users
Clients should promptly notify Compudile when:
- an employee is terminated
- an employee changes role
- a device is lost or stolen
- credentials may be compromised
- access must be revoked
Compudile may act quickly to disable accounts, revoke sessions, reset credentials, or take other reasonable protective actions.
14. Third-Party Vendor Access
Vendor access to managed systems may require Client authorization.
Least privilege should be used. Temporary access should be used when practical. Vendor access may be documented and revoked after the work is complete.
Compudile may require vendor participation before altering proprietary applications, databases, EMR / EHR systems, or vendor-controlled platforms.
15. Unsupported / End-of-Life Technology
Compudile may identify end-of-life, end-of-support, or otherwise unsupported technology.
Compudile may recommend replacement, isolation, upgrade, or remediation.
Unsupported technology may be excluded from applicable SLA and security commitments.
Client refusal may be documented as a security or operational exception.
This page does not promise support for unsupported technology.
16. Backup Operations
These backup procedures apply only when backup services are expressly included in the applicable signed Schedule or Order.
Operational activities may include:
- backup configuration
- backup monitoring
- failed-job review
- alert handling
- storage monitoring
- restoration assistance
- retention according to the contracted plan
Backup scope and retention are Client-specific. This page does not create a universal retention period.
Advanced disaster-recovery or business-continuity services may require a separate agreement.
Backup cannot guarantee successful restoration under every circumstance.
17. Change Management
Material changes may require authorization, including:
- firewall changes
- DNS changes
- Microsoft 365 security changes
- network changes
- identity / access changes
- server changes
- security-policy changes
- vendor integrations
Compudile may document significant changes and approvals.
18. Security Incident Reporting
Clients should promptly contact Compudile through an approved channel when they suspect:
- phishing
- credential theft
- malware
- ransomware
- unauthorized access
- a suspicious login
- a lost or stolen device
- unusual account activity
- suspected data exposure
Security events involving PHI / ePHI are also governed by the applicable Business Associate Agreement where one exists.
This page does not publish a breach-notification deadline. Any statutory or contractual deadline in a signed BAA controls.
19. Security Containment Actions
When reasonably necessary to protect Client systems or other environments, Compudile may:
- isolate endpoints
- disable accounts
- revoke sessions
- block suspicious traffic
- disable compromised credentials
- temporarily restrict access
- suspend risky vendor access
These actions should be proportionate to the perceived risk and operational circumstances.
20. Client Operational Responsibilities
Clients are expected to:
- maintain accurate authorized-contact information
- provide timely approvals
- promptly report security issues
- notify Compudile of employee changes
- maintain required licenses
- maintain supported systems
- not disable RMM, EDR, or other security agents without Compudile coordination
- not permit unauthorized vendors to alter managed systems
- cooperate with remediation
- maintain internal privacy, security, and workforce policies
22. Scheduled Maintenance and Service Interruptions
Routine maintenance may occur. Emergency maintenance may occur where necessary for security or stability.
Compudile will use reasonable efforts to limit disruption.
Third-party outages are outside Compudile's direct control.
23. Third-Party Platforms and Service Dependencies
Managed Services may depend on third parties such as:
- Microsoft
- Internet service providers
- cloud providers
- telecom providers
- security vendors
- software vendors
- hardware vendors
Compudile cannot guarantee the availability, pricing, functionality, or performance of third-party services. Compudile is not automatically in breach for outages or failures primarily caused by those parties outside Compudile's reasonable control.
24. Medical / HIPAA Environments
Medical or other Covered Entity Clients may require a separate Business Associate Agreement.
PHI / ePHI handling is governed by the BAA when applicable.
This web policy is not a BAA.
Compudile's technical services alone do not guarantee HIPAA compliance.
25. Client Data and Ownership
Client retains ownership of Client data.
Client retains its rights in Client-specific tenants, accounts, and domains.
Client-purchased assets remain Client property.
Compudile administrative access does not transfer ownership.
Compudile retains ownership of its internal tools, automation, methodologies, scripts, templates, multi-tenant systems, and proprietary technology.
26. Operational Offboarding
Offboarding is coordinated through the applicable signed Agreement.
Client-specific documentation, configuration information, transition records, and Client-specific administrative credentials are delivered through formal offboarding.
Compudile does not disclose master credentials, internal Compudile credentials, multi-tenant credentials, internal API keys or secrets, credentials that would expose other clients, or Compudile-controlled vendor master accounts.
Extraordinary transition work may be separately billable.
Payment, notice, early-termination, and invoice mechanics remain controlled by the signed contract and are not restated on this page.
27. Policy Updates
Compudile may update these operational procedures from time to time.
Updates may address support processes, security procedures, maintenance practices, ticket workflows, technical standards, and service administration.
Operational web-policy updates may not silently modify material negotiated contractual terms.
28. Contractual Priority
These Managed Services Policies provide operational procedures and administrative standards for services delivered by Compudile, Inc. They supplement, but do not replace, the applicable signed Master Managed Services Agreement, Service Schedule, Statement of Work, Order, or other executed agreement.
In the event of a conflict, the signed agreement controls.
These online policies may not be used to unilaterally modify material contractual terms including pricing, contract duration, renewal, termination rights, early termination obligations, limitation of liability, indemnification, dispute resolution, arbitration, privileged administrative access rights, or other negotiated material terms.
29. VoIP and Telecommunications Services
Voice, SIP, hosted PBX, messaging, telecommunications, fax, and related communications services are governed separately and are not automatically governed by these Managed Services Policies.
30. Contact Information
Compudile, Inc. 4023 N Armenia Ave, Suite 105 Tampa, Florida 33607
Website: https://compudile.com
Telephone: +1 (813) 444-0110
General sales email: sales@compudile.com
Legal notice email: legal@compudile.com