Security Overview
Security practices appropriate to our size, documented transparently. Azroth provides independent third-party maintenance, lifecycle support, environment optimization, and troubleshooting for NetApp storage environments approaching or beyond OEM end-of-availability, end-of-life, or end-of-service-life milestones. We are a small, remote-first, U.S.-based team of five founding engineers with deep technical support backgrounds.
Review status: confirm actual tooling, policies, and contacts before publishing
Security is integral to the trust required for support work. We apply practical controls appropriate to our current size and operating model, and we aim to describe those controls plainly rather than imply certifications or capabilities we do not hold. This page is a high-level overview; more detailed security, insurance, and reference information may be available under NDA during a procurement review.
Our Security Approach
Azroth limits access to customer information and customer environments to what is reasonably necessary for an authorized assessment or support engagement. We seek to use clear scopes of work, authorized points of contact, least-privilege access, and documented handoffs. Our operational controls are reviewed as the company and its service-delivery footprint grow.
[Current security-owner role, policy-review cadence, and approved tooling pending confirmation]
Data Handling
What we may handle
During a Lifecycle Risk Assessment, troubleshooting activity, or authorized support engagement, Azroth may receive customer-provided information such as:
- asset inventories and system models;
- general architecture, configuration, version, and lifecycle information;
- capacity, performance, health, diagnostic, and support-case information;
- business contacts and communication history; and
- other technical information necessary to evaluate or deliver the agreed service.
We ask customers not to place credentials, patient information, payment-card information, or other unnecessary sensitive personal information in general website forms or routine support materials. Where access to a customer environment is needed, the customer and the applicable agreement should define the authorized scope and access method.
Storage, transmission, and access
Operational standard: Customer information is intended to be stored only in access-controlled business systems approved by Azroth, and transmitted using secure, approved channels. Access should be limited to personnel with a business need to know and should be removed when no longer required. [Approved storage and transmission tooling pending confirmation]
Operational standard: Azroth does not request or retain customer credentials in general-purpose website forms. Where credentials or access methods are necessary for an authorized engagement, they should be exchanged and handled through an approved, customer-authorized process.
Retention and deletion: We retain customer information for the period reasonably necessary to perform the assessment or services, maintain appropriate business records, meet legal or contractual obligations, and resolve disputes. At the end of the applicable retention period or as required by a signed agreement, Azroth will delete, return, or securely dispose of customer information as appropriate, subject to legal, backup, and recordkeeping needs. [Retention schedule pending confirmation]
Remote Access Controls
Remote support is performed only when authorized by the customer and within the scope of the applicable engagement.
Company policy: All remote access to customer systems requires multi-factor authentication and is logged. Remote sessions must use a customer-approved secure access path, such as a customer-provided VPN, secure remote-access solution, or other approved method. Azroth personnel may not share accounts or use a customer environment beyond the authorized scope. [Actual VPN/MFA tooling in use pending confirmation]
Company policy: Remote-access permissions are limited to the personnel and duration necessary for the engagement and are reviewed or removed when no longer needed. Azroth coordinates access and escalation with the customer's designated contacts.
Customers may have their own access, logging, session-recording, approval, or jump-host requirements. Azroth will work within those requirements when mutually agreed.
Personnel and Confidentiality
Azroth's five founding engineers are U.S.-based, long-tenured former NetApp technical and escalation support engineers, bringing more than 75 years of combined relevant experience. Their experience supports technical depth and continuity, but it is not a substitute for disciplined handling of customer information.
Personnel policy: Before receiving access to customer information or systems, personnel are subject to Azroth's approved screening, confidentiality, and access-authorization practices. Personnel with access to customer information are expected to follow confidentiality obligations and applicable security procedures. [Background-check policy pending confirmation]
Azroth will limit access to qualified personnel who need it for an authorized business purpose. We do not represent that former employment with NetApp creates an affiliation with, endorsement by, or authorization from NetApp.
Subcontractors and Field-Service Partners
Azroth's current core delivery focus is remote-first support for NetApp environments. If an engagement requires field-service or specialized capacity that Azroth does not directly staff, we will coordinate that support only with appropriately qualified partners and only as authorized by the customer and applicable agreement.
Partner requirement: Any field-service partner or subcontractor that receives customer information or access to a customer environment must be bound by written confidentiality and data-handling obligations appropriate to the engagement. Azroth will disclose the use of material subcontracted capacity when required by the applicable agreement. [Specific contractual requirements pending confirmation]
Incident Response and Customer Notification
Azroth is developing and formalizing its incident-response process as it scales.
Incident-response commitment: If Azroth confirms an incident involving unauthorized access to, acquisition of, loss of, or disclosure of customer information under our control, we will investigate, contain, and communicate with affected customers in a timely manner, consistent with applicable law and our contractual commitments. Specific notification timelines, cooperation obligations, and remediation responsibilities should be addressed in the applicable signed agreement. [Formal IR process pending definition]
We encourage customers to report a suspected security issue involving Azroth to [Security contact email pending]. Please do not send sensitive technical details, credentials, or exploit instructions through an unsecured channel.
Business Continuity and Service Resilience
Azroth is intentionally built as a multi-engineer team rather than a single-expert practice. Our five founding engineers provide overlapping NetApp experience and a shared escalation culture, helping reduce single-person dependency for assessments, troubleshooting, and continuity of customer context.
This does not eliminate all small-company risk. We set expectations transparently: availability, response commitments, backup coverage, parts logistics, and on-site requirements are defined per service scope and signed agreement. [Business-continuity and service-coverage documentation pending]
Certifications, Attestations, and Insurance
Azroth does not currently hold SOC 2, ISO 27001, or similar third-party security attestations. We are evaluating a certification roadmap as the company scales.
Security documentation, insurance certificates, and reference information are available under NDA during procurement review, where available and appropriate.
Insurance: [General liability / E&O / cyber insurance details pending — once secured]
We will not claim compliance with HIPAA, PCI DSS, NIST, or other standards unless and until the relevant controls, assessments, and legal review support that claim. Customers in regulated industries remain responsible for determining whether Azroth's services and the agreed controls meet their requirements.
Responsible Disclosure
If you believe you have identified a security vulnerability affecting an Azroth website, account, or system, please contact [Security contact email pending] with enough information for us to investigate. We ask that you act in good faith, avoid accessing data that is not yours, avoid disrupting services, and give us a reasonable opportunity to assess and address the report.
Security and Procurement Contact
For security questionnaires, procurement requests, NDA requests, or responsible-disclosure reports, contact:
[Security contact email pending]
[Legal entity name pending]
[Business mailing address pending]
Before publishing: confirm the approved storage and transmission tools, MFA/logging implementation, remote-access workflow, personnel screening policy, partner contract requirements, retention schedule, formal incident-response process, business-continuity documentation, insurance details, legal entity, mailing address, and security contact email. This page is an overview, not a substitute for a signed services agreement, security addendum, or DPA.