Book a 20-minute Azure review

Security practices

Minimum access. Clear purpose. Written handover.

Security terms are finalised in the engagement documents. This page describes the working defaults for an Azure Audit and the principles used in a delivery engagement.

Read-only first

For an Audit, we request Reader and Cost Management Reader roles only. We do not need broad administrative access to make a cost and reliability assessment.

CSV alternative

If direct access does not fit your policy, send a Cost Management CSV export and join a focused walkthrough. We document the limits of that evidence path.

Purpose limitation

We use the agreed evidence to deliver the agreed work. We do not use client environments as demonstration material or share details without written permission.

Change control

Implementation work is separately scoped. Production changes follow the agreed approval, validation, and rollback path.

Knowledge transfer

The final handover records the decision, assumptions, operating notes, and ownership so the client is not dependent on undocumented knowledge.

Access handling on our side

We do not store client access credentials. MFA is not enforced by Accepire. We do not require a dedicated identity, and a shared identity is acceptable where the client permits it.

Incident notification

We will notify the client within 12 hours if a security incident affects their data or environment.

Subprocessors

We do not use subprocessors.

Insurance

We do not hold professional indemnity insurance.

Contract details

Data handling, confidentiality, liability, insurance details, retention, and any data-residency requirements are confirmed in the engagement letter.