Protected around the clock.
Our office environment has continuous physical security and controlled access. We keep the public description intentionally high-level so the security controls do not become a map of how they work.
Security & resilience
Security at Climb and Maintain is part of ordinary operations. We protect physical access, power, identities, endpoints, administrative systems, and recovery paths without publishing the details that would make those controls easier to work around.
Our security baseline
No single control is perfect. We use overlapping physical, technical, and operational safeguards so that one failure does not have to become the whole failure.
Our office environment has continuous physical security and controlled access. We keep the public description intentionally high-level so the security controls do not become a map of how they work.
Critical company IT equipment is protected by conditioned uninterruptible power supplies. That helps reduce risk from outages, brownouts, surges, and abrupt power loss.
Multi-factor authentication is required across company accounts and administrative systems wherever the service supports it. Hardware security keys are our preferred authentication factor when they are available.
Company-managed computers use hardware-backed authentication for access. A stolen password by itself should not be enough to unlock a company workstation.
Hosting, administrative, and infrastructure systems use additional access controls and multi-factor authentication. Privileged access is kept separate from ordinary public use wherever practical.
We use encrypted and off-system backups where appropriate, along with automated service monitoring and alerting, so security also includes recovery and availability rather than only keeping people out.
What we do not publish
We are happy to describe our security posture, but we do not publish device serial numbers, exact network topology, physical-security implementation details, recovery credentials, key inventories, or step-by-step privileged access procedures.
If you have a legitimate security question or believe you found a vulnerability in a Climb and Maintain service, please contact us with enough detail for us to investigate safely.
A practical standard
We choose controls that are strong enough to matter and usable enough to stay enabled. Security that gets bypassed because it makes routine work impossible is not much of a control.