The Circle Square Standard

We don't promise uptime. We engineer for it.

No one honestly can promise uptime on a system they haven't planned for. We promise the work that makes uptime possible, and we write it down so you can hold us to it.

Ten commitments

What every client can hold us to.

  1. 01

    We start with your business.

    Before we recommend anything, we complete a Downtime Ledger with you: what your business earns in an hour, which systems that depends on, and what an outage would cost. We revisit it at least once a year.
  2. 02

    Every client has a plan.

    We build a written continuity and disaster recovery plan with you, or a written list of the gaps and what closing each takes. We test recovery on a schedule set by your service level, typically once a year, and share the results.
  3. 03

    Every client has a person.

    A primary engineer owns your account and knows your business.
  4. 04

    We're there when it breaks.

    Our help desk answers and remediates during your covered hours: business hours (Monday to Friday, 8 AM to 6 PM), after hours (6 PM to 8 AM, plus weekends and holidays), or both on 24-hour coverage, 365 days a year. Monitoring and automated security remediation run 24x7x365 on every plan.
  5. 05

    We respond on a clock.

    Our response times are published in our Services Guide, by severity. They are set out below.
  6. 06

    We verify, not assume.

    Backups are monitored around the clock and recovery is verified daily. Patches are reviewed before they're applied. Systems are monitored 24x7 and alerts are worked by people.
  7. 07

    We hold a minimum standard.

    We manage environments we can stand behind: supported operating systems, genuine licensed software, servers under warranty and on battery backup, encrypted wireless, and a monitored backup. If yours isn't there yet, we'll tell you exactly what it takes.
  8. 08

    We secure to a framework.

    Our security baseline maps to NIST CSF 2.0 and CIS Controls v8.1, so your posture can be explained to an auditor, an insurer or a board.
  9. 09

    We sit down with you.

    Your vCIO meets with you to review risk, continuity, spend and what's next, typically once a year and more often if your service level includes it.
  10. 10

    AI holds up.

    Any AI we deploy comes through Signet: reviewed by a person, logged, and signed for by a named engineer. Nothing that decides about a person. Nothing deployed where we can't see or administer it.

Response

We respond on a clock.

SeverityExampleFirst responseUpdates until resolved
CriticalService not available: all users and functionsWithin 2 business hours; around the clock on 24-hour coverageUntil resolved
Significant degradationMany users or business-critical functions affectedWithin 4 business hoursUntil resolved
Limited degradationLimited users or functions; business continuesWithin 8 business hoursDaily
Small degradationOne user; business continuesWithin 2 business daysAs needed
Projects and maintenancePlanned workWithin 4 business daysWeekly

Response times as published in our Services Guide.

What we won't do

  • We won't take on an environment we can't secure.
  • We won't sell you technology that doesn't protect or produce revenue, and we'd rather consolidate tools than add them.
  • We won't mark up AI model or API usage.
  • We won't promise numbers we don't control.

What we ask of you

  • Tell us when the business changes.
  • Keep one authorized contact current.
  • Fund the fixes we agree are necessary.
  • Give us the administrative access we need to protect you.

The Standard describes how we work. Your agreement with us is governed by the Master Services Agreement and Services Guide.

Find out what an hour costs you.

Book a Downtime Ledger

About 60 minutes. Your numbers. You keep the result.