Security & resilience

Small company. Deliberate controls.

Security at Climb and Maintain is part of ordinary operations. We protect physical access, power, identities, endpoints, administrative systems, and recovery paths without publishing the details that would make those controls easier to work around.

Our security baseline

Security is a stack, not a checkbox.

No single control is perfect. We use overlapping physical, technical, and operational safeguards so that one failure does not have to become the whole failure.

01Physical security

Protected around the clock.

Our office environment has continuous physical security and controlled access. We keep the public description intentionally high-level so the security controls do not become a map of how they work.

02Power resilience

Clean power and graceful shutdowns.

Critical company IT equipment is protected by conditioned uninterruptible power supplies. That helps reduce risk from outages, brownouts, surges, and abrupt power loss.

03Identity & access

More than a password.

Multi-factor authentication is required across company accounts and administrative systems wherever the service supports it. Hardware security keys are our preferred authentication factor when they are available.

04Company endpoints

Hardware-backed login controls.

Company-managed computers use hardware-backed authentication for access. A stolen password by itself should not be enough to unlock a company workstation.

05Administrative systems

Layered controls for privileged access.

Hosting, administrative, and infrastructure systems use additional access controls and multi-factor authentication. Privileged access is kept separate from ordinary public use wherever practical.

06Recovery & monitoring

Plan for failure before it happens.

We use encrypted and off-system backups where appropriate, along with automated service monitoring and alerting, so security also includes recovery and availability rather than only keeping people out.

What we do not publish

Transparency has a sensible stopping point.

We are happy to describe our security posture, but we do not publish device serial numbers, exact network topology, physical-security implementation details, recovery credentials, key inventories, or step-by-step privileged access procedures.

If you have a legitimate security question or believe you found a vulnerability in a Climb and Maintain service, please contact us with enough detail for us to investigate safely.

A practical standard

Protect the work without making the work impossible.

We choose controls that are strong enough to matter and usable enough to stay enabled. Security that gets bypassed because it makes routine work impossible is not much of a control.