Minimum Technology & Security Standards

Recommended Technology Platform • Version 1.0 • Last updated February 1st, 2026
Why this exists
These standards define the minimum technology and security conditions required for Bit Perfection to deliver managed services consistently. They are a baseline—not a guarantee that cyber incidents, failures, or downtime can never occur.

This page is the “Recommended Technology Platform” and “Minimum Standards” resource referenced by Bit Perfection managed services documentation. Exact products may change over time; the required capability is the standard, while approved vendors and licenses are identified in the applicable Proposal, Approved Software List, or onboarding documentation.

Quick Reference

Area Minimum Requirement
Operating systems Vendor-supported operating systems only. Windows endpoints must use Windows 11 Pro, Enterprise, or Education; Windows 10 requires an active Extended Security Updates (ESU) entitlement and written temporary approval.
Hardware Business-class, vendor-supported hardware capable of running the required supported operating system and security tools. Critical servers and network infrastructure must have current warranty/support or an approved replacement plan.
Management & endpoint security Bit Perfection-approved RMM, endpoint protection/EDR, patching, and security controls must remain installed, healthy, and enabled on managed systems.
Identity & access Unique user accounts, least-privilege access, and MFA for cloud productivity/email, privileged accounts, remote access, and security/admin portals.
Email & cloud Supported Microsoft 365 or Google Workspace configuration, appropriate licensing, email authentication, and approved filtering/security controls when those services are in scope.
Network Business-class managed firewall, supported firmware, secure Wi-Fi, segmented guest access, and no direct exposure of RDP or other management services to the public internet.
Backup & recovery Business-critical data must be protected by an approved backup/recovery solution with appropriate retention, an isolated recovery copy, and periodic restore validation.
Business software Legally licensed, vendor-supported applications. Business-critical line-of-business software must have available vendor support.
Power & physical environment Servers, storage, firewall, and core network equipment must have appropriate UPS protection and be installed in a reasonably secure, ventilated location.
Access & change control Bit Perfection must receive the administrative access and vendor authorizations needed to manage covered systems. Material infrastructure/security changes must be coordinated with us.

1. Purpose and Scope

  • These Minimum Technology & Security Standards establish the baseline conditions required for Bit Perfection to consistently support, secure, monitor, and maintain technology covered by a Managed Services Agreement (the “Covered Environment”).
  • These standards apply only when they are referenced by a signed Agreement, Proposal, or other written service document. If there is a conflict between this page and a signed Agreement or Proposal, the signed Agreement or Proposal controls.
  • The exact products and vendors used to satisfy a standard may be identified in the Proposal, Approved Software List, onboarding documentation, or other written documentation. Bit Perfection may approve functionally equivalent replacement technologies as our platform evolves.

2. Supported Operating Systems and Lifecycle

  • All operating systems, firmware, and core infrastructure software in the Covered Environment must be within the vendor’s supported lifecycle and eligible to receive security updates.
  • Windows workstations must run Windows 11 Pro, Enterprise, or Education. Windows Home editions and Windows in S mode are not supported as the standard configuration for managed business endpoints.
  • Windows 10 may be accepted only as a temporary exception when the device is enrolled in a valid Microsoft Extended Security Updates (ESU) program, remains technically supportable, and has written approval from Bit Perfection. A replacement or upgrade plan may be required.
  • Windows Server systems must run a Microsoft-supported server operating system. End-of-support server operating systems require a documented temporary exception and, where available, an active extended support/security update entitlement.
  • macOS devices, when included in scope, must run a version currently receiving security updates from Apple. Other operating systems require written approval before they are considered supported under the Agreement.

3. Hardware Standards

  • Managed computers must be business-class hardware that is reliable, serviceable, and capable of running the required operating system, monitoring, security, and productivity applications.
  • As a general baseline, Windows workstations must have an SSD, at least 8 GB of RAM, and hardware that meets Microsoft’s requirements for the supported version of Windows, including TPM 2.0 and Secure Boot where required. Higher specifications may be required based on workload.
  • Business-critical servers, firewalls, switches, wireless infrastructure, and storage systems must be covered by current manufacturer warranty/support or have an approved replacement/spare strategy. Equipment with recurring hardware faults or unavailable security updates may be designated for replacement even if it remains operational.
  • Consumer-grade routers, wireless gateways, unmanaged switches, or other devices may not be used as the sole production infrastructure when they prevent the monitoring, security, segmentation, or administrative access required by Bit Perfection.

4. Endpoint Management and Security

  • All managed endpoints and servers must permit installation and operation of Bit Perfection-approved Remote Monitoring & Management (RMM), endpoint protection/EDR, patching, and related management/security agents.
  • Required management and security agents may not be disabled, removed, blocked, or materially reconfigured by the Client or a third party without Bit Perfection’s written approval.
  • Supported operating systems and approved third-party applications must be allowed to receive security updates on the maintenance schedule established by Bit Perfection. Client-requested update deferrals that materially increase risk may require a documented exception.
  • Host firewalls must remain enabled unless an approved technical requirement calls for an alternative configuration.
  • Portable computers must use full-disk encryption such as BitLocker or FileVault where supported, with recovery information stored in an approved administrative system.
  • Standard users should not routinely operate with local administrator privileges. Administrative access must be limited to approved accounts and technical need. Managed devices must use automatic screen locking after a reasonable period of inactivity, generally no more than 15 minutes.

5. Identity, Authentication, and Privileged Access

  • Each user must have an individually assigned account. Shared user credentials are not permitted unless technically necessary and specifically approved.
  • Multi-factor authentication (MFA) is required for Microsoft 365 or Google Workspace accounts, privileged/administrator accounts, remote access services, password managers, security platforms, and other business systems containing sensitive information where MFA is supported.
  • Phishing-resistant MFA methods such as FIDO2/security keys or passkeys are preferred for privileged access where supported. SMS or voice-based MFA may be used only when stronger methods are unavailable or an exception is approved.
  • Access must follow least-privilege principles. Administrative accounts should be separate from normal day-to-day user accounts where the platform supports that model.
  • The Client must promptly notify Bit Perfection of employee terminations, role changes, suspected credential compromise, or other events requiring access changes.

6. Microsoft 365, Google Workspace, Email, and Cloud Services

  • Cloud productivity and email systems in scope must use supported business subscriptions and licensing sufficient for the security and management features required by the selected service plan or Proposal.
  • Legacy or insecure authentication methods must be disabled where the platform and application dependencies allow.
  • For Client-owned domains that send email, SPF, DKIM, and DMARC must be configured where technically supported. Bit Perfection may recommend phased DMARC enforcement based on the Client’s mail flow and third-party senders.
  • When email security is included in the Covered Environment, an approved email security/spam filtering service or approved native security configuration must remain enabled.
  • Administrative access to business cloud platforms must remain under Client/Bit Perfection control and may not rely solely on a former employee, outside vendor, or personal consumer account.

7. Network, Firewall, Wi-Fi, and Remote Access

  • Each managed location must use a business-class firewall or security gateway that is actively supported by the vendor, receives security/firmware updates, and provides the management and security capabilities required by Bit Perfection.
  • Where a firewall depends on security subscriptions or support licensing for threat protection, firmware updates, or management, those subscriptions must remain active.
  • Business wireless networks must use currently accepted encryption such as WPA2-AES or WPA3. WEP, legacy WPA, and TKIP are not acceptable for production wireless networks. Guest wireless access must be separated from business systems unless a documented design requires otherwise.
  • Remote administration and remote user access must use an approved secure method such as a VPN or zero-trust/secure access solution with MFA. RDP, SMB, administrative web interfaces, and similar management services may not be exposed directly to the public internet except under a documented, approved exception.
  • Default vendor credentials must be changed, and Bit Perfection must have the administrative access required to manage network devices that are part of the Covered Environment.

8. Backup and Recovery

  • Business-critical data must be protected by a supported backup and recovery solution approved by Bit Perfection, whether that solution is included in the selected Service Plan, purchased separately, or maintained by an approved third party.
  • Unless a different recovery objective is documented, business-critical server and data backups should run at least daily and retain recoverable versions for at least 30 days. Systems with greater business, regulatory, or operational risk may require more frequent backups or longer retention.
  • The backup design must maintain at least one recovery copy that is isolated from ordinary production credentials or otherwise protected against routine deletion, compromise, or ransomware. Backups must be encrypted in transit and at rest where the platform supports it.
  • Restore testing and reporting will be performed by Bit Perfection only when included in the selected Service Plan or separately purchased. When Bit Perfection does not manage or test the backup solution, the Client remains responsible for verifying backup success and recoverability.
  • A third-party or Client-managed backup service may be required to provide status reports, evidence of successful backups, or restore validation upon reasonable request.

9. Software, Licensing, and Line-of-Business Applications

  • All software must be legally licensed and supported by its publisher. Pirated, cracked, unlicensed, abandoned, or end-of-support software is not permitted in the Covered Environment.
  • Software listed in the Agreement’s Approved Software List, or a functionally equivalent product approved by Bit Perfection, is the standard supported platform.
  • Business-critical line-of-business applications must have an available vendor support path. Where the application vendor requires an active maintenance/support agreement to provide updates or technical assistance, the Client must maintain that agreement.
  • Software that cannot be patched, requires obsolete operating systems, weakens required security controls, or conflicts with management/security agents may require replacement, isolation, or a documented exception.

10. Power, Physical Environment, and Connectivity

  • Servers, network-attached storage, firewalls, and core switching equipment must be connected to appropriately sized UPS/surge protection. UPS batteries and units that fail self-tests or can no longer provide adequate runtime must be replaced.
  • Core technology equipment must be installed in a reasonably secure, dry, ventilated environment with adequate power and temperature control. Network/server equipment should not be placed where unauthorized users can easily disconnect, reset, or tamper with it.
  • Internet connectivity must provide sufficient bandwidth, stability, and availability for the Client’s normal operations and cloud services. Bit Perfection may recommend redundant internet connectivity when loss of internet access would materially interrupt the Client’s business.

11. Administrative Access, Documentation, and Changes

  • The Client must provide Bit Perfection with the administrative access, permissions, vendor authorizations, and cooperation reasonably required to manage systems included in the Covered Environment.
  • The Client must allow Bit Perfection to maintain an inventory of managed devices, users, key applications, vendors, and core infrastructure information required to deliver Services.
  • Material changes to firewalls, servers, identity systems, Microsoft 365/Google Workspace, backup systems, security tools, network addressing, internet services, or other managed infrastructure must be coordinated with Bit Perfection. Uncoordinated changes by the Client or third parties may fall outside normal support commitments under the Agreement.

12. Non-Compliant Systems, Remediation, and Exceptions

  • A system that does not meet these standards at onboarding is not automatically rejected. Bit Perfection may work with the Client to document the issue, the business or security risk, the recommended remediation, and a reasonable target date based on urgency, availability, and budget.
  • Temporary exceptions must be approved by Bit Perfection and may require compensating controls, additional monitoring, restricted access, a replacement plan, or written acknowledgement of risk.
  • Support involving non-compliant hardware, software, or configurations may be provided on a best-effort basis, may be billable, and may be excluded from Response Time Guarantees or other service commitments as provided in the Agreement.
  • Bit Perfection may decline to connect, manage, or support a system when doing so would create an unreasonable security, reliability, legal, or operational risk. Continued failure to maintain required standards may result in the remedies available under the Managed Services Agreement.

13. Updates to These Standards

  • Technology lifecycles and security threats change. Bit Perfection may revise these standards to address end-of-support products, newly identified risks, changes to our management platform, or evolving security practices.
  • Material changes will be versioned and communicated to the Client’s Primary IT Contact with reasonable advance notice whenever practicable. Urgent security changes may require a shorter implementation period when a delay would create material risk.
  • The current published version should always display a version number and last-updated date so the Client and Bit Perfection can identify the applicable standard.

14. Informational Reference Points

These standards are informed by widely recognized cybersecurity guidance and vendor lifecycle requirements. This does not mean that Bit Perfection or the Client is certified as compliant with any particular framework solely by meeting this page.

Questions or exception requests
Contact Bit Perfection through your normal support or account-management channel. We will document any approved exception, compensating control, and remediation plan as appropriate.