MP Technology applies administrative, technical, and operational safeguards intended to protect its own systems, business information, credentials, and access used during authorized service delivery. This page provides a high-level overview and a responsible path for reporting a suspected vulnerability affecting MP Technology's public systems.
Scope note: This is not a certification, warranty, service-level commitment, or complete description of internal controls. Client-specific security responsibilities and requirements are established in the applicable agreement, statement of work, data-processing terms, or security exhibit.
1. Security Principles
Security practices are selected according to the sensitivity of the information, the systems involved, and the risks presented. MP Technology's operating principles include:
- limiting access to authorized individuals with a legitimate business need;
- using strong authentication and multifactor authentication where appropriate;
- maintaining managed and protected administrative devices;
- reducing unnecessary collection, access, and retention of customer information;
- using secure methods for remote and privileged access;
- maintaining software, configuration, logging, and incident-handling practices appropriate to the system; and
- reviewing safeguards as technology, threats, and business requirements change.
2. Access to Client Environments
Access to a client environment is limited to the authorized engagement and the access made available by the client. Access may be temporary or persistent depending on the statement of work, technical requirements, and written authorization. MP Technology does not assume responsibility for operating or securing a client environment beyond responsibilities expressly accepted in writing.
Clients remain responsible for their users, business decisions, legal and regulatory obligations, licensing, data governance, risk acceptance, and systems not placed within MP Technology's defined scope.
3. Devices, Credentials, and Data
Devices used for administrative access may be protected through measures such as centralized management, encryption, endpoint protection, patching, configuration standards, and access revocation. Credentials and administrative access are handled according to the sensitivity and requirements of the applicable platform and engagement.
Customer information is accessed and used only as reasonably necessary for authorized discovery, advisory, project, troubleshooting, documentation, communication, or related business purposes. MP Technology avoids retaining customer data when it is not needed for the engagement, business records, legal obligations, or legitimate operational purposes.
4. Third-Party Platforms
MP Technology uses third-party cloud, communications, security, productivity, customer-management, invoicing, and remote-access platforms. We consider security and operational suitability when selecting and configuring providers. Third-party services remain subject to their own architecture, availability, security controls, terms, and data practices.
5. Incident Handling
MP Technology maintains processes intended to support identification, investigation, containment, escalation, communication, recovery, and follow-up when a suspected security event affects systems or information under its control. Notification obligations concerning client information are governed by applicable law and the relevant written agreement.
6. Responsible Vulnerability Reporting
If you believe you have identified a vulnerability affecting the MP Technology public website or another system clearly owned and operated by MP Technology, report it through the contact page and identify the inquiry as a security vulnerability report.
Please include:
- the affected URL, host, or service;
- a clear description of the observed behavior and potential impact;
- reproduction steps, screenshots, or supporting details where safe to provide; and
- contact information for follow-up.
Do not include passwords, authentication tokens, personal information, confidential client data, or exploit code that is unnecessary to explain the issue.
7. Good-Faith Testing Boundaries
MP Technology welcomes responsible reports but does not authorize unrestricted security testing. Unless written authorization has been provided, do not:
- access, modify, download, or destroy data that is not your own;
- attempt to access client systems or third-party services;
- use social engineering, phishing, credential attacks, malware, or physical intrusion;
- perform denial-of-service, load, or availability testing;
- continue testing after sensitive data or unauthorized access is encountered; or
- publicly disclose an unresolved issue before MP Technology has had a reasonable opportunity to investigate and address it.
Testing that violates law, affects third parties, disrupts service, or exceeds these boundaries is not authorized by this statement.
8. No Guarantee
No security program can eliminate all risk. MP Technology does not represent that its systems, vendors, or services are invulnerable, continuously available, or free from error. Specific client commitments must be stated in an executed agreement.
9. Security Questions
Prospects, clients, vendors, and authorized reviewers may use the contact page for security questions, due-diligence requests, or vulnerability reports.