Services Guide
This Services Guide contains provisions that define, clarify, and govern the scope of the services described in the quote that has been provided to you (the “Quote”), as well as the policies and procedures that we follow (and to which you agree) when we provide a service to you or facilitate a service for you. If you do not agree with the terms of this Services Guide, you should not sign the Quote and you must contact us for more information.
This Services Guide is our “owner’s manual” that generally describes all managed services provided or facilitated by Enstep Technology Solutions (“Enstep,” “we,” “us,” or “our”); however, only those services specifically described in the Quote will be facilitated and/or provided to you.
This Services Guide is governed under our Master Services Agreement (“MSA”). You may locate our MSA through the link in your Quote or, if you want, we will send you a copy of the MSA by email upon request. Capitalized terms in this Services Guide will have the same meaning as the capitalized terms in the MSA, unless otherwise indicated below.
Activities or items that are not specifically described in the Quote will be out of scope and will not be included unless otherwise agreed to by us in writing.
Please read this Services Guide carefully and keep a copy for your records.
Initial Audit / Diagnostic Services
In most cases, we will conduct an initial audit of your information technology (IT) environment to determine the readiness for, and compatibility with, our proposed ongoing managed services. This audit may be comprised of some or all the following:
If deficiencies are discovered during the onboarding process (such as outdated equipment or unlicensed software), we will bring those issues to your attention and discuss the impact of the deficiencies on our provision of the Services and provide you with options to correct the deficiencies. Please note, unless otherwise expressly agreed by us in writing, auditing services do not include the remediation of any issues, errors, or deficiencies (“Issues”), and we cannot guarantee that all Issues will be detected during the onboarding process. Issues that are discovered in the Environment after the auditing process is completed may be addressed in one or more subsequent quotes.
Onboarding Services (Standard)
Onboarding is the stage during which we prepare your IT environment for the monthly managed services described in the Quote. During this phase, we will work with your Authorized Contact(s) to review the information we need to prepare the targeted environment, and we may also:
Applicable to both basic and standard onboarding:
This list is subject to change if we determine, at our discretion, that different or additional onboarding activities are required.
If deficiencies are discovered during the onboarding process, we will bring those issues to your attention and discuss the impact of the deficiencies on our provision of our monthly managed services. Please note, unless otherwise expressly stated in the Quote, onboarding-related services do not include the remediation of any issues, errors, or deficiencies (“Issues”), and we cannot guarantee that all Issues will be detected during the onboarding process.
The duration of the onboarding process depends on many factors, many of which may be outside of our control—such as product availability/shortages, required third party vendor input, etc. As such, we can estimate, but cannot guarantee, the timing and duration of the onboarding process. We will keep you updated as the onboarding process progresses.
Ongoing / Recurring Managed Services
The tables below describe Enstep’s managed service plans and all managed services provided or facilitated by Enstep; however, only the plan or those services specifically described in the Quote will be facilitated and/or provided to you (collectively, the “Services”). Please review the Quote to determine which of the managed services plans listed below will be provided to / facilitated for you.
Ongoing/recurring managed services are provided to you or facilitated for you on an ongoing basis and, unless otherwise indicated in a Quote, are billed to you monthly. Some ongoing/recurring services will begin with the commencement of onboarding services; others will begin when the onboarding process is completed. Please direct any questions about start or “go live” dates to your account manager.
Managed Service Plans
Feature | Enable | Engage | Encompass | Add-on |
Business Premium |
✓
|
✓
|
✓
|
✓
|
MDM License |
✓
|
✓
| ||
VoIP License |
✓
| |||
Agent Based Support | ✓ | ✓ | ✓ | |
Help Desk Basic SLA - 8 Hour Response | ||||
Help Desk Standard SLA - 4 Hour Response | ✓ | |||
Help Desk VIP SLA - 1 Hour Response | ✓ | ✓ | ||
Unlimited Remote Support * | ✓ | ✓ | ✓ | |
Unlimited Onsite Support * | ✓ | ✓ | ||
Business Hours Support Included | ✓ | ✓ | ✓ | |
After Hours (5:00 PM - 10:00 PM CST) | ✓ | |||
24 x 7 x 365 Logging and Monitoring | ✓ | ✓ | ✓ | |
Proactive Resolution of Qualified Logged Events * | ✓ | ✓ | ✓ | |
Automated Routine Maintenance | ✓ | ✓ | ✓ | |
Windows Updates | ✓ | ✓ | ✓ | |
Office Updates | ✓ | ✓ | ||
Supported Application Update (Not Upgrade) * | ✓ | ✓ | ||
CPA Specialized Application Updates | ✓ | ✓ | ||
Critical Firmware (PC) Updates | ✓ | ✓ | ||
Volume License Management and Tracking | ✓ | ✓ | ||
Asset Management (Agent Based) | ✓ | ✓ | ✓ | |
Depot Services | ✓ | ✓ | ||
Mobile Device Management | ✓ | ✓ | ✓ | |
Basic Hardware Upgrades | ✓ | ✓ | ||
New End Point Installation* | ✓* | ✓ | ✓ | |
eWaste Recycling | ✓ | ✓ | ✓ | |
Secure Data Destruction | ✓ | ✓ | ✓ | |
Basic Procurement | ✓ | ✓ | ✓ | |
Scoped Procurement | ✓ | ✓ | ✓ | |
Human Resource Integration | ✓ | ✓ | ✓ | |
Warranty Liaison | ✓ | ✓ | ✓ | |
Vender Liaison | ✓ | ✓ | ✓ | |
Runbook Documentation | ✓ | ✓ | ✓ | |
Onboarding (Standard) | ✓ | ✓ | ✓ |
Feature | Enable | Engage | Encompass | Add-on |
Periodic Strategy Meeting | ✓ | ✓ | ||
vCIO Services | ✓ | ✓ | ||
Support Portal Access | ✓ | ✓ | ✓ | |
Microsoft 365 Licensing Management | ✓ | ✓ | ✓ | |
KB/ FAQ Access | ✓ | ✓ | ✓ | |
Automated Reports | ✓ | |||
Basic Policies (User, Device, etc) | ✓ | ✓ | ||
Managed Firewall(s) * | ✓ | ✓ | ✓ | |
Managed Wireless Access Point(s) * | ✓ | ✓ | ||
Managed Switch(es) * | ✓ | ✓ | ||
Managed Basic Antivirus | ✓ | ✓ | ||
BCP/ Backup and Data Recovery Appliance | ✓ | ✓ | ✓ | |
Backup Monitoring | ✓ | ✓ | ✓ | |
Office 365 Data Protection / Backups | ✓ | ✓ | ✓ | |
Multi-Factor Authentication | ✓ | ✓ | ✓ | |
Email Threat Protection | ✓ | ✓ | ✓ | |
E-mail Encryption | ✓ | |||
Secure File Sharing | ✓ | ✓ | ✓ | |
Identity and Access Management | ✓ | ✓ | ✓ | |
eDiscovery | ✓ | ✓ | ✓ | |
Managed EDR Antivirus | ✓ | |||
Malicious Content Filtering | ✓ | |||
Internet Category Content Filtering | ✓ | |||
Threat Detection (AMP/IDS/IPS) | ✓ | |||
Security Education, Training, and Awareness (SETA) Programs | ✓ | |||
Phishing Testing | ✓ | |||
Advanced Client VPN | ✓ | |||
Advanced Multi-Factor Authentication | ✓ | ✓ | ||
Identity Threat Detection and Response (ITDR) | ✓ | |||
24x7 Security Operations Center (SOC) | ✓ | |||
Third Party Patch Management | ✓ | |||
Penetration (Pen) Testing | ✓ | |||
Password Manager | ✓ |
Managed Services Features
Feature | General Description | |||||||||||||||||||||||||||
MDM License | The Mobile Device Management (“MDM”) License provides the Client with the right to use our designated third-party MDM software platform for the management of supported mobile devices. The MDM License is limited to software licensing only and does not include professional services, configuration, deployment, or administrative change." | |||||||||||||||||||||||||||
Mobile Device Management | Mobile Device Management (“MDM”) Services consist solely of the provision of an MDM software licensing and ongoing operational support for supported mobile devices and users enrolled by the Client. These Services are intended to assist the Client in maintaining device security, compliance, and basic operational functionality through our designated MDM platform. Any request that involves setup, configuration, modification, or change to the existing MDM environment shall be classified as Moves, Adds, and Changes (“MAC”). MAC work is outside the scope of this Service and will be performed only upon Client approval and billed separately in accordance with Enstep’s then-current MAC rates or under a separate statement of work. | |||||||||||||||||||||||||||
Business Premium | Implementation and facilitation of business premium licenses from our designated Third Party Provider. The most comprehensive Office 365 solution, Business Premium offers everything included in Business Standard, plus advanced security features like data loss prevention, Azure Information Protection, and Basic Mobile Device Management (MDM) capabilities. License also includes productivity and business analytics tools to help optimize business operations and comply with regulatory requirements. | |||||||||||||||||||||||||||
VoiP License | Implementation and facilitation of an industry-recognized VoIP solution from our designated Third Party Provider. Features include:
Important: There are additional terms related to the VoIP service, including your use of E911 features, toward the end of this Services Guide. Please read them carefully. You may be required to sign an additional consent form indicating your understanding and acceptance of the limitations of 911 dialing using the VoIP services. VoIP license includes access to a VoIP solution and does not include changes, modifications, or support. Any support or change requests will be billed at out of scope rates. | |||||||||||||||||||||||||||
Agent Based Support | Provides remote support via an installed software agent that enables real-time system diagnostics, performance monitoring, and issue resolution. Support is available during specified service hours and includes both routine troubleshooting and proactive problem identification to minimize downtime. Efforts to resolve issues will follow a reasonable effort standard—if a resolution path becomes unproductive or excessively time-consuming, alternative actions such as system reimaging may be pursued to restore functionality efficiently. | |||||||||||||||||||||||||||
Help Desk Standard SLA - 4 Hour Response |
| |||||||||||||||||||||||||||
Help Desk VIP SLA - 1 Hour Response |
| |||||||||||||||||||||||||||
Unlimited Remote Support | Remote support provided during normal business hours for managed devices and covered software Tiered-level support provides a smooth escalation process and helps to ensure effective solutions. Includes unlimited ticket submissions—not unlimited labor time—with a reasonable effort standard applied. If an issue requires disproportionate labor (e.g., complex vendor coordination or integration work), Enstep may recommend a scoped project or alternative resolution. This service excludes moves, adds, or changes; Hardware as a Service (HaaS); and Software as a Service (SaaS). | |||||||||||||||||||||||||||
Unlimited Onsite Support | Provides onsite support only after reasonable remote resolution attempts have been exhausted, at Enstep's sole discretion and in accordance with our service map coverage areas. This service is available during business hours (8:00 AM - 5:00 PM CST, M-F, excluding holidays) and excludes moves, adds, or changes; hardware repairs not covered under warranty; or issues deemed resolvable remotely. Onsite visits are scheduled based on technician availability, and efforts are made on a reasonable effort basis to resolve issues efficiently. If excessive time or resources are required, Enstep may recommend a scoped project with additional fees. Excludes after-hours or emergency onsite support unless separately contracted. | |||||||||||||||||||||||||||
Business Hours Support Included | Provides access to help desk and remote support services during standard business hours of 8:00 AM to 5:00 PM CST, Monday through Friday, excluding holidays. This includes ticket submission, troubleshooting, and issue resolution for covered devices and software under the applicable SLA tier. Support is delivered on a reasonable effort basis, subject to client cooperation and issue complexity, with no guarantee of immediate resolution. Excludes after-hours support, onsite visits, or out-of-scope work such as major configurations. | |||||||||||||||||||||||||||
After Hours (5:00 PM - 10:00 PM CST) | Provides access to IT support after regular business hours, specifically between 5:00 PM to 10:00 PM CST, for incidents requiring immediate attention beyond the typical working day. Suitable for emergency fixes, ensuring key systems are operational for the next business day, minimizing impact on business productivity. For plans without this service, after-hours support will be billed at Out of Scope Rates | |||||||||||||||||||||||||||
24 x 7 x 365 Logging and Monitoring | Software agents installed on covered Equipment (defined below) report status and IT-related events on a 24x7 basis; alerts are generated and responded to in accordance with the Service Levels described below.
In addition to the above, our remote monitoring and management service will be provided as follows:
| |||||||||||||||||||||||||||
Proactive Resolution of Qualified Logged Events* | Enstep will use reasonable efforts to proactively identify and resolve qualified logged events through configuration, monitoring, and preventative maintenance of the managed IT infrastructure. This includes automated alerts and initial remote troubleshooting to address potential issues before they impact operations. If remote efforts are unsuccessful, Enstep may, at its discretion, dispatch a technician to the Client’s premises to resolve covered incidents (timing of onsite support is subject to technician availability, scheduling, and service map coverage). This service is provided on a best efforts basis, *excludes non-qualified events (e.g., user errors or unsupported hardware), and does not guarantee prevention of all issues. If resolution requires disproportionate resources, Enstep may recommend a scoped project with additional fees. | |||||||||||||||||||||||||||
Automated Routine Maintenance | Implementation and facilitation of maintenance tools from our designated Third Party Provider. Enstep employs automated scripts and tools to perform routine maintenance tasks on managed devices, such as clearing temporary files, defragmenting disks, and running cleanup routines to help maintain system performance and stability. These activities are scheduled during low-impact periods to minimize disruption and are executed under a reasonable effort standard. This service does not guarantee optimal performance in all scenarios, excludes custom scripting or unsupported software, and relies on client-maintained device access. If issues arise from automation, alternative manual interventions may be pursued at Enstep's discretion. | |||||||||||||||||||||||||||
Windows Updates | Monthly patching and updating of the Windows operating system to address security vulnerabilities, enhance system performance, and support compliance standards. Enstep curates and deploys only certified or broadly verified patches that are deemed stable, excluding updates known to cause widespread compatibility issues. Deployment activity is documented and logged for audit and review purposes. | |||||||||||||||||||||||||||
Office Updates | Regular updates to Microsoft Office applications, ensuring all systems remain secure, stable, and equipped with the latest productivity features. Includes coordination of update scheduling. | |||||||||||||||||||||||||||
Supported Application Update (Not Upgrade) * | Routine updates to supported third-party applications - to maintain stability, functionality, and security not including changing major versions. Updates are deployed under a reasonable effort standard and does not include major version updates or application migrations. Coverage is limited to Enstep-approved applications where scripting automation or standardized procedures are in place to ensure scalability. | |||||||||||||||||||||||||||
CPA Specialized Application Updates | Regular maintenance and patching of CPA-specific software—such as QuickBooks, CCH, and similar applications—to address security vulnerabilities, compliance updates, and bug fixes. Updates are coordinated with the client to minimize disruption during tax season or critical reporting windows. This service excludes major version upgrades (e.g., 2024 to 2025), new module installations, or complex after-hours deployments, which may be scoped and billed separately. Support is provided under a reasonable effort standard. Updates and patches may originate from the software vendor or be distributed as standalone update files or hotfixes. While Enstep follows best practices in testing and deployment, we are not responsible for any system instability or loss resulting from the application of vendor-provided updates. Enstep may, at its discretion, delay or decline deployment of an update if it is known or reasonably believed to cause instability or conflict. | |||||||||||||||||||||||||||
Critical Firmware (PC) Updates | Scheduled updates to selected critical firmware components on PCs, such as BIOS and hardware drivers, which ensure that the hardware is optimized and secure. | |||||||||||||||||||||||||||
Volume License Management and Tracking | Enstep will monitor, track, assign, and unassign volume licenses from Microsoft for any existing Volume or Open license agreements | |||||||||||||||||||||||||||
Asset Management (Agent Based) | Implementation and facilitation of an asset management solution from our designated Third Party Provider. Automated tracking of IT assets—including workstations, servers, and agent-visible components—via installed software agents. This service maintains inventory details to assist with lifecycle management, from procurement to decommissioning, for assets under management. Reporting is available upon request. Asset data is limited to devices actively reporting into Enstep’s monitoring platform. Non-agent-based assets (e.g., printers, unmanaged switches, client-purchased peripherals) are not included unless separately tracked through approved tools or processes. This service operates under a reasonable effort standard and relies on platform visibility; manual inventory upkeep is not guaranteed. | |||||||||||||||||||||||||||
Depot Services | Centralized logistics and hardware lifecycle management for approved clients and qualifying devices. This service includes the collection (receiving by our shipping department, does not include onsite pickup), repair (By OEM), and re-deployment of supported client owned hardware through Enstep’s service depot, enabling rapid turnaround on failed or end-of-life devices while minimizing user downtime. Depot Services may be limited to hardware supplied by Enstep and covered under a manufacturer or Enstep-provided warranty plan that includes accidental damage protection and a 5-year term. Devices not procured through Enstep, or lacking adequate warranty coverage, may be excluded and may require separate, billable support or replacement arrangements. | |||||||||||||||||||||||||||
Basic Hardware Upgrades | Labor-only service for installing approved hardware components—such as memory (RAM) and secondary storage drives—on Enstep-supplied devices that are five years old or newer and meet our system specifications. Upgrades involving the primary drive (e.g., cloning, OS reinstallation) or requiring more than 15 minutes are considered out of scope and may be billed separately as a change order. This service includes installation and basic compatibility checks but does not guarantee performance improvement or the functionality of any specific hardware. Clients may be responsible for procuring compatible hardware; Enstep cannot guarantee refunds or returns for incompatible parts. Installation records are maintained within the ticketing system for reference. Please note: This service is not a warranty or repair plan and does not imply guaranteed outcomes for any device or component. | |||||||||||||||||||||||||||
New End Point Installation* | Enstep provides comprehensive configuration for new workstations to ensure secure integration and compliance with internal policy standards. This service includes:
Pricing:
Note: Preparing or reassigning a user’s previous device (equipment cascading) is not included and requires a separate work order. | |||||||||||||||||||||||||||
eWaste Recycling | Facilitation of an eWaste recycling solution from our designated Third Party Provider. Secure and environmentally responsible disposal of obsolete or decommissioned electronics. Devices are data-wiped using industry-recognized standards prior to recycling. Enstep does not provide formal Certificates of Disposal. This service is performed based on commonly accepted environmental practices and does not include ongoing tracking of evolving regulatory standards. This service does not include ongoing regulatory monitoring; disposal methods are based on commonly accepted standards and best efforts to follow current environmental guidance. Bulk pickups may require advance scheduling and approval. Certain items—including copiers, CRT monitors, and other specialty devices—are excluded from standard eWaste handling and may require separate arrangements or incur additional fees. | |||||||||||||||||||||||||||
Secure Data Destruction | Facilitation of a secure data destruction solution from our designated Third Party Provider. Secure and environmentally responsible destruction of storage devices containing client data. Enstep does not provide formal certificates of destruction. This service is performed based on commonly accepted data hygiene practices and does not include tracking of evolving regulatory standards. This service is provided as “best effort” with no guarantees. | |||||||||||||||||||||||||||
Basic Procurement | Assistance with sourcing standard IT hardware and software, ensuring cost-effective procurement that adheres to technical requirements | |||||||||||||||||||||||||||
Scoped Procurement | Tailored procurement assistance for unique business requirements, involving detailed needs assessments, vendor vetting, RFP management, and coordination of purchases. Suitable for specialized hardware or software requirements that need in-depth evaluation to ensure optimal fit for business operations. | |||||||||||||||||||||||||||
Human Resource Integration | Implementation and facilitation of a human resource integration solution from our designated Third Party Provider. Integration of IT systems with human resource workflows, ensuring that new hires, terminations, and other personnel changes are reflected in the IT infrastructure in a timely and secure manner. This includes provisioning and de-provisioning of user accounts, configuring appropriate access controls, and ensuring compliance with HR policies. Detailed change logs are maintained for auditing purposes. | |||||||||||||||||||||||||||
Warranty Liaison | Acting on behalf of the client to manage warranty claims for supported hardware, including coordination with OEMs or vendors. This deliverable includes maintaining an inventory of warranty statuses and facilitating hardware replacement or repair to ensure business continuity. | |||||||||||||||||||||||||||
Vender Liaison | Serving as the primary point of contact between the client and third-party vendors for any supported IT-related services or products as reviewed and needed. This includes issue escalation, and coordination of support activities. | |||||||||||||||||||||||||||
Runbook Documentation | Development and maintenance of runbooks that include detailed, step-by-step procedures for executing specific IT tasks, such as system recovery, backup, and failover processes. The runbooks are created in consultation with client stakeholders to ensure that they align with business continuity requirements and are regularly reviewed and updated. | |||||||||||||||||||||||||||
Periodic Strategy Meeting | Scheduled strategy meetings with business stakeholders and IT leadership (vCIO) to review ongoing projects, address emerging needs, evaluate system performance, and align IT initiatives with business goals. Meeting minutes and action plans are documented, with follow-ups on assigned tasks. Typically held quarterly or as requested. | |||||||||||||||||||||||||||
vCIO Services | Act as the main point of contact for certain business-related IT issues and concerns.
These services are intended to cover your core needs. If you would like additional time for deeper strategy or planning, let us know. We are happy to provide a quote for additional time and services. | |||||||||||||||||||||||||||
Support Portal Access | Access to a dedicated IT support portal where clients can submit, track, and manage support tickets. The portal also includes self-help guides, system status updates, and FAQs. All tickets and associated responses are logged for compliance and service quality monitoring. | |||||||||||||||||||||||||||
Microsoft 365 Licensing Management | End-to-end management of Microsoft 365 licenses, covering procurement, license assignment, compliance management, and renewals. This service optimizes license usage by adjusting plans based on user roles and minimizing over-licensing. | |||||||||||||||||||||||||||
KB/ FAQ Access | Access to a knowledge base containing self-help articles, how-to guides, and frequently asked questions. The content is continually updated based on recurring issues and client requests, enabling users to resolve common problems independently and reduce downtime. | |||||||||||||||||||||||||||
Automated Reports | Regular generation of automated reports, including system health, user activity, patch status, and security incidents. Reports are generated upon request and include actionable insights to assist in decision-making. Customized reports can also be created based on client-specific KPIs. | |||||||||||||||||||||||||||
Basic Policies (User, Device, etc) | Development, deployment, and enforcement of fundamental IT policies, such as acceptable use policies, device management, and security protocols. These policies are designed to align with industry standards and the client’s operational needs. Policy compliance is reviewed and updates are made based on regulatory changes or new security threats. | |||||||||||||||||||||||||||
Managed Firewall(s) * |
| |||||||||||||||||||||||||||
Managed Wireless Access Point(s) * | Enstep will install at the Client’s premises Wireless Access Points to provide bandwidth in all areas requiring wireless network coverage, as agreed upon by Enstep and Client.
Please note: Any Wi-Fi devices, such as access points or routers, which are supplied by Client must be considered a supported model by Enstep. Enstep does not manage or support third party (I.E not standard) vendors or equipment. | |||||||||||||||||||||||||||
Managed Switch(es) * | Enstep will install and manage network switches at the Client’s premises to provide reliable connectivity in the managed network, as agreed upon by Enstep and Client. This includes installation, configuration, maintenance, and supervision of the switches at no additional cost. Installed equipment, if provided by Enstep, will be compatible with then-current industry standards and is subject to meet the client's connectivity needs under a reasonable effort standard. Enstep will provide remote monitoring during normal business hours to assist with connectivity issues, on a best efforts basis only (Client understands that some devices may not connect or perform optimally). Switches are subject to “Hardware as a Service” terms and conditions located in this Guide and must be returned upon termination of service, with Client responsible for missing or damaged equipment (normal wear and tear excepted). Excludes third-party or client-supplied equipment unless explicitly approved by Enstep. This will be based of user count. | |||||||||||||||||||||||||||
Managed Basic Antivirus | Implementation and facilitation of an endpoint malware protection solution from our designated Third Party Provider.
* Please see Anti-Virus; Anti-Malware and Breach / Cyber Security Incident Recovery sections below for important details. | |||||||||||||||||||||||||||
BCP/ Backup and Data Recovery Appliance | Implementation and facilitation of a backup and file recovery solution from our designated Third Party Provider. This service only includes the backup and data recovery appliance, it does not include backup monitoring or cloud storage, unless available in the selected plan.
*Available for clients with Azure hosted Virtual machines in an existing Enstep managed Azure Subscription. | |||||||||||||||||||||||||||
Recovery Appliance |
Backup Data Security: All backed up data is encrypted in transit and at rest in 256-bit AES encryption. Backup Retention: Backed up data will be retained for the periods indicated below, unless a different time period is expressly stated in the Quote. This includes both on-premise and cloud backups.
Recovery of Data: If you need to recover any of your backed up data, then the following procedures will apply: Service Hours: Backed up data can be requested during our normal business hours. Request Method. Requests to restore backed up data should be made via the ticketing system. Restoration Time: We will endeavor to restore backed up data as quickly as possible following our receipt of a request to do so; however, in all cases data restoration services are subject to (i) technician availability and (ii) confirmation that the restoration point(s) is/are available to receive the backed up data. | |||||||||||||||||||||||||||
Backup Monitoring | Implementation and facilitation of a backup monitoring solution from our designated Third Party Provider. Features include:
Note: Backup monitoring is limited to monitoring activities only and is not a backup and file recovery | |||||||||||||||||||||||||||
Office 365 Data Protection / Backups |
| |||||||||||||||||||||||||||
Multi-Factor Authentication | Implementation and facilitation of a multi-factor authentication solution from Microsoft 365.
| |||||||||||||||||||||||||||
Domain Name Management Services | Migration, management, and renewals of client domains through Enstep’s designated third-party provider. Features include:
* Cost is per top-level domain (TLD) managed. | |||||||||||||||||||||||||||
Email Threat Protection | Implementation and facilitation of a trusted email threat protection solution from our designated Third Party Provider.
Please see Anti-Virus; Anti-Malware and Breach / Cyber Security Incident Recovery sections below for important details. All hosted email is subject to the terms of our Hosted Email Policy and our Acceptable Use Policy. | |||||||||||||||||||||||||||
E-mail Encryption | Implementation and facilitation of an e-mail encryption solution from our designated Third Party Provider. A comprehensive email encryption service that ensures all outgoing emails containing sensitive information are encrypted, protecting them from unauthorized access during transit. Encryption policies are customizable, with enforcement based on keywords, recipients, or content. The service ensures compliance with data protection regulations like GDPR and HIPAA, and includes user training on the use of secure email tools. All encrypted emails and attempted access are logged for security auditing. | |||||||||||||||||||||||||||
Secure File Sharing | Implementation and facilitation of a secure file sharing solution from our designated Third Party Provider. A secure file-sharing solution that enables authorized users to share files internally or externally with strong encryption and role-based access control. This solution ensures sensitive data is shared securely, and all activities are logged for audit purposes. Integration with productivity tools allows seamless collaboration without compromising security. | |||||||||||||||||||||||||||
Identity and Access Management | Implementation and management of tools and procedures for ensuring that only authorized users have access to critical resources. Includes Single Sign-On (SSO), identity lifecycle management, and user provisioning/de-provisioning in alignment with HR processes. Comprehensive audit logs are maintained to support compliance. | |||||||||||||||||||||||||||
eDiscovery | eDiscovery tools to assist with searching, identifying, and retrieving electronically stored information (ESI) during litigation or internal investigations. This service includes implementing legal holds, generating audit trails, and producing requested documentation according to legal requirements. | |||||||||||||||||||||||||||
Managed EDR Antivirus | Implementation and facilitation of an endpoint malware protection solution with extended functionalities from our designated Third Party Provider.
* Requires at least two layers (e.g., endpoint, email, network, servers, and/or cloud workload.)
Please see Anti-Virus; Anti-Malware and Breach / Cyber Security Incident Recovery sections below for important details. | |||||||||||||||||||||||||||
Malicious Content Filtering | Implementation and management of filtering mechanisms to prevent access to websites known for distributing malicious software, protecting both individual devices and the overall network. Content filtering policies are configured based on the client's security posture and adjusted as new threats emerge. | |||||||||||||||||||||||||||
Internet Category Content Filtering | Implementation and facilitation of an internet content filtering solution from our designated Third Party Provider. Features include categorizing websites and blocking access to non-business or high-risk categories (e.g., adult content, gambling). Filtering rules are customizable to suit specific client needs, with logs provided detailing blocked activities for compliance review. | |||||||||||||||||||||||||||
Threat Detection (AMP/IDS/IPS) | Implementation and facilitation of a threat detection solution from our designated Third Party Provider. Deployment and management of advanced threat detection technologies, including Anti-Malware Protection (AMP), Intrusion Detection Systems (IDS), and Intrusion Prevention Systems (IPS). Services include monitoring, alerting, and responding to potential threats in real-time. | |||||||||||||||||||||||||||
Security Education, Training and Awareness (SETA) Program | Implementation and facilitation of a security awareness training solution from an industry-leading third party solution provider.
Please see Anti-Virus; Anti-Malware and Breach / Cyber Security Incident Recovery sections below for important details. | |||||||||||||||||||||||||||
Phishing Testing | Baseline testing to assess the phish-prone percentage of users; simulated phishing email campaigns designed to educate employees about security threats. | |||||||||||||||||||||||||||
Advanced Client VPN | Setup and management of advanced secure Virtual Private Network (VPN) connections for remote workers, providing encrypted access to corporate resources. Advanced features include an SSLVPN over the basic L2TP VPN allowing for greater flexibility, control, and security. | |||||||||||||||||||||||||||
Advanced Multi-Factor Authentication | Implementation and facilitation of a multi-factor authentication solution from our designated Third Party Provider.
| |||||||||||||||||||||||||||
Identity Threat Detection and Response (ITDR) | Implementation and management of tools to detect and respond to threats targeting user identities and access credentials. This includes monitoring for suspicious login attempts, credential stuffing, and anomalous behavior; alerting on potential compromises; and assisting with initial response efforts such as account lockdowns. Services are provided under a reasonable effort standard, subject to client-provided identity data and integration capabilities. Does not guarantee detection or prevention of all threats, and remediation may require additional scoped work or third-party involvement at extra cost. Excludes forensic investigations unless separately contracted. | |||||||||||||||||||||||||||
24x7 Security Operations Center (SOC) | Provides round-the-clock monitoring, analysis, and initial response to security events by a dedicated SOC team using industry-recognized tools. This includes threat detection across managed endpoints, networks, and cloud environments; triage of alerts; and notification of potential incidents. Services are delivered on a best efforts basis, with response times subject to defined SLAs and no guarantee of preventing or resolving all security events. Excludes full incident remediation, forensic analysis, or liability for undetected threats. Client cooperation is required for effective monitoring, and additional fees may apply for custom configurations or escalated responses. | |||||||||||||||||||||||||||
Third Party Patch Management | Management of updates for supported third-party software (e.g., Adobe, VLC) to ensure they are always patched against the latest vulnerabilities. This includes automated distribution, testing for compatibility, and scheduling patch installations to minimize business disruptions. | |||||||||||||||||||||||||||
Penetration (Pen) Testing | Penetration testing (or “pen” testing) simulates a cyberattack against your IT infrastructure to identify exploitable vulnerabilities. Unlike ongoing vulnerability scanning services that provide a constant, static level of network scanning, pen testing may involve several stages of reconnaissance and actual attack methodologies (such as brute force attacks and/or SQL injection attacks) and may include unconventional and targeted attacks that occur during business and non-business hours. Pen testing may consist of any of the following: External Pen Testing: exposes vulnerabilities in your internet-facing systems, networks, firewalls, devices, and/or web applications that could lead to unauthorized access. Internal Pen Testing: Validates the effort required for an attacker to overcome and exploit your internal security infrastructure after access is gained. PCI Pen Testing: Using the goals set by the PCI Security Standards Council, this test involves both external and internal pen testing methodologies. Web App Pen Testing: Application security testing using attempted infiltration through a website or web application utilizing PTES and the OWASP standard testing checklist. Please see additional terms for Penetration Testing below. | |||||||||||||||||||||||||||
Password Manager | Implementation and facilitation of a password management protection solution from our designated Third Party Provider.
| |||||||||||||||||||||||||||
Security Information and Event Management (SIEM) | Implementation and facilitation of an industry leading SIEM solution from our designated Third Party Provider. The SIEM service utilizes threat intelligence to detect threats that can exploit potential vulnerabilities against your managed network.
Events are triggered when conditions on the monitored system meet or exceed predefined criteria (the “Criteria”). Since the Criteria are established and optimized over time, the first thirty (30) days after deployment of the SIEM services will be used to identify a baseline of the Client’s environment and user behavior. During this initial thirty (30) day period, Client may experience some “false positives” or, alternatively, during this period not all anomalous activities may be detected. Note: The SIEM service is a monitoring and alert-based system only; remediation of detected or actual threats are not within the scope of this service and may require Client to retain Enstep’s services on a time and materials basis. | |||||||||||||||||||||||||||
Advanced eDiscovery | Provides in-depth capabilities for locating and managing electronically stored information during investigations or litigation. Advanced features include metadata analysis, content indexing, and support for large-scale data retrieval. The service includes consulting with stakeholders to refine search criteria and minimize unnecessary data exposure. | |||||||||||||||||||||||||||
Vulnerability Management | Implementation and facilitation of an industry-recognized vulnerability scanning solution from our designated Third Party Provider. Vulnerability scanning identifies holes in the managed network that could be exploited. External vulnerability scans (which pertain to the IP address assigned to each customer location through the Client’s ISP) are run monthly. Internal vulnerability scans (which pertain to all systems inside the managed network) are run at least annually. Vulnerability results will be discussed during business review meetings with Client. Vulnerability reports will be made available on request. Please see additional terms for vulnerability scanning below. | |||||||||||||||||||||||||||
CSIRT (Computer Security Incident Response Team) | Dedicated team responsible for responding to security incidents. Services include containment, eradication, recovery, and root cause analysis of incidents. The CSIRT works with stakeholders to restore normal operations as quickly as possible while minimizing damage. | |||||||||||||||||||||||||||
Vulnerability Assessment | In-depth assessments conducted to identify vulnerabilities in hardware, software, and network configurations. Assessments are carried out using both automated tools and manual methods. Findings are compiled into a detailed report with risk ratings and recommended actions for mitigation. Assessments are performed based on client requirements or regulatory needs. | |||||||||||||||||||||||||||
Data Loss Prevention (DLP) | Implementation of policies and technologies to prevent unauthorized access, transfer, or sharing of sensitive data. DLP solutions are applied across endpoints, email, and cloud storage, ensuring that all sensitive information is tracked and protected according to corporate and regulatory requirements. | |||||||||||||||||||||||||||
Rights Management | Implementation and management of digital rights management tools to control access, usage, and distribution of sensitive documents and data. This includes setting encryption policies, revocation options, and tracking for protected content. Services are provided under a reasonable effort standard, subject to client-defined policies and compatible applications. Does not guarantee prevention of all unauthorized access or use, and excludes custom development or integration with unsupported systems. Additional fees may apply for advanced configurations. | |||||||||||||||||||||||||||
Data Lifecycle Management | Assistance with managing data from creation through archiving and deletion, including classification, retention scheduling, and disposal in alignment with client policies and regulations. This service includes policy development and tool implementation under a reasonable effort standard. Does not include data migration, legal advice on compliance, or guarantees against data loss; relies on client-provided requirements and may require additional scoped work for complex environments. | |||||||||||||||||||||||||||
Information Barriers | Implementation of information barriers within collaboration platforms (e.g., Microsoft Teams) to prevent communication or sharing between specified user groups, ensuring compliance with internal ethical walls or regulatory requirements. Configuration is based on client-defined rules and provided under a reasonable effort standard. Does not guarantee absolute separation in all scenarios, and excludes ongoing monitoring or adjustments unless requested; changes may incur additional fees. | |||||||||||||||||||||||||||
Advanced Message Encryption | Implementation and facilitation of an advanced email encryption solution from our designated Third Party Provider. Enhanced encryption for emails and messages containing sensitive data, with customizable policies for automatic application based on content, recipients, or keywords. Includes tracking of encrypted messages and revocation capabilities. Services are delivered on a best efforts basis, subject to compatible email systems, and do not guarantee decryption prevention by advanced threats. Excludes user training or integration with non-standard platforms. | |||||||||||||||||||||||||||
Privileged Access Management | Implementation of controls for managing and monitoring privileged user access, including just-in-time elevation, session recording, and auditing. This helps mitigate risks from elevated permissions and is configured based on client roles. Provided under a reasonable effort standard with no guarantee of detecting all misuse; requires client cooperation for policy definition and may involve additional fees for custom workflows or integrations. | |||||||||||||||||||||||||||
Records Management | Tools and processes for managing business records throughout their lifecycle, including automated retention schedules, disposition rules, and compliance labeling. Services include initial setup and ongoing maintenance under a reasonable effort standard, aligned with client regulatory needs. Does not include legal compliance consulting, data recovery, or guarantees against audit failures; excludes manual record handling or custom reporting unless scoped separately. |
Moves, Adds, Changes (MAC)
The following provisions apply to all Moves, Adds, or Changes (collectively referred to as “MAC”). MAC activities are defined as modifications to the client’s environment that are not considered routine maintenance, general housekeeping, or remediation of an active or potential issue.
1. Moves
A Move is defined as the relocation or repositioning of equipment, data, services, or any other system component when such action is not part of an incident response or preventative emediation.
- Relocating workstations or hardware
- Moving data or services from one location, server, or system to another
2. Adds
An Add is defined as the introduction of a new component that did
not previously exist within the environment.
- Installation of new applications or software
- Onboarding or configuring new users or employees
- Hardware or equipment installation
(excluding computers purchased through Enstep, if applicable)
3. Changes
A Change is defined as any modification to the existing environment that is not related to resolving an incident or preventing a potential incident.
- Updating copier address books or configurations
- Updating email addresses or mailbox settings/delegations
- Removing equipment, configurations, or automations from existing systems
Billing and Additional Provisions
All MAC activities are billed at the applicable labor rate for the required resource. Certain MACs may require higher-tier engineering or escalation, in which case the labor will be billed at the rate associated with that resource or skill level.
Hardware as a Service (Haas)
The provisions below apply to all hardware, devices, and accessories that are provided to you on a “hardware as a service” basis.
Scope: Provision and deployment of hardware and devices listed in the Quote or other applicable schedule (“HaaS Equipment”).
Deployment: We will deploy the HaaS Equipment within the timeframe stated in the Quote, provided that you promptly provide all information that we reasonably request from you to complete deployment. This deployment guaranty does not apply to any software, other managed services, or hardware devices other than the HaaS Equipment. In addition, this deployment time frame may be extended as necessary to accommodate delays that are outside of our reasonable control, such as embargoes, labor or supply chain shortages, or other force majeure events.
Delayed Deployment: If you wish to delay the deployment of the HaaS Equipment, then you may do so if you give us written notice of your election to delay no later than five (5) days following the date you sign the Quote. Deployment shall not extend beyond two (2) months following the date on which you sign the Quote. You will be charged at the rate of fifty percent (50%) of the monthly recurring fees for the HaaS-related services during the period of delay. Following deployment, we will charge you the full monthly recurring fee (plus other usage fees as applicable) for the full term indicated in the Quote.
Repair/replacement of HaaS Equipment: Enstep will endeavor to repair or replace HaaS Equipment within five (5) business days following the business day on which the applicable problem is identified by, or reported to, Enstep and has been determined by Enstep to be incapable of being remediated remotely. This warranty does not include the time required to rebuild your system, such as the time required to configure a replacement device, rebuild a RAID array, reload the operating system, reload and configure applications, and/or restore from backup (if necessary).
Technical Support for HaaS Equipment: We will provide technical support for HaaS Equipment in accordance with the Service Levels listed in this Services Guide.
Usage: You will use all HaaS Equipment for your internal business purposes only. You shall not sublease, sublicense, rent or otherwise make the HaaS Equipment available to any third party without our prior written consent. You agree to refrain from using the HaaS Equipment in a manner that unreasonably or materially interferes with our other hosted equipment or hardware, or in a manner that disrupts or that is likely to disrupt the services that we provide to our other clientele. We reserve the right to throttle or suspend your access and/or use of the HaaS Equipment if we believe, in our sole but reasonable judgment, that your use of the HaaS Equipment violates the terms of the Quote, this Services Guide, or the Agreement.
Return of HaaS Equipment: Unless we expressly direct you to do so, you shall not remove or disable, or attempt to remove or disable, any software agents installed in the HaaS Equipment. Doing so could result in network vulnerabilities and/or the continuation of license fees for the software agents for which you will be responsible, and/or the requirement that we remediate the situation at our then-current hourly rates, for which you will also be responsible. Within ten (10) days after the termination of HaaS-related Services, Client will provide Enstep access to the premises at which the HaaS Equipment is located so that all such equipment may be retrieved and removed by us. If you fail to provide us with timely access to the HaaS Equipment or if the equipment is returned damaged (normal wear and tear excepted), then we will have the right to charge you, and you hereby agree to pay, the replacement value of all such unreturned or damaged equipment.
Policies and Procedures Applicable to Services
Software Licensing: All software provided to you by or through Enstep is licensed, not sold, to you (“Software”). In addition to any Software-related requirements described in Enstep’s Master Services Agreement, Software may also be subject to end user license agreements (EULAs), acceptable use policies (AUPs), and other restrictions all of which must be strictly followed by you and any of your authorized users.
When installing/implementing software licenses in the managed environment or as part of the Services, we may accept (and you agree that we may accept) any required EULAs or AUPs on your behalf. You should assume that all Software has an applicable EULA and/or AUP to which your authorized users and you must adhere. If you have any questions or require a copy of the EULA or AUP, please contact us.
Covered Environment: Services will be applied to the number of devices indicated in the Quote (“Covered Hardware”). The list of Covered Hardware may be modified by mutual consent (email is sufficient for this purpose); however, we reserve the right to modify the list of Covered Hardware at any time if we discover devices that were not previously included in the list of Covered Hardware and which are receiving Services, or as necessary to accommodate changes to the quantity of Covered Hardware.
Unless otherwise stated in the Quote, Covered Devices will only include technology assets (such as computers, servers, and networking equipment) owned by the Client’s organization. As an accommodation, Enstep may provide guidance in connecting a personal device to the Client’s organization’s technology, but support of personal devices is generally not included in the Scope of Services. Enstep will not and cannot be held responsible for issues pertaining to personal device.
If the Quote indicates that the Services are billed on a “per user” basis, then the Services will be provided for up to two (2) Business Devices used by the number of users indicated in the Quote. A “Business Device” is a device that (i) is owned or leased by Client and used primarily for business, (ii) is regularly connected to Client’s managed network, and (iii) has installed on it a software agent through which we (or our designated Third Party Providers) can monitor the device.
We will provide support for any software applications that are licensed through us. Such software (“Supported Software”) will be supported on a “best effort” basis only and any support required beyond Level 2-type support will be facilitated with the applicable software vendor/producer. Coverage for non-Supported Software is outside of the scope of the Quote and will be provided to you on a “best-effort” basis and a time and materials basis with no guarantee of remediation. Should our technicians provide you with advice concerning non-Supported Software, the provision of that advice should be viewed as an accommodation and not an obligation to you.
Enstep will provide support for standard incidents for client purchased software only if you maintain a service or support contract. Additional fees may apply complex issues which may require extensive hours of labor.
If we are unable to remediate an issue with Unsupported Software, then you will be required to contact the manufacturer/distributor of the software for further support. Please note: Manufacturers/distributors of such software may charge fees, some of which may be significant, for technical support; therefore, we strongly recommend that you maintain service or support contracts for all Unsupported Software (“Service Contract”). If you request that we facilitate technical support for Unsupported Software and if you have a Service Contract in place, our facilitation services will be provided to you at our then-current hourly rates.
In this Services Guide, Covered Hardware and Supported Software will be referred to as the “Environment” or “Covered Equipment.”
Physical Locations Covered by Services: Services will be provided remotely unless, in our discretion, we determine that an onsite visit is required. Enstep visits will be scheduled in accordance with the priority assigned to the issue (below) and are subject to technician availability. Unless we agree otherwise, all onsite Services will be provided at Client’s primary business location. In some cases, Enstep may determine that hardware must be removed from the client site for in-office diagnosis or repair, with reinstallation scheduled upon completion. Moves, adds, and changes (MAC) are not included and are billed separately. Onsite support outside the Greater Houston Area is subject to availability and will be prioritized based on urgency and service level. Additional fees may apply for onsite visits: Please review the Service Level section below for more details.
Evolving Technologies: Technologies can evolve rapidly. In certain instances, depending on the scope and timing of an applicable service, technologies comprising or included in a service may evolve before the service can be fully implemented. Should this occur, we will provide you with options to leverage the latest version of the evolved technology and inform you of the attendant fees and costs to do so. If you decline to implement the evolved technology, then we will continue to implement the service as indicated in the Quote; however, you understand and agree that (i) you will not benefit from improvements in the evolved technology, and (ii) the applicable technology and service may become obsolete more quickly.
Minimum Requirements / Exclusions: The scheduling, fees and provision of the Services are based upon the following assumptions and minimum requirements, all of which must be provided/maintained by Client at all times:
Exclusions: Services that are not expressly described in the Quote will be out of scope and will not be provided to Client unless otherwise agreed, in writing, by Enstep. Without limiting the foregoing, the following services are expressly excluded, and if required to be performed, must be agreed upon by Enstep in writing:
Service Levels: Automated monitoring is provided on an ongoing (i.e., 24x7x365) basis. Response, repair, and/or remediation services (as applicable) will be provided only during our business hours (currently M-F, 9 AM – 6 PM Central Time, excluding legal holidays and Enstep-observed holidays as listed below), unless otherwise specifically stated in the Quote or as otherwise described below.
We will respond to problems, errors, or interruptions in the provision of the Services in the timeframe(s) described below. Severity levels will be determined by Enstep in our discretion after consulting with the Client. All remediation services will initially be attempted remotely; Enstep will provide onsite service only if remote remediation is ineffective and, under all circumstances, only if covered under the Service plan selected by Client.
| Trouble / Severity | Description | Response Time |
|---|---|---|
| Critical / Service Not Available | All users and functions unavailable | Response within two (2) business hours after notification. |
| Significant Degradation | Large number of users or business critical functions affected | Response within four (4) business hours after notification. |
| Limited Degradation | Limited number of users or functions affected, business process can continue | Response within eight (8) business hours after notification. |
| Small Service Degradation | Business process can continue, one user affected | Response within two (2) business days after notification. |
| Long Term Project / Preventative Maintenance | Planned work, non-urgent | Response within four (4) business days after notification. |
* All time frames are calculated as of the time that we are notified of the applicable issue/problem by client through our designated support portal or help desk. Notifications received in any manner other than described herein may result in a delay in the provision of remediation efforts.
Critical / Service Not Available
All users and functions unavailable
Response: within two (2) business hours after notification.
Significant Degradation
Large number of users or business critical functions affected
Response: within four (4) business hours after notification.
Limited Degradation
Limited number of users or functions affected, business process can continue
Response: within eight (8) business hours after notification.
Small Service Degradation
Business process can continue, one user affected
Response: within two (2) business days after notification.
Long Term Project / Preventative Maintenance
Planned work, non-urgent
Response: within four (4) business days after notification.
Support During Off-Hours/Non-Business Hours: Technical support provided outside of our normal business hours is offered on a case-by-case basis and is subject to technician availability. If Enstep agrees to provide off-hours/non-business hours support (“Non-Business Hour Support”), then that support will be provided on a time and materials basis (which is not covered under any Service plan), and will be billed to Client at twice our normal hourly rates.
All hourly services are billed in 15 minute increments, and partial increments are rounded to the next highest increment. A one (1) hour minimum applies to all Non-Business Hour Support.
Enstep-Observed Holidays: Enstep observes the following holidays:
Fees. The fees for the Services will be as indicated in the Quote.
Reconciliation: Fees for certain Third Party Services that we facilitate or resell to you may begin to accrue prior to the “go-live” date of other applicable Services. (For example, Microsoft Azure or AWS-related fees begin to accrue on the first date on which we start creating and/or configuring certain hosted portions of the Environment; however, the Services that rely on Microsoft Azure or AWS may not be available to you until a future date). You understand and agree that you will be responsible for the payment of all fees for Third Party Services that are required to begin prior to the “go-live” date of Services, and we reserve the right to reconcile amounts owed for those fees by including those fees on your monthly invoices.
Changes to Environment: Initially, you will be charged the monthly fees indicated in the Quote. Thereafter, if the managed environment changes, or if the number of authorized users accessing the managed environment changes, then you agree that the fees will be automatically and immediately modified to accommodate those changes.
Travel Time: If onsite services are provided, we will travel up to 45 minutes from our office to your location at no charge. Time spent traveling beyond 45 minutes (e.g., locations that are beyond 45 minutes from our office, occasions on which traffic conditions extend our drive time beyond 45 minutes one-way, etc.) will be billed to you at our then current hourly rates. In addition, you will be billed for all tolls, parking fees, and related expenses that we incur if we provide onsite services to you.
Appointment Cancellations: You may cancel or reschedule any appointment with us at no charge by providing us with notice of cancellation at least one business day in advance. If we do not receive timely a notice of cancellation/re-scheduling, or if you are not present at the scheduled time or if we are otherwise denied access to your premises at a pre-scheduled appointment time, then you agree to pay us a cancellation fee equal to two (2) hours of our normal consulting time (or non-business hours consulting time, whichever is appropriate), calculated at our then-current hourly rates.
Access Licensing: One or more of the Services may require us to purchase certain “per seat” or “per device” licenses (often called “Access Licenses”) from one or more Third Party Providers. (Microsoft “New Commerce Experience” licenses as well as Cisco Meraki “per device” licenses are examples of Access Licenses.) Access Licenses cannot be canceled once they are purchased and often cannot be transferred to any other customer. For that reason, you understand and agree that regardless of the reason for termination of the Services, fees for Access Licenses are non-mitigatable and you are required to pay for all applicable Access Licenses in full for the entire term of those licenses. Provided that you have paid for the Access Licenses in full, you will be permitted to use those licenses until they expire.
Term Termination: The Services will commence, and billing will begin, on the date indicated in the Quote (“Commencement Date”) and will continue through the initial term listed in the Quote (“Initial Term”). We reserve the right to delay the Commencement Date until all onboarding/transition services (if any) are completed, and all deficiencies / revisions identified in the onboarding process (if any) are addressed or remediated to Enstep’s satisfaction.
The Services will continue through the Initial Term until terminated as provided in the Agreement, the Quote, or as indicated in this Service Guide (the “Service Term”).
Per Seat/Per Device Licensing: Regardless of the reason for the termination of the Services, you will be required to pay for all per seat or per device licenses that we acquire on your behalf. Please see “Access Licensing” in the Fees section above for more details.
Removal of Software Agents; Return of Firewall & Backup Appliances: Unless we expressly direct you to do so, you will not remove or disable, or attempt to remove or disable, any software agents that we installed in the managed environment or any of the devices on which we installed software agents. Doing so without our guidance may make it difficult or impracticable to remove the software agents, which could result in network vulnerabilities and/or the continuation of license fees for the software agents for which you will be responsible, and/or the requirement that we remediate the situation at our then-current hourly rates, for which you will also be responsible. Depending on the particular software agent and the costs of removal, we may elect to keep the software agent in the managed environment but in a dormant and/or unused state.
Within ten (10) days after being directed to do so, you must remove, package and ship, at your expense and in a commercially reasonable manner, all hardware, equipment, and accessories leased, loaned, rented, or otherwise provided to you by Enstep “as a service.” If you fail to timely return all such equipment to us, or if the equipment is returned to us damaged (normal wear and tear excepted), then we will have the right to charge you, and you hereby agree to pay, the replacement value of all such unreturned or damaged equipment.
Offboarding: Subject to the requirements in the MSA, Enstep will off-board Client from Enstep’s services by performing one or more of the following:
Additional Policies
The following additional policies (“Policies”) apply to Services that we provide or facilitate under a Quote. By accepting a Service for which one or more of the Policies apply, you agree to the applicable Policy.
Authenticity:
Everything in the managed environment must be genuine and licensed, including all hardware, software, etc. If we ask for proof of authenticity and/or licensing, you must provide us with such proof. All minimum hardware or software requirements as indicated in a Quote or this Services Guide (“Minimum Requirements”) must be implemented and maintained as an ongoing requirement of us providing the Services to you.
Monitoring Services; Alert Services:
Unless otherwise indicated in the Quote, all monitoring and alert-type services are limited to detection and notification functionalities only. Monitoring levels will be set by Enstep, and Client shall not modify these levels without our prior written consent.
Configuration of Third Party Services:
Certain third party services provided to you under a Quote may provide you with administrative access through which you could modify the configurations, features, and/or functions (“Configurations”) of those services. However, any modifications of Configurations made by you without authorization could disrupt the Services and/or cause a significant increase in the fees charged for those third party services. For that reason, we strongly advise you to refrain from changing the Configurations unless we authorize those changes. You will be responsible for paying any increased fees or costs arising from or related to changes to the Configurations.
Modification of Environment:
Changes made to the Environment without our prior authorization or knowledge may have a substantial, negative impact on the provision and effectiveness of the Services and may impact the fees charged under the Quote. You agree to refrain from moving, modifying, or otherwise altering any portion of the Environment without our prior knowledge or consent. For example, you agree to refrain from adding or removing hardware from the Environment, installing applications on the Environment, or modifying the configuration or log files of the Environment without our prior knowledge or consent.
Anti-Virus; Anti-Malware:
Our anti-virus / anti-malware solution will generally protect the Environment from becoming infected with new viruses and malware (“Malware”); however, Malware that exists in the Environment at the time that the security solution is implemented may not be capable of being removed without additional services, for which a charge may be incurred. We do not warrant or guarantee that all Malware will be detected, avoided, or removed, or that any data erased, corrupted, or encrypted by Malware will be recoverable. To improve security awareness, you agree that Enstep or its designated third party affiliate may transfer information about the results of processed files, information used for URL reputation determination, security risk tracking, and statistics for protection against spam and malware. Any information obtained in this manner does not and will not contain any personal or confidential information.
Breach/Cyber Security Incident Recovery:
Unless otherwise expressly stated in the Quote, the scope of the Services does not include the remediation and/or recovery from a Security Incident (defined below). Such services, if requested by you, will be provided on a time and materials basis under our then-current hourly labor rates. Given the varied number of possible Security Incidents, we cannot and do not warrant or guarantee (i) the amount of time required to remediate the effects of a Security Incident (or that recovery will be possible under all circumstances), or (ii) that all data or systems impacted by the incident will be recoverable or remediated. For the purposes of this paragraph, a Security Incident means any unauthorized or impermissible access to or use of the Environment, or any unauthorized or impermissible disclosure of Client’s confidential information (such as user names, passwords, etc.), that (i) compromises the security or privacy of the information or applications in, or the structure or integrity of, the managed environment, or (ii) prevents normal access to the managed environment, or impedes or disrupts the normal functions of the managed environment.
Environmental Factors:
Exposure to environmental factors, such as water, heat, cold, or varying lighting conditions, may cause installed equipment to malfunction. Unless expressly stated in the Quote, we do not warrant or guarantee that installed equipment will operate error-free or in an uninterrupted manner, or that any video or audio equipment will clearly capture and/or record the details of events occurring at or near such equipment under all circumstances.
Fair Usage Policy:
Our Fair Usage Policy (“FUP”) applies to all services that are described or designated as “unlimited” or which are not expressly capped in the number of available usage hours per month. An “unlimited” service designation means that, subject to the terms of this FUP, you may use the applicable service as reasonably necessary for you to enjoy the use and benefit of the service without incurring additional time-based or usage-based costs. However, unless expressly stated otherwise in the Quote, all unlimited services are provided during our normal business hours only and are subject to our technicians’ availabilities, which cannot always be guaranteed. In addition, we reserve the right to assign our technicians as we deem necessary to handle issues that are more urgent, critical, or pressing than the request(s) or issue(s) reported by you. Consistent with this FUP, you agree to refrain from (i) creating urgent support tickets for non-urgent or non-critical issues, (ii) requesting excessive support services that are inconsistent with normal usage patterns in the industry (e.g., requesting support in lieu of training), (iii) requesting support or services that are intended to interfere, or may likely interfere, with our ability to provide our services to our other customers.
Hosted Email:
You are solely responsible for the proper use of any hosted email service provided to you (“Hosted Email”).
Hosted Email solutions are subject to acceptable use policies (“AUPs”), and your use of Hosted Email must comply with those AUPs—including ours. In all cases, you agree to refrain from uploading, posting, transmitting or distributing (or permitting any of your authorized users of the Hosted Email to upload, post, transmit or distribute) any prohibited content, which is generally content that (i) is obscene, illegal, or intended to advocate or induce the violation of any law, rule or regulation, or (ii) violates the intellectual property rights or privacy rights of any third party, or (iii) mischaracterizes you, and/or is intended to create a false identity or to otherwise attempt to mislead any person as to the identity or origin of any communication, or (iv) interferes or disrupts the services provided by Enstep or the services of any third party, or (v) contains Viruses, trojan horses or any other malicious code or programs. In addition, you must not use the Hosted Email for the purpose of sending unsolicited commercial electronic messages (“SPAM”) in violation of any federal or state law. Enstep reserves the right, but not the obligation, to suspend Client’s access to the Hosted Email and/or all transactions occurring under Client’s Hosted Email account(s) if Enstep believes, in its discretion, that Client’s email account(s) is/are being used in an improper or illegal manner.
Backup (BDR) Services:
All data transmitted over the Internet may be subject to malware and computer contaminants such as viruses, worms and trojan horses, as well as attempts by unauthorized users, such as hackers, to access or damage Client’s data. Neither Enstep nor its designated affiliates will be responsible for the outcome or results of such activities.
BDR services require a reliable, always-connected internet solution. Data backup and recovery time will depend on the speed and reliability of your internet connection. Internet and telecommunications outages will prevent the BDR services from operating correctly. In addition, all computer hardware is prone to failure due to equipment malfunction, telecommunication-related issues, etc., for which we will be held harmless. Due to technology limitations, all computer hardware, including communications equipment, network servers and related equipment, has an error transaction rate that can be minimized, but not eliminated. Enstep cannot and does not warrant that data corruption or loss will be avoided, and Client agrees that Enstep shall be held harmless if such data corruption or loss occurs. Client is strongly advised to keep a local backup of all stored data to mitigate against the unintentional loss of data.
Procurement:
Equipment and software procured by Enstep on Client’s behalf (“Procured Equipment”) may be covered by one or more manufacturer warranties, which will be passed through to Client to the greatest extent possible. By procuring equipment or software for Client, Enstep does not make any warranties or representations regarding the quality, integrity, or usefulness of the Procured Equipment. Certain equipment or software, once purchased, may not be returnable or, in certain cases, may be subject to third party return policies and/or re-stocking fees, all of which shall be Client’s responsibility in the event that a return of the Procured Equipment is requested. Enstep is not a warranty service or repair center. Enstep will facilitate the return or warranty repair of Procured Equipment; however, Client understands and agrees that (i) the return or warranty repair of Procured Equipment is governed by the terms of the warranties (if any) governing the applicable Procured Equipment, for which Enstep will be held harmless, and (ii) Enstep is not responsible for the quantity, condition, or timely delivery of the Procured Equipment once the equipment has been tendered to the designated shipping or delivery courier.
Business Review / IT Strategic Planning Meetings:
We strongly suggest that you participate in business review/strategic planning meetings as may be requested by us from time to time. These meetings are intended to educate you about recommended (and potentially crucial) modifications to your IT environment, as well as to discuss your company’s present and future IT-related needs. These reviews can provide you with important insights and strategies to make your managed IT environment more efficient and secure. You understand that by suggesting a particular service or solution, we are not endorsing any specific manufacturer or service provider.
VCTO or VCIO Services:
The advice and suggestions provided by us in our capacity as a virtual chief technology or information officer (if applicable) will be for your informational and/or educational purposes only. Enstep will not hold an actual director or officer position in Client’s company, and we will neither hold nor maintain any fiduciary relationship with Client. Under no circumstances shall Client list or place Enstep on Client’s corporate records or accounts.
Sample Policies, Procedures:
From time to time, we may provide you with sample (i.e., template) policies and procedures for use in connection with Client’s business (“Sample Policies”). The Sample Policies are for your informational use only, and do not constitute or comprise legal or professional advice, and the policies are not intended to be a substitute for the advice of competent counsel. You should seek the advice of competent legal counsel prior to using or distributing the Sample Policies, in part or in whole, in any transaction. We do not warrant or guarantee that the Sample Policies are complete, accurate, or suitable for your (or your customers’) specific needs, or that you will reduce or avoid liability by utilizing the Sample Policies in your (or your customers’) business operations.
Penetration Testing; Vulnerability Scanning:
You understand and agree that security devices, alarms, or other security measures, both physical and virtual, may be tripped or activated during the penetration testing and/or vulnerability scanning processes, despite our efforts to avoid such occurrences. You will be solely responsible for notifying any monitoring company and all law enforcement authorities of the potential for “false alarms” due to the provision of the penetration testing or vulnerability scanning services, and you agree to take all steps necessary to ensure that false alarms are not reported or treated as “real alarms” or credible threats against any person, place, or property. Some alarms and advanced security measures, when activated, may cause the partial or complete shutdown of the Environment, causing substantial downtime and/or delay to your business activities. We will not be responsible for any claims, costs, fees, or expenses arising or resulting from (i) any response to the penetration testing or vulnerability scanning services by any monitoring company or law enforcement authorities, or (ii) the partial or complete shutdown of the Environment by any alarm or security monitoring device.
No Third Party Scanning:
Unless we authorize such activity in writing, you will not conduct any test, nor request or allow any third party to conduct any test (diagnostic or otherwise), of the security system, protocols, processes, or solutions that we implement in the managed environment (“Testing Activity”). Any services required to diagnose or remediate errors, issues, or problems arising from unauthorized Testing Activity are not covered under the Quote, and if you request us (and we elect) to perform those services, those services will be billed to you at our then-current hourly rates.
Obsolescence:
If at any time any portion of the managed environment becomes outdated, obsolete, reaches the end of its useful life, or acquires “end of support” status from the applicable device’s or software’s manufacturer (“Obsolete Element”), then we may designate the device or software as “unsupported” or “non-standard” and require you to update the Obsolete Element within a reasonable time period. If you do not replace the Obsolete Element reasonably promptly, then in our discretion we may (i) continue to provide the Services to the Obsolete Element using our “best efforts” only with no warranty or requirement of remediation whatsoever regarding the operability or functionality of the Obsolete Element, or (ii) eliminate the Obsolete Element from the scope of the Services by providing written notice to you (email is sufficient for this purpose). In any event, we make no representation or warranty whatsoever regarding any Obsolete Element or the deployment, service level guarantees, or remediation activities for any Obsolete Element.
Licenses:
If we are required to re-install or replicate any software provided by you as part of the Services, then it is your responsibility to verify that all such software is properly licensed. We reserve the right, but not the obligation, to require proof of licensing before installing, re-installing, or replicating software into the managed environment. The cost of acquiring licenses is not included in the scope of the Quote unless otherwise expressly stated therein.
VOIP – Dialing 911 (Emergency) Services:
The following terms and conditions apply to your use of any VoIP service that we facilitate for you or that is provided to you by a third party provider of such service. Please note, by using VoIP services you agree to the provisions of the waiver at the end of this section. If you do not understand or do not agree with any of the terms below, you must not subscribe to, use, or rely upon any VoIP service and, instead, you must contact us immediately.
There is an important difference in how 9-1-1 (i.e., emergency) services can be dialed using a VoIP service as compared to a traditional telephone line. Calling emergency services using a VoIP service is referred to as “E911.”
Registration: You are responsible for activating the E911 dialing feature by registering the address where you will use the VoIP service. This will not be done for you, and you must take this step on your own initiative. To do this, you must log into your VoIP control panel and provide a valid physical address. If you do not take this step, then E911 services may not work correctly, or at all, using the VoIP service. Emergency service dispatchers will only send emergency personnel to a properly registered E911 service address.
Location: The address you provide in the control panel is the location to which emergency services (such as the fire department, the police department, etc.) will respond. For this reason, it is important that you correctly enter the location at which you are using the VoIP services. PO boxes are not proper addresses for registration and must not be used as your registered address. Please note, even if your account is properly registered with a correct physical address, (i) there may be a problem automatically transmitting a caller’s physical location to the emergency responders, even if the caller can reach the 911 call center, and (ii) a VoIP 911 call may go to an unstaffed call center administrative line or be routed to a call center in the wrong location. These issues are inherent to all VoIP systems and services. We will not be responsible for, and you agree to hold us harmless from, any issues, problems, incidents, damages (both bodily- and property-related), costs, expenses, and fees arising from or related to your failure to register timely and correctly your physical location information into the control panel.
Address Change(s): If you change the address used for E911 calling, the E911 services may not be available and/or may operate differently than expected. Moreover, if you do not properly and promptly register a change of address, then emergency services may be directed to the location where your services are registered and not where the emergency may be occurring. For that reason, you must register a change of address with us through the VoIP control panel no less than three (3) business days prior to your anticipated move/address change. Address changes that are provided to us with less than three (3) business days notice may cause incorrect/outdated information to be conveyed to emergency service personnel. If you are unable to provide us with at least three (3) business days notice of an address change, then you should not rely on the E911 service to provide correct physical location information to emergency service personnel. Under those circumstances, you must provide your correct physical location to emergency service dispatchers if you call them using the VoIP services.
If you do not register the VoIP service at your location and you dial 9-1-1, that call will be categorized as a “rogue 911 call.” If you are responsible for dialing a rogue 911 call, you will be charged a non-refundable and non-disputable fee of $250/call.
Power Loss: If you lose power or there is a disruption to power at the location where the VoIP services are used, then the E911 calling service will not function until power is restored. You should also be aware that after a power failure or disruption, you may need to reset or reconfigure the device prior to utilizing the service, including E911 dialing.
Internet Disruption: If your internet connection or broadband service is lost, suspended, terminated or disrupted, E911 calling will not function until the internet connection and/or broadband service is restored.
Account Suspension: If your account is suspended or terminated, then all E911 dialing services will not function.
Network Congestion: There may be a greater possibility of network congestion and/or reduced speed in the routing of E911 calls as compared to 911 dialing over traditional public telephone networks.
Messaging: All messages sent through the VoIP service must conform to the following requirements and restrictions:
WAIVER: You hereby agree to release, indemnify, defend, and hold us and our officers, directors, representatives, agents, and any third party service provider that furnishes VoIP-related services to you, harmless from any and all claims, damages, losses, suits or actions, fines, penalties, costs and expenses (including, but not limited to, attorneys’ fees), whether suffered, made, instituted or asserted by you or by any other party or person (collectively, “Claims”) arising from or related to the VoIP services, including but not limited to any failure or outage of the VoIP services, incorrect routing or use of, or any inability to use, E911 dialing features. The foregoing waiver and release shall not apply to Claims arising from our gross negligence, recklessness, or willful misconduct.
Acceptable Use Policy
The following policy applies to all hosted services provided to you, including but not limited to (and as applicable) hosted applications, hosted websites, hosted email services, and hosted infrastructure services (“Hosted Services”).
Enstep does not routinely monitor the activity of hosted accounts except to measure service utilization and/or service uptime, security-related purposes and billing-related purposes, and as necessary for us to provide or facilitate our managed services to you; however, we reserve the right to monitor Hosted Services at any time to ensure your compliance with the terms of this Acceptable Use Policy (this “AUP”) and our master services agreement, and to help monitor and ensure the safety, integrity, reliability, or security of the Hosted Services.
Similarly, we do not exercise editorial control over the content of any information or data created on or accessible over or through the Hosted Services. Instead, we prefer to advise our customers of inappropriate behavior and any necessary corrective action. If, however, Hosted Services are used in violation of this AUP, then we reserve the right to suspend your access to part or all of the Hosted Services without prior notice.
Violations of this AUP: The following constitute violations of this AUP:
Harmful or illegal uses: Use of a Hosted Service for illegal purposes or in support of illegal activities, to cause harm to minors or attempt to contact minors for illicit purposes, to transmit any material that threatens or encourages bodily harm or destruction of property or to transmit any material that harasses another is prohibited.
Fraudulent activity: Use of a Hosted Service to conduct any fraudulent activity or to engage in any unfair or deceptive practices, including but not limited to fraudulent offers to sell or buy products, items, or services, or to advance any type of financial scam such as “pyramid schemes,” “Ponzi schemes,” and “chain letters” is prohibited.
Forgery or impersonation: Adding, removing, or modifying identifying network header information to deceive or mislead is prohibited. Attempting to impersonate any person by using forged headers or other identifying information is prohibited. The use of anonymous remailers or nicknames does not constitute impersonation.
SPAM: Enstep has a zero tolerance policy for the sending of unsolicited commercial email (“SPAM”). Use of a Hosted Service to transmit any unsolicited commercial or unsolicited bulk e-mail is prohibited. You are not permitted to host, or permit the hosting of, sites or information that is advertised by SPAM from other networks. To prevent unnecessary blacklisting due to SPAM, we reserve the right to drop the section of IP space identified by SPAM or denial-of-service complaints if it is clear that the offending activity is causing harm to parties on the Internet, if open relays are on the hosted network, or if denial of service attacks are originated from the hosted network.
Internet Relay Chat (IRC): The use of IRC on a hosted server is prohibited.
Open or “anonymous” proxy: Use of open or anonymous proxy servers is prohibited.
Cryptomining: Using any portion of the Hosted Services for mining cryptocurrency or using any bandwidth or processing power made available by or through a Hosted Services for mining cryptocurrency, is prohibited.
Hosting spammers: The hosting of websites or services using a hosted server that supports spammers, or which causes (or is likely to cause) our IP space or any IP space allocated to us or our customers to be listed in any of the various SPAM databases, is prohibited. Customers violating this policy will have their server immediately removed from our network and the server will not be reconnected until such time that the customer agrees to remove all traces of the offending material immediately upon reconnection and agree to allow Enstep to access the server to confirm that all material has been completely removed. Any subscriber guilty of a second violation may be immediately and permanently removed from the hosted network for cause and without prior notice.
Email/message forging: Forging any email message header, in part or whole, is prohibited.
Unauthorized access: Use of the Hosted Services to access, or to attempt to access, the accounts of others or to penetrate, or attempt to penetrate, Enstep’s security measures or the security measures of another entity’s network or electronic communications system, whether or not the intrusion results in the corruption or loss of data, is prohibited. This includes but is not limited to accessing data not intended for you, logging into or making use of a server or account you are not expressly authorized to access, or probing the security of other networks, as well as the use or distribution of tools designed for compromising security such as password guessing programs, cracking tools, or network probing tools.
IP infringement: Use of a Hosted Service to transmit any materials that infringe any copyright, trademark, patent, trade secret or other proprietary rights of any third party, is prohibited.
Collection of personal data: Use of a Hosted Service to collect, or attempt to collect, personal information about third parties without their knowledge or consent is prohibited.
Disruptive Activity: Use of the Hosted Services for any activity which affects the ability of other people or systems to use the Hosted Services or the internet is prohibited. This includes “denial of service” (DOS) attacks against another network host or individual, “flooding” of networks, deliberate attempts to overload a service, and attempts to “crash” a host.
Distribution of malware: Intentional distribution of software or code that attempts to and/or causes damage, harassment, or annoyance to persons, data, and/or computer systems is prohibited.
Excessive use or abuse of shared resources: The Hosted Services depend on shared resources. Excessive use or abuse of these shared network resources by one customer may have a negative impact on all other customers. Misuse of network resources in a manner which impairs network performance is prohibited. You are prohibited from excessive consumption of resources, including CPU time, memory, and session time. You may not use resource-intensive programs which negatively impact other customers or the performances of our systems or networks.
Allowing the misuse of your account: You are responsible for any misuse of your account, even if the inappropriate activity was committed by an employee or independent contractor. You shall not permit your hosted network, through action or inaction, to be configured in such a way that gives a third party the capability to use your hosted network in an illegal or inappropriate manner. You must take adequate security measures to prevent or minimize unauthorized use of your account. It is your responsibility to keep your account credentials secure.
To maintain the security and integrity of the hosted environment, we reserve the right, but not the obligation, to filter content, Enstep requests, or website access for any web requests made from within the hosted environment.
Revisions to this AUP: We reserve the right to revise or modify this AUP at any time. Changes to this AUP shall not be grounds for early contract termination or non-payment.
Where do you go
from here?
Reach out and find out how
great Enstep support can be!
