This overview is intended for business clients evaluating how ProTek handles systems, credentials, devices, and customer information.
Governance and Personnel
- Access is assigned according to job responsibilities and least-privilege principles.
- Administrative credentials are restricted to authorized personnel.
- Employees are subject to confidentiality, acceptable-use, credential-handling, and security requirements.
- Access is reviewed and revoked when roles change or employment ends.
Technical Controls
- Individual accounts and multi-factor authentication are used where supported and appropriate.
- Approved systems are used for credentials, tickets, documentation, remote access, and service records.
- Sensitive information is protected in transit and at rest where supported by the platform and service.
- Administrative and destructive actions are logged where supported.
- Endpoint security, monitoring, patching, and backup controls are applied according to the contracted service plan.
Physical and Laboratory Controls
- Customer devices and media are stored in designated nonpublic areas.
- Device condition and identifiers are documented at intake when appropriate.
- Data recovery and transfer work is performed in controlled work areas by authorized personnel.
- Customer working data is logically separated and temporary copies follow a 30-day maximum retention rule unless an exception applies.
Incident Management
Suspected incidents are escalated, investigated, contained, documented, and mitigated. ProTek coordinates client notification and response according to applicable contracts and law.
Vendors and Subprocessors
ProTek uses approved providers for hosting, email, messaging, security, remote management, backups, payments, and business operations. Regulated data is placed with providers only when the arrangement is appropriate and required contractual protections are in place.
Client Responsibilities
Security is shared. Clients are responsible for timely approvals, accurate user lists, lawful instructions, appropriate internal access controls, current contact information, employee offboarding notices, and maintaining service plans appropriate to their risks.
Documentation Requests
Clients may request additional information, applicable service descriptions, a business associate agreement, or a security questionnaire response by contacting support@protek.team.