Resource
Security & Data Handling Overview
How we think about access, data and risk — described honestly, without claiming certifications or guarantees we do not hold.
Last Updated: September 20, 2026
This document describes Retrisa’s approach and intent. It is not a certification, an audit report, or a warranty. Specific security obligations owed to a customer are set out in that customer’s written agreement.
Our Starting Position
A managed IT provider holds privileged access to its customers’ environments. That access is the most sensitive thing we are trusted with, and we treat it that way.
We would rather describe what we actually do than publish a list of impressive-sounding claims. Where we do not yet hold a certification, we say so.
Least Privilege and Administrative Access
Administrative access is granted for a defined purpose and scope, and is intended to be no broader than the work requires. Where a platform supports separating everyday accounts from privileged accounts, we use that separation.
Multi-factor authentication is expected on accounts used to administer customer environments. Access is reviewed as roles and engagements change, and removed when it is no longer needed.
Client Separation
Customer environments, credentials and documentation are kept logically separated. Access to a given customer’s information is limited to personnel who need it in order to deliver that customer’s services.
Data Handling
We aim to collect and retain only the information needed to deliver services, and to keep it for only as long as it is needed or legally required.
Credentials are never requested or accepted through ordinary email or web forms. Where sensitive material has to be exchanged, we provide an appropriate secure method.
Information handled while providing services to a customer is governed by that customer’s agreement, including any Data Processing Addendum or Business Associate Agreement in place.
How We Secure the Environments We Manage
Our standard approach to a managed environment emphasizes:
- Identity as the primary control: MFA coverage, conditional access, privileged account review;
- Known, managed and encrypted devices rather than an unmanaged fleet;
- Patching on a defined cadence, with visibility into what is falling behind;
- Email authentication and phishing defenses;
- Endpoint protection deployed and actually reporting;
- Backups that are verified, and restores that are tested; and
- Prompt, complete offboarding when people leave.
What We Do Not Claim
To be explicit, and to avoid any ambiguity:
- We do not claim SOC 2 certification;
- We do not claim HIPAA certification, and no vendor can be “HIPAA certified”;
- We do not claim any other security certification we do not hold;
- We do not guarantee that a breach, outage, data loss or security incident will be prevented; and
- We do not publish customer names, counts, testimonials or statistics we cannot substantiate.
Security work reduces risk and improves your ability to detect and recover. It does not eliminate risk, and any provider telling you otherwise is selling something.
Compliance Support
We can help an organization prepare for frameworks and questionnaires — mapping existing controls, closing gaps and producing evidence. That is readiness and technical support work. It is not an audit, an attestation or a certification, and it does not make Retrisa your auditor.
Questions
Security questions, questionnaire requests and diligence inquiries can be sent to support@retrisa.com.