Read-only first
For an Audit, we request Reader and Cost Management Reader roles only. We do not need broad administrative access to make a cost and reliability assessment.
Security practices
Security terms are finalised in the engagement documents. This page describes the working defaults for an Azure Audit and the principles used in a delivery engagement.
For an Audit, we request Reader and Cost Management Reader roles only. We do not need broad administrative access to make a cost and reliability assessment.
If direct access does not fit your policy, send a Cost Management CSV export and join a focused walkthrough. We document the limits of that evidence path.
We use the agreed evidence to deliver the agreed work. We do not use client environments as demonstration material or share details without written permission.
Implementation work is separately scoped. Production changes follow the agreed approval, validation, and rollback path.
The final handover records the decision, assumptions, operating notes, and ownership so the client is not dependent on undocumented knowledge.
We do not store client access credentials. MFA is not enforced by Accepire. We do not require a dedicated identity, and a shared identity is acceptable where the client permits it.
We will notify the client within 12 hours if a security incident affects their data or environment.
We do not use subprocessors.
We do not hold professional indemnity insurance.
Data handling, confidentiality, liability, insurance details, retention, and any data-residency requirements are confirmed in the engagement letter.