Read-only first
For an Audit or Readiness Sprint, we request Reader and Cost Management Reader roles only. We do not need broad administrative access and make no production changes during assessment work.
Security practices
Security requirements are agreed before access is requested. This page describes Accepire’s current working defaults and states the limitations a security or procurement reviewer should know early.
For an Audit or Readiness Sprint, we request Reader and Cost Management Reader roles only. We do not need broad administrative access and make no production changes during assessment work.
For direct access, we ask the client to issue a named, time-bounded identity and apply its own MFA and conditional-access policy. Accepire does not store client credentials. Access should be revoked when the agreed evidence work ends.
If direct access does not fit your policy, provide agreed exports and join a focused walkthrough. We document what could not be verified through that evidence path.
We use the agreed evidence only to deliver the agreed work. We do not use client environments as demonstration material or disclose engagement details without written permission.
The engagement letter records what evidence may be retained, where it is handled, and the deletion or return date. Do not send credentials or unnecessary personal data through website forms.
Implementation work is separately scoped. Production changes follow the agreed approval, validation, access, and rollback path.
We notify the client within 12 hours if a confirmed security incident affects its data or environment, then follow the notification and cooperation terms in the engagement documents.
Accepire does not use delivery subcontractors by default. Website providers used for analytics, forms, and scheduling are listed in the privacy notice. Any third party required for an engagement is disclosed and agreed before access.
Accepire does not currently hold professional indemnity insurance. If insurance is mandatory, we must agree an insured prime-contractor route or decline the engagement.
Data handling, confidentiality, liability, retention, access revocation, and any data-residency requirements are confirmed in the engagement letter.
We use Google Tag Manager, Google Analytics, and Microsoft Clarity to understand how the site is used. No analytics run until you choose. Privacy details