Contact Us

How we work

Everything we do, answered.

SafePoint IT is a Chicago-area managed IT services and cybersecurity provider for businesses of roughly 10 to 100 users. Everything below is what we tell prospective clients on a first call, written out so you can read it before you talk to anyone. Response times, exclusions and contract terms come straight from our published agreements, including the parts most providers leave for you to discover later.

49 questions across 8 sectionsLast reviewed August 2026Cannot find it? Ask us directly

Getting started and switching

6 questions

What the first 90 days look like, and what leaving your current provider actually involves.

What does onboarding look like when we become a client?

Onboarding starts before we touch anything. Sales, the engineer who performed your assessment, and our technical team hold an internal knowledge transfer so everyone working on your account understands your environment and your priorities from day one. Then we hold a kickoff with you.

From there we run a 30/60/90 plan built from your assessment, so the dates and deliverables are specific to your environment, not a template.

  • First 30 days, onboarding. We inventory every device, account, license and vendor relationship and build your documentation from scratch instead of inheriting someone else's notes. We establish administrative access and deploy monitoring, endpoint security, managed detection and response, email security and backup across the fleet.
  • Days 30 to 60, remediation. Discovery always surfaces items. We prioritize them by risk and tell you what we found in plain language, including anything your previous provider will not enjoy reading.
  • Days 60 to 90, stabilization. A documented environment, steady-state support, and your first Business Review.

One thing we say plainly. Our SLA commitments formally begin 60 days in, which is the transition period written into the SLA itself. Committing to a 30 minute critical response on an environment we have not finished documenting and securing would not be a real commitment. Until then we use commercially reasonable efforts, and if your environment settles sooner we can agree in writing to start the commitments early. The whole first 90 days carry our satisfaction guarantee either way.

Can you act as our primary technology administrator?

Yes. For most clients we hold the top-level administrative role across everything we manage: identity and email, device management, network equipment, and the business applications you ask us to cover.

Administrator of record is not the same as owner. The accounts, the tenancy and the data stay yours, and handing you administrative credentials whenever you ask is written into our agreement. If you want a standing break-glass admin account of your own, we set one up on request.

Where a previous provider holds those credentials, recovering them is the first work of the transition. We make the requests in writing and copy you, so you can see what has and has not been provided instead of having to referee it.

Where an incumbent will not cooperate, most major platforms have a domain-verification recovery path that does not depend on them at all. It typically adds one to two weeks. That is worth knowing while you are setting a start date, because it is the item most likely to move one.

How long does switching providers take, and how disruptive is it?

Roughly 90 days from signature to steady state. Most of that work is invisible to your staff. Your people keep working while we build documentation, deploy tools and take over administrative access underneath them.

Where we deliberately go slowly is platform changes. We do not migrate you off a working system during a provider transition just because we would have chosen differently. One change at a time, and the provider change is the change.

If the assessment finds significant misalignment with best practice, remediation may be sized as a separate project instead of being absorbed into onboarding. That call is driven by hours, and small corrections are simply part of onboarding.

What do you need from our current provider to make the switch?

Less than you would expect. We plan every transition on the assumption that cooperation may be limited, because often it is.

What we need comes from you, not from them: administrative access to your email and identity platform in an account created in your own name, access to your device management platform, registrar and DNS access, and physical access to any on-premises equipment.

What we would ask of them and appreciate but never depend on: existing documentation and licensing information.

One recommendation from experience. Instead of having your current provider hand over their own administrative account, create a separate administrative account in your company's name and give us access to that. You get a clean revocation point, and the transition never depends on anyone's goodwill.

How long have you been in business, and how big is your team?

In business since 2002, from two offices, our Palatine headquarters and downtown Chicago. Around 19 staff, including a dedicated service manager, service coordinator, account manager and NOC engineer alongside our systems and solutions engineers.

We have been named to the Inc. 5000 three times.

The more useful number: our typical client runs 10 to 100 users. A company that size sits in the core of what we do, not at the edge of it, which is not true of a provider whose book is mostly enterprise or mostly one-person shops.

The roles matter more than the headcount. A provider with no dedicated service coordinator is one where engineers triage their own queue, and the queue is what loses.

Is there a setup or onboarding fee to become a client?

Yes. Bringing a new client on is a project, and it is quoted separately from your monthly fee. It gets sized during the assessment as a block of hours, so you see the number before you commit to it rather than after.

We put a number on it up front because onboarding is real work with a real cost. A provider who tells you it is free is either recovering it somewhere less visible or not doing much of it.

This is a one-time project fee for becoming a client. It is a different thing from adding and removing staff once you are up and running, which is part of your monthly service at no additional charge.

Day-to-day support

7 questions

Hours, response commitments, escalation, and who picks up the phone.

What are your standard support hours?

Business hours are Monday through Friday, 8:30 AM to 5:00 PM Central, excluding observed U.S. federal holidays.

Security monitoring is not tied to those hours. It runs 24 hours a day, every day, and is watched by a security operations center, not by an inbox.

For emergencies outside business hours, an on-call engineer covers 7:00 AM to 11:00 PM Central, described under after-hours coverage.

What are your response times?

These come from our published Service Level Agreement, so they are contractual, not marketing.

PriorityResponse, business hoursResponse, after hoursResolution target
P1 Critical30 minutes1 hour4 hours
P2 High1 hour2 hours8 hours
P3 Medium2 hoursNext business day1 to 2 business days
P4 LowNext business dayNext business day3 to 5 business days

Response Times are commitments. Resolution Targets are objectives we use commercially reasonable efforts to meet. We say it that plainly instead of calling a resolution time guaranteed, because whether a fix lands in four hours can depend on a vendor we do not control.

How priority gets set. We combine Impact, meaning how many people are affected, with Urgency, meaning whether a critical process has stopped. Whole company down with work stopped is P1. One user with a workaround is P4.

How the clock works. Resolution may be a permanent fix or an acceptable temporary workaround that restores your ability to work. The clock starts when we acknowledge and stops when your point of contact confirms the issue is resolved. We pause it only where progress is blocked by a third-party vendor, or by something we need from you and are waiting on. Both get documented on the ticket.

Some industries need an override, and we write it into the agreement. For healthcare clients, any interruption to a clinical or patient-facing system is P1 by default no matter how few users it touches. The same mechanism works for a filing deadline, a payroll run, or a production line.

Is remote support unlimited, or is there a ticket cap?

Unlimited for covered services. No ticket cap, no per-incident charge, and no meter running while your staff decide whether a problem is worth reporting.

That last part is the actual point. Capped plans train people not to call, and the problems they stop reporting are the early ones.

What happens after hours, on a weekend, or in an emergency?

An on-call engineer covers emergencies, meaning P1 and P2 priorities, at no extra charge, on the support phone line. Combined with business hours, help desk coverage runs from 7:00 AM to 11:00 PM Central. After-hours tickets carry their own committed response times, listed under response times.

Between 11:00 PM and 7:00 AM the help desk is offline, and we would sooner print that than write "24/7 support" and hope nobody tests it at 3 AM.

What never goes offline is security. Monitoring and managed detection and response run around the clock, with a security operations center behind them. If something is detected on your environment at 2 AM it gets acted on at 2 AM, by the security team, not an inbox that gets read in the morning.

Routine, non-urgent work requested after hours is scheduled into the next business day. After-hours work that is out of scope is quoted before it starts and billed in 15 minute increments.

How do we submit tickets, and can we see status and history?

Four intake channels, all carrying the same SLA commitments: the client portal, a web support form, email to our support address, and the support phone line.

Everything is tracked in our professional services platform. Every ticket carries its full history, time entries and notes, and authorized contacts can view status and history through the portal at any time.

One honest note about what counts. Requests through those four channels carry the SLA commitments. A text to an engineer's personal phone, or a mention in passing on a call, may still get worked, but it is not tracked and it does not count against a response time. That is how we keep the numbers we report to you honest, and it is worth telling your staff during onboarding.

You also receive a Technology Checkpoint report, monthly or quarterly depending on what fits your environment, a cadence we set together during onboarding, showing ticket volume, categories, response and resolution performance measured against the SLA, and any trend worth acting on. Live incidents and scheduled maintenance are posted publicly on our status page.

Do we get a dedicated contact, or a queue?

Both, and the roles are separate on purpose.

  • An account manager owns the relationship, reporting and Business Reviews. Not a dispatcher. This is the person who notices a pattern in your tickets before you have to raise it.
  • A service manager owns ticket flow, escalation and scheduling. If something is stuck, this is your escalation point.
  • Our CTO oversees technology and is the next escalation point. He is involved in your transition directly, not just at the sales stage.
  • Day-to-day support comes from our engineering team. A service coordinator triages every incoming ticket and assigns it.

We do not assign one named engineer to your account, and we will tell you why, without dressing it up. A company your size with one named engineer is one vacation away from having no support. The failure mode of a boutique provider is a single point of knowledge, not a lack of skill.

What makes a shared team work is documentation, described under how we document your environment.

Do you come on-site, and how fast?

Yes. Our standard service area runs within roughly 40 miles of our Palatine headquarters, and we have engineers living in and around Chicago, so most of the metro is close to someone.

How much on-site is included depends on your tier. Our middle tier includes one scheduled visit per month. Our top tier includes unlimited on-site. Additional or unscheduled visits outside the included allowance bill at the on-site rate, covered under rates for work outside the agreement. Travel inside the standard service area is included.

For an urgent need we typically dispatch same day or next business day depending on when the call comes in. We will not promise you a guaranteed on-site arrival window, because honest scheduling depends on the day. Most of what historically required a visit we now resolve remotely.

Have a support scenario we have not covered?Describe it and we will tell you exactly how it would be handled, priority and all.

Ask a question

Platforms and devices

6 questions

What we support, what we will not force you to replace, and what happens to hardware at both ends of its life.

Do you fully support Macs, or just tolerate them?

Fully, and there is no difference in service levels, response times or ticket handling between platforms.

Macs are a meaningful share of the fleet we manage, including environments that are Mac-first, not a Windows shop with two Macs in a corner.

The honest distinction is in staffing. We do not have a separate Mac-only team. Our engineers work across mixed fleets and handle Apple every day as part of that. For a company your size that is an advantage, not a gap, because your ticket goes to whoever is available instead of waiting for the one Apple person to free up.

Security carries over in full. The security and management stack we deploy, endpoint protection, managed detection and response, patching, monitoring and backup, runs natively on macOS as well as Windows. A Mac under our management gets the same protection as any Windows machine, with no gap in coverage and no watered-down Apple version of the stack.

We also work with Apple device management, configuration profiles, disk encryption key escrow, app deployment, update enforcement, and zero-touch enrollment as normal daily work.

Do you support Google Workspace, or only Microsoft 365?

Both, in full. Google Workspace administration is a named covered service in our Service Level Agreement, on equal footing with Microsoft 365.

That covers user and group administration, Drive structure and sharing controls, security settings including two-step verification enforcement and context-aware access, spam and routing rules, and day-to-day troubleshooting.

It also covers the email authentication layer, meaning SPF, DKIM and DMARC. That is worth naming, because a misconfigured DMARC record is one of the most common findings in our assessments and one of the least likely to have been noticed. We add backup and email filtering to Google Workspace environments as standard, because the native retention in either platform is not a backup.

Will you make us replace the tools we already use?

No, and we will not pretend otherwise to sell you a migration.

If you already run a well-built platform that does its job, we will manage it, not move you off it. On device management in particular, the work is the same regardless of which console issues it. Configuration profiles, restrictions, encryption key escrow, app deployment, update enforcement and enrollment are platform constructs. The management tool is the console you drive them from, and we already work across several depending on the client.

Where we do recommend a change, it is because something is genuinely unsupported, insecure or end of life, and we will show you the evidence instead of just asserting it. A provider transition is already a change. Stacking a platform migration on top of it is how transitions go badly.

Do you support a fully remote or distributed team?

Yes, and it is the normal case in our book, not an accommodation. Our client base is predominantly cloud-first and distributed, so provisioning devices to home addresses, remote onboarding and offboarding, cloud identity administration, and managing endpoints that never touch a corporate network are ordinary work for us.

We build the machine here, ship it directly to the new hire's home address anywhere in the United States, and they sign in once to a device that configures itself. No imaging visit, and no shipping a laptop to an office first so somebody can open the box.

On departure it runs in reverse. Access is disabled immediately across every platform, we arrange return shipping, and we confirm the device is back in inventory instead of assuming it.

If your people are spread across several states and your current provider needs somebody to be in a building, that is the gap this closes.

Do you support personally owned computers?

Yes, within limits worth stating up front. A personally owned computer can be brought under management as part of that person's user seat, with no additional per-device charge, subject to a written acknowledgment from the device owner covering what management on a personal device actually means.

If you would rather keep a personal machine entirely out of scope, we document it as excluded and support requests against it fall outside the agreement. Either answer is workable.

What we will not do is manage a personal device informally with nothing written down. That is the arrangement that goes wrong later, and it goes wrong for the employee, not for us.

In practice this comes up most often with owners and executives, so it is worth settling during onboarding instead of the first time something breaks.

What happens to our old equipment when we retire it?

Redeployment or recycling, per your instruction. We do not resell client equipment.

For equipment being retired outright: we collect the device, remove it from active inventory, and hold it securely until our recycling partner's scheduled collection. The partner destroys the storage media and reports the media serial numbers back to us afterward, and that documentation is available to you on request.

Two things better said now than assumed later. Disposal is not same-week. Retired equipment accumulates between scheduled collections, which is exactly why secure interim custody matters and why a retired device stays in your inventory the whole time instead of being treated as gone the moment somebody stops using it. And the serial numbers we can report are for the storage media destroyed, which is the part that carried data and the part an auditor or a privacy question is actually about.

Want to donate still-serviceable equipment? Tell us. We wipe it, document the wipe, and hand it back to you to donate. What we do not do is put client hardware back into circulation ourselves.

Scope of service

7 questions

What sits inside the monthly fee, what gets billed separately, and who we have done this for.

What is included in the monthly fee, and what is billed separately?

One monthly per-user fee covers the ongoing service:

  • Unlimited remote help desk for covered services
  • Remote monitoring and management of every endpoint
  • Patch and operating system update management, Apple and Windows alike
  • Microsoft 365 or Google Workspace administration
  • Managed endpoint security, email security, and 24/7 security monitoring
  • Managed backup of each user's email and files, with tested restores
  • Security awareness training for staff
  • Vendor coordination on your behalf
  • Documentation of your environment, maintained continuously
  • Employee onboarding and offboarding

Billed separately: project work, migrations, new deployments and upgrades; hardware and software procurement; server maintenance and backup, priced per server; end-user training beyond reasonable how-to guidance; custom development; consumables; and anything outside the scope defined in your accepted quote.

Security, backup, training and 24/7 monitoring are not optional line items we strip out to hit a price. They are in every tier.

Do you handle new hires and departures, including remote staff?

Yes. Both are part of your monthly service with no one-time setup charge, per onboarding or per offboarding, however many people come and go, and office, remote and hybrid staff are handled the same way.

Onboarding runs from a standard form and we ask for two business days' notice so the device arrives enrolled, configured and ready instead of being set up while the new person waits. Expedited same-day requests are often possible. We create accounts, configure security, assign permissions, install software, prepare the device, and either deliver or ship it depending on location.

Five onboardings in a month cost the same as none: nothing. The per-user count on your next invoice moves with headcount, but the setup work itself is never billed. Some providers price it per event. We do not.

Offboarding runs from its own form and we can execute the same day, which is the one that actually matters. Inconsistent offboarding is one of the most common findings in our assessments, and it is how former employees keep access for months.

Can you work alongside our internal IT person or department?

Yes, and this is a large part of what we do. We supplement your team with whatever it needs, whether that is ongoing coverage or specialized expertise they should not have to build.

Common shapes this takes: we own the security stack and monitoring while your person owns applications and users; we cover vacations and after-hours so one person is not permanently on call; or we take specific projects your team does not have the hours for.

A co-managed arrangement needs its boundaries written down rather than assumed, so we define who owns what in the agreement before we start.

Do you handle hardware purchasing, and do you mark it up?

Yes, and yes. We source hardware and software and handle the transaction, and there is a markup on resale. Better you read that here than discover it on an invoice.

You are also free to buy direct. Apple hardware in particular is often best bought from Apple, and we are glad for you to do that as long as the machine is built to our specification. Our specification is about warranty coverage, configuration and age, not a particular model, and we will confirm a build before you order.

Equipment bought to specification carries no fees from us. Warranty claims, return authorizations, part replacement and vendor chasing are part of the service, and you never really see that work happen.

Equipment bought outside specification is still supported, and your help desk is unlimited either way. The caveat, and it applies only to hardware bought outside our specification: when a machine keeps generating tickets because of the hardware itself, that repeat work can become billable. If that starts happening we put an estimate in front of you for approval first, so nothing gets invoiced that you had not already agreed to.

Replacement planning and disposal. We track age and warranty across your whole fleet and give you a rolling refresh forecast, so hardware is a budget line, not an emergency. Disposal is secure wipe and certified destruction with documentation, which matters more than the disposal itself if you hold client data.

Do you manage our software licenses and renewals?

Yes. User provisioning and deprovisioning, license assignment, permission management, and a periodic review of licenses nobody is using.

That last one is where the money is. Paying for seats belonging to people who left is the most common piece of quiet waste we find in a new environment, and it is usually months old by the time anyone looks.

Renewal dates live in your documentation, so a renewal is a decision you make in advance rather than a charge you notice afterwards.

Where nonprofit, education or grant-funded pricing is available to you, we will put you on it. We would rather your license spend be right than be marked up.

Do you have experience in our industry?

Our book is concentrated in healthcare, meaning medical, dental and veterinary; financial services, including CPA and accounting firms; professional services and law firms; nonprofits and schools; and manufacturing.

Healthcare is a genuine specialty, not a listed vertical. Our SLA carries a clinical priority rule where any interruption to a clinical or patient-facing system is treated as P1 by default regardless of how few users it touches, and we execute Business Associate Agreements as a matter of course.

For nonprofits we understand the budget discipline that comes with donor and grant funding: predictable flat pricing, no surprise line items, and a bias toward the nonprofit and grant-funded licensing you already qualify for instead of selling you something new.

What matters more than the vertical is the shape. Lean or no internal IT, somebody in operations or finance carrying technology as a second job, and a compliance or governance obligation that a person has to answer for personally. If that is you, we have done this before.

Are you an approved E-Rate (USAC) service provider?

Yes. E-Rate is the federal program, administered by the Universal Service Administrative Company (USAC) under the FCC, that helps eligible schools and libraries fund connectivity and eligible technology services at a discount.

E-Rate Service Provider
Premier Hosting, Inc dba SafePoint IT is an approved E-Rate service provider.
SPIN / 498 ID: 143048151

If you are a school or library, that approval matters when you pick a provider, because program funding can only flow through an approved one. The rhythm of the program, filing windows, funding years, documentation, is something we have been through, and we support schools today.

Not a school or library? Then this question is not for you, and nothing about your pricing touches it.

Security and compliance

8 questions

What is deployed, what happens during an incident, and what we will not claim.

How do you protect our business from cyber threats?

A layered model, because any single control fails eventually. Every item below is included in every tier, not sold as an upgrade:

  • Next-generation endpoint protection on every managed device
  • Managed detection and response with a 24/7 security operations center behind it
  • Email security for phishing and impersonation detection
  • Email and cloud collaboration backup with independent retention
  • Privileged access management, so day-to-day users are not local administrators
  • Security awareness training with simulated phishing
  • Multi-factor authentication enforcement and administration
  • DNS and network edge protection
  • Patch management

The only element we will let a client opt out of is security awareness training, and only where they carry no cyber insurance. Everything else is non-negotiable, because a partial security posture is the one we would end up defending after an incident.

We describe our stack by capability, not by vendor name, on a public page. Prospective clients receive the specific product list in their proposal.

How do you monitor and patch our environment?

Continuous agent-based monitoring on every managed endpoint, covering device health, disk, memory, uptime, operating system version, installed software and patch state, on Macs and Windows alike, plus your servers and cloud systems.

Patching runs on a defined schedule with staged rollout instead of pushing everything to everyone at once, which is how a routine update becomes a company-wide outage. Operating system update enforcement on Apple devices runs through your device management platform.

Alerts route into our ticketing system automatically, so a failing disk becomes a tracked ticket with an owner, not an email someone might read.

If we have a security incident, what do you do, and is it included?

Detection, triage, containment and coordination are included. Our security operations center runs 24/7 and can isolate a compromised endpoint from the network immediately, without waiting for business hours.

Included: initial detection and alerting, endpoint isolation, investigation of what happened and what was touched, remediation of systems under our management, notification to you without undue delay, and coordination with your cyber insurance carrier and outside counsel.

Billed separately: extended forensic investigation by a specialist firm, legal and regulatory notification work, and large-scale rebuild or recovery projects.

We are honest that a serious incident becomes a project. A provider who tells you unlimited incident response is included has not priced a real one.

We carry Technology Errors and Omissions and Cyber Liability coverage, and a certificate is available on request.

Do you run vulnerability scans or security testing?

Two different things live under this question, and they get confused constantly, so it is worth keeping them straight.

24/7 security monitoring is included in every tier. It is its own dedicated tool, it watches for active threats in real time, and it never turns off.

Vulnerability scanning is an add-on for clients who need it, typically for compliance, cyber insurance conditions, or industry requirements. It is scheduled scanning across servers, workstations and network devices that looks for weaknesses before an attacker finds them. Findings come with a priority and a recommendation, not as a raw report you have to interpret.

The distinction in one line: monitoring catches an attack in progress, scanning finds the doors an attack would use.

Penetration testing and formal compliance assessments are a different thing again, and we scope them as projects. Many clients in regulated industries run them annually, and we will tell you plainly whether you need one or whether the included monitoring is sufficient for where you are.

Do you provide security training and phishing simulations?

Yes, and we manage the whole process instead of handing you a platform login. Short, engaging lessons that teach people how to spot a threat, plus regular simulated phishing to test awareness in realistic scenarios.

We handle scheduling, tracking and reporting, including who has not completed training, which is the part that quietly never happens when a client is left to run it themselves.

Your cyber insurance carrier will very likely ask whether you do this. Being able to produce completion records is the difference between a smooth renewal and an awkward one.

Can you help us with SOC 2, HIPAA, or client security questionnaires?

We are not a compliance auditor and we will not position ourselves as one. Our part is simpler: we run the technical controls those audits ask about, and we hand you the evidence when someone asks for it.

In practice that means access control and multi-factor enforcement, endpoint hardening, patch management with reportable history, backup and restore testing with documented results, logging and monitoring, offboarding with a documented trail, and asset inventory. Those map directly onto the Security trust services criteria, and they are the questions that stall companies when a client sends a questionnaire.

For client security questionnaires, we answer the technical sections directly instead of sending you a template to fill in yourself. That is included, not billed by the hour.

We work with healthcare clients under HIPAA and execute Business Associate Agreements. If you pursue a formal SOC 2 attestation you will need an audit firm for the attestation itself, and we work alongside them as the party producing technical evidence.

Will you help with our cyber insurance application or renewal?

Yes, and it is included rather than billed. We complete the technical sections of the application and attest to the controls we actually operate, instead of handing you a questionnaire full of terms you would have to go and research.

Where a carrier requires specific controls as a condition of coverage, those become our deadlines to implement and report on. Not yours to chase.

Worth knowing before your next renewal. Carriers have tightened considerably. Multi-factor authentication everywhere, endpoint detection and response, tested backups, and documented security awareness training are now common conditions of coverage, not discounts on it. All four are included in every tier we sell, which is a large part of why we do not let clients strip them out.

If you carry no cyber policy at all, we will say so plainly during a Business Review. It is the one control that changes what a bad day actually costs you.

What security certifications does SafePoint IT hold?

SafePoint IT does not currently hold a SOC 2 Type II attestation or ISO 27001 certification.

What we can provide:

  • Certificate of insurance for Technology Errors and Omissions and Cyber Liability
  • Documentation of the specific controls deployed in your environment, on request at any time
  • Our published Service Level Agreement, Master Services Agreement, Terms and Privacy Policy

We also work with healthcare clients under HIPAA and execute Business Associate Agreements, so we operate under regulated-industry expectations even where a certification is not the mechanism.

Better you read it here than discover it three weeks into an evaluation. A provider who leaves the question unanswered is usually answering it the same way.

Backup and documentation

4 questions

What survives a bad day, and who owns the record of your environment.

What do you take responsibility for on backup and disaster recovery?

Three layers, three different answers, and a provider who blurs them is hiding either a cost or a gap.

Your cloud environment, included. Backup of each user's Microsoft 365 or Google Workspace data, meaning mail, files, calendar and contacts, with retention independent of the platform.

This matters more than most companies realize. Your platform's own retention is not a backup. A file deleted or encrypted by ransomware past the retention window is simply gone.

Workstations, by exception. We do not back up every workstation by default, and that is deliberate. Most staff keep their documents in Microsoft 365 or Google Workspace or on a server, so paying to back up every machine is cost without benefit. During onboarding we look for the handful of machines where someone genuinely works locally, and we bring those to your first Business Review as a recommendation. Adding them is priced per machine, on top of the monthly fee.

Servers, always, with their own fee. Every server we manage carries a monthly maintenance fee and a monthly backup fee, sized during the assessment. Finding your servers, and what it costs to protect them properly, is one of the main things the assessment is for.

We test restores instead of trusting that the job ran. A backup nobody has restored from is an assumption, and the assumption fails on the day you need it. Test results are documented, and you can see them.

Business continuity planning, meaning documented recovery objectives and a written plan for the scenarios that actually threaten a company your size, is part of the ongoing relationship, not a separate engagement.

How do you document our environment, and can we get that documentation?

We document continuously as part of the service, instead of compiling something at the end. That covers device inventory and configuration, network topology and equipment, all accounts and access, licensing and renewal dates, vendor contacts and account numbers, administrative credentials, and written procedures for the things specific to your business.

Yes, it remains yours. Your environment documentation is your property under our Master Services Agreement, and you can request an export at any point during the relationship, not only on the way out.

This is also the direct answer to the single-point-of-knowledge risk. If the engineer who knows your environment is unavailable, the next one opens the documentation.

Who holds our administrator credentials?

Administrative credentials live in an access-controlled vault, not in a spreadsheet and not in an engineer's personal password manager. Access is role-based and logged.

  • You own your administrative accounts. We do not hold the only keys to your environment, and handing you administrative credentials whenever you ask is written into our agreement.
  • A standing break-glass account is available on request. We do not set one up by default, and that is deliberate. In smaller companies a standing admin account ends up used for everyday things, approving an app install on the owner's laptop without anyone running it past us, and that is exactly how environments get compromised. If you want one, say so and we will build it properly.
  • Multi-factor authentication on every administrative account, ours and yours.
  • Privilege elevation is managed, so day-to-day users are not local administrators and each elevation is approved and logged.

On remote access. We maintain persistent management connections to managed endpoints, and the practice is documented in our Master Services Agreement. During business hours we connect in response to a ticketed request. After hours we rely on an idle-time threshold, or we ask permission first. If you ever see a connection you did not expect, call us and we will reconcile it against ticket records.

Do you use subcontractors or offshore support?

Your day-to-day support is delivered by SafePoint IT employees. Our entire help desk is staffed by engineers local to the Chicago area.

We do use third parties in defined, limited situations, and it is fairer to describe them than to answer no:

  • Specialist project work, for example software development or DevOps engagements, under written agreement for a specific scoped project.
  • Remote hands outside our geography, for a client site beyond the Chicago area.
  • Our security operations center, which belongs to our managed detection and response provider and runs 24/7. They see security telemetry from endpoint agents. This is how any credible 24/7 monitoring works, at any provider.

All of them operate under written agreements including confidentiality, and Business Associate Agreements where regulated data is involved.

Reporting and planning

3 questions

What you see monthly, what you see quarterly, and how budgets stop surprising you.

What reports and business reviews do we receive?

Two things, on two different rhythms, and they are deliberately different animals.

The Technology Checkpoint report. Generated automatically from live data: ticket volume and categories, response and resolution performance against the SLA, patch status, backup status, asset changes and upcoming lifecycle needs. Then a person reviews it before it reaches you, because an automated report nobody checked is noise with a logo on it. It runs monthly or quarterly, and we set the cadence with you during onboarding based on what your environment actually generates, which usually tracks with company size.

The Business Review. This is the centerpiece of the relationship, and it is the piece many providers quietly skip. Your account manager compiles it personally, built around your specific environment, nothing about it is automated, and our CTO reviews every one before it reaches you.

A Business Review's real job is accountability in both directions. It is where we lay out what was promised during the sale, what has been implemented, and what is still in progress, so the gap between the pitch and the reality is a document we hand you, never a feeling you slowly develop.

It also covers risk, lifecycle, budget and recommendations. Cadence is monthly, quarterly, semi-annual or annual, set after onboarding based on what your business needs. We do not run reviews on a calendar for the calendar's sake.

Your first Business Review happens inside the first 90 days, not a year in.

How do we know we are getting real value for what we pay?

By outcomes you can see, not activity you have to take on faith. Uptime, support response measured against the SLA, reduced risk, and fewer unexpected issues over time.

The honest measure of a good managed IT relationship is that the ticket count on repetitive problems goes down. If you are paying us the same amount every month and still having the same conversation every month, something is wrong and the Business Review is where we say so.

We connect technical performance to business impact in every review, in language you can take to a board or a partner group without translating it first.

How do you help us avoid surprise IT costs?

We track your technology lifecycle, warranties, software renewals and business goals, and build a forward-looking roadmap with a multi-year budget forecast, so you plan ahead instead of reacting.

The practical effect is that hardware refresh becomes a budget line you approved twelve months earlier, instead of an emergency purchase in the middle of a quarter.

Project work is always quoted before it starts. We do not bill a surprise.

Pricing and agreements

8 questions

How pricing works, what the terms actually say, and how you leave if you want to.

What does fully managed IT support cost?

From $130 to $195 per user, per month, across three tiers. The tiers differ in how much on-site support is included, from none, to one scheduled visit per month, to unlimited. Everything else, including the full security stack, is the same in all three.

Where your exact dollar amount lands takes an assessment, because the number depends on your environment. What we need to know before the number is honest: how many servers you run, on-site or virtual, since every server carries its own monthly maintenance and backup fee on top of the per-user figure; how many office locations you have; what compliance obligations apply, the conditions on your cyber insurance policy, and most importantly, how much remediation your environment requires. You get a firm number after an assessment, in writing, before anything is signed.

What the monthly fee covers. Every user, every endpoint, the full security and management stack, backup of each user's email and files, monitoring, unlimited remote support, employee onboarding and offboarding, and documentation. There is no separate device charge and no per-endpoint uplift on top of the per-user number. Where device count runs well ahead of user count, as it does in some clinical and manufacturing environments, we structure the arrangement around that instead of pretending per-user math works everywhere.

We often recommend starting on a higher tier than you will settle on, which is the opposite of what you would expect. The first months of any provider change are when the most breaks and the most gets discovered, so during the period you are most likely to need us, nothing should be metered. Once things are stable, typically around six months, you step down. Moving between tiers stays available in both directions.

We are also straightforward about fit. There is a size below which a full managed service is not the right answer for you, and we will say so on the first call, not the third.

What does co-managed IT cost, if we already have an internal IT team?

There is no published number for co-managed, and anyone who hands you one before understanding the split is guessing.

A co-managed arrangement is assembled around what your team actually needs. Some teams want our security stack and tooling running under their own hands. Some want help desk overflow, or after-hours coverage so one person is not permanently on call. Some want project capacity their team does not have hours for. Each mix prices differently, because each mix is a different amount of tooling and labor.

What we do promise: the split of responsibilities goes in writing before we start, the price follows the scope, and both are quoted after a conversation, never guessed at. How the arrangement itself works is covered under working alongside internal IT.

What are your rates for work outside the agreement?

Project work such as wiring, migrations, new deployments, environment upgrades and anything outside your accepted scope is quoted separately before it starts. Never billed as a surprise.

Out-of-scope hourly work bills in 15 minute increments, at a published rate card that varies by the type of work: on-site engineering, project engineering, consulting, and development each have their own rate. The full rate card is part of every proposal and every signed agreement, so the numbers are in front of you before you could ever be billed against them.

Anything that would be billable gets an estimate in front of you for approval first. Nothing gets invoiced that you had not already agreed to.

Third-party licensing you buy through us, such as Microsoft 365 or Google Workspace seats, is separate from the monthly support fee. The security and management tooling that comes with the managed service is included in it.

How does billing work?

Recurring monthly fees are invoiced ten days before the first of the service month and are due on the first, so you are never being billed for a month already half spent.

Out-of-scope hourly work is invoiced weekly, on Thursday or Friday, on Net 10 terms, so it never accumulates into a quarterly surprise.

Equipment purchases are invoiced immediately after the purchase. Minor amounts are the exception; those ride along on the standard weekly invoice.

We accept ACH, wire, eCheck and credit card. Card payments carry a processing surcharge; the other three do not. Late balances accrue interest from the original due date. The exact rates are in your agreement, in front of you before you sign it.

We expect you to actually read your invoice each month and flag anything that looks wrong. Raise it right away and we sort it before it compounds into a reconciliation problem for both of us.

Do you prorate the invoice when we add or remove users mid-month?

No, in either direction, and here is how it actually works.

Your invoice is generated from the active user list on the invoice date. Someone hired after that date is not billed until the next invoice, even though we do the onboarding work right away. Someone removed after that date comes off the next invoice, and there is no partial credit for the days in between.

It cuts both ways on purpose. We do not issue partial charges for mid-month additions, so we do not issue partial credits for mid-month removals. Across a year, hires and departures come out close to a wash, and neither of us spends time auditing day counts.

The one exception: if you submitted the removal before the invoice date and the person still appeared, that is our miss, and we credit it.

If you ever spot someone on the invoice who no longer works for you, send the offboarding request and they come off going forward. That request is also the thing that actually closes their access, which matters more than the line item.

What is the contract term, and how do we cancel?
  • Initial term. Our standard agreement runs 36 months. Shorter initial terms are available and we quote them regularly, particularly for a company leaving another provider and comparing options carefully.
  • Renewal. Automatic one-year renewal terms unless either party gives written notice of non-renewal at least 60 days before the end of the current term.
  • First 90 days. A 100% satisfaction guarantee. You can terminate for any reason or no reason, with written notice.
  • After 90 days. Termination is for cause, with a 30 day cure period for a material breach.

The satisfaction guarantee exists because the risk of a provider change should sit with us, not with you. Asking you to sign three years to find out whether we are any good would put the risk on the wrong side of the table.

The full Master Services Agreement is provided with any quote, so you read the terms before you are asked to sign anything.

Will our price go up?

It depends on the shape of the engagement, so here are the three scenarios.

Fully managed. The support fee adjusts once a year, between 3 and 5 percent, with at least 30 days' written notice, and those limits are contractual, not discretionary. Two forces drive it: the security and management stack bundled into your fee is repriced annually by our vendors, and wages have to keep pace with inflation for the engineers who answer your tickets.

Co-managed. Depends on what your fee actually contains. A co-managed arrangement may or may not include tooling or labor, so the annual adjustment follows what is in it, and we set that expectation in the agreement itself.

Tools bought through us without management. When you buy a product through us as licensing only, vendor increases pass through, and in recent years vendors have raised 10 to 15 percent in a single year. We show you the vendor notice, so you can see the increase is theirs.

If we leave, how do we get our data and documentation back?

This is a clause in our Master Services Agreement, not an assurance. On termination or expiration:

  • We return or securely destroy your data at your direction, subject only to anything we are legally required to retain or that exists in routine backups, which is deleted on our normal retention schedule.
  • We provide transition assistance to your successor provider for up to 90 days after termination. The standard handover, giving your new provider access and turning over documentation, costs nothing. Fees apply only to work beyond that, meaning migration work that is normally the incoming provider's responsibility, moving your phone service, a virtual server, or a platform, for example, and any such work is quoted before it starts, never invoiced by surprise.
  • You own your data throughout. Our access is a limited license to provide the service, and it ends when the service ends.

In practice you receive your full documentation export, all administrative credentials, network and device configurations, licensing and vendor detail, and your ticket history, all at no charge.

We want clients who stay because the service is good, not clients who stay because leaving is hard. And we do not believe in burning bridges. This industry is smaller than it looks, people change companies and call us again, and more than one former client has come back. An exit handled well is part of the service too.

Ready for a real number?Pricing starts with a short discovery call to verify fit, then a scheduled assessment of your environment. The number you get back afterwards is firm, in writing.

Request an assessment
chevron-down linkedin facebook pinterest youtube rss twitter instagram facebook-blank rss-blank linkedin-blank pinterest youtube twitter instagram