Ordering Logic: To scale existing mandates with tiered credits and avoid redundant setup fees, please utilize our Payment Portal. Use this Catalog for new service enrollments and distinct structural orders only. To ensure full fiscal transparency, all hardware, cloud services, and VoIP usage are delivered as pure MSRP pass-throughs.

The Stewardship Model: Provision for a specific number of Personas that evolve with your organization. For your permanent infrastructure, Annual Mandates provide one month of stewardship at no additional cost. Two-Year Mandates extend this advantage to 1.5 months. Monthly Mandates provide on-demand elasticity, serving as a flexible operational buffer for short-term contractors and transitional staff.

Architectural Governance: To enforce consistent security and governance without sacrificing flexibility, your architecture is anchored by a single Identity Provider (Microsoft or Google). From this baseline, you dictate your footprint: drive deep integration within a single-cloud Primary Foundation or provision Multi-Cloud Enclaves for specialized teams. continue reading …

Core Stewardship Mandates (Cloud Personas)

Full Concierge Single-Cloud
Microsoft 365
Description
The Full Concierge Single-cloud Mandate is our Executive Standard: a comprehensive stewardship residency that pairs the strategic depth of a dedicated CIO with senior-level engineering. We manage your firm's entire technical lifecycle, including long-term technology roadmapping, cybersecurity hardening, daily employee support, and cloud service management. By acting as your single point of accountability for all technology vendors, we eliminate the "productivity tax" of unmanaged IT and ensure uninterrupted billability. This establishes the architectural baseline for teams requiring durable performance, verifiable data integrity, and a permanent, high-trust partner to lead their digital strategy.
Investment

$225 per unit / month
with annual commitment
5 users min. on first order
$250 one-time asset hardening / PC
One-time per-org 365 foundation is ordered separately.



Check our Service Blueprints and our detailed Mandates feature list for more information.

Note: Virtual Desktop and Virtual App Delivery available as add-ons (see add-ons section below)
Commitment
USD  Monthly | Yearly | 2-Year
EUR  Monthly | Yearly | 2-Year
Full Concierge Enterprise Multi-Cloud
Microsoft 365 + Google Workspace (or Zoho Workplace)
Description
The Multi-Cloud Standard. Advanced governance for teams operating across fragmented cloud ecosystems. This mandate eliminates administrative islands, keeps systems aligned, and supports a frictionless experience while mitigating orphaned data and identity risks.
Investment

$290 per unit / month
with annual commitment
5 users min. on first order
$250 one-time asset hardening / PC
No asset hardening for ChromeOS devices
Macs in a M365 estate, and PCs or Macs in a Google estate need the Outlier mandate.
Any applicable, one-time, per-org ecosystem or hardware foundations are ordered separately.



Check our Service Blueprints and our detailed Mandates feature list for more information.

Note: When you need a secondary collaborative environment strictly to isolate management or sensitive R&D workflows, we also offer The Concierge Cloud Atelier. The Atelier completely air-gaps your data from Big Tech ecosystems and makes your intellectual property immune to AI training scans by encrypting it before it ever reaches a server.

Note: Windows Virtual App Delivery available as an add-on. Virtual Desktop is included natively in the Full Concierge Federated Enterprise mandate.

Commitment
USD  Monthly | Yearly | 2-Year
EUR  Monthly | Yearly | 2-Year
Full Concierge Single-Cloud
Google Workspace
Description
The Hardened Baseline. This mandate is designed for firms seeking to harden their perimeter and reduce capital hardware costs for task-oriented and cloud-native teams. It combines the near-impenetrable, "ransomware-proof" security of Google Enterprise devices with seamless, browser-based access to essential Windows applications via an optional Virtual App Delivery (VAD) layer.
Investment

$180 per unit / month
with annual commitment
5 users min. on first order
No asset hardening for ChromeOS devices.
PCs or Macs in a Google estate need the Outlier mandate.
Any applicable, One-time, per-org Google Workspace, ChromeOS, or virtualization foundations are ordered separately.



Check our Service Blueprints and our detailed Mandates feature list for more information.

Note: If your firm runs Google Workspace on Windows PCs or Macs, a Managed Outlier mandate is required for hardening, device management and endpoint threat protection.

Note: Windows Virtual App Delivery available as an add-on. Virtual Desktop is included natively in the Full Concierge Federated Enterprise mandate.
Commitment
USD  Monthly | Yearly | 2-Year
EUR  Monthly | Yearly | 2-Year
Concierge Cloud Workspace
Microsoft 365 via Virtual Desktop
Description
The Digital Clean Room. Secure virtual workspaces for contractors and BYOD users. A controlled, on-your-soil digital environment delivered through Windows 365, Azure Virtual Desktop, or your VDI infrastructure that enables external talent to work within your firm's ecosystem and security standards, on a full desktop they do not have to own.

For a deeper look at the architecture behind virtual desktops and how isolation boundaries enforce compliance, see Why Virtualization?
Investment

$190 per unit / month
with annual commitment
5 users min. on first order
Any applicable one-time, per-org ecosystem and virtualization foundations are ordered separately.



Check our Service Blueprints for more information.

Note: Stewardship does not include physical hardware coverage or the 1.20 Readiness Standard for personal computer management.

Commitment
USD  Monthly | Yearly | 2-Year
EUR  Monthly | Yearly | 2-Year
Full Concierge Federated Enterprise
Multi-Cloud + Virtual Desktop
Description
This is the apex of stewardship, unifying multi-cloud governance with full-stack virtualized resilience. Built for high-compliance sectors like FinTech and Defense, it combines federated identity across all SaaS platforms with the isolation of a Digital Clean Room. This integrated mesh enables zero-day productivity on any platform or device while allowing you to maintain a Zero-Trust posture that meets SOC 2 standards.
Investment

$325 per unit / month
with annual commitment
5 users min. on first order
$250 one-time asset hardening / PC
No asset hardening for ChromeOS devices
Macs in a M365 estate, and PCs or Macs in a Google estate need the Outlier mandate.
Any applicable one-time, per-org ecosystem, hardware, or virtualization foundations are ordered separately.



Check our Service Blueprints and our detailed Mandates feature list for more information.

Commitment
USD  Monthly | Yearly | 2-Year
EUR  Monthly | Yearly | 2-Year
Concierge Frontline
Microsoft 365
Description
Frontline Mobility Governance. Many field-based roles operate entirely on mobile phones, tablets, and web apps. This mandate equips your mobile team for secure, efficient work without the licensing or management overhead of a primary desk workstation. It protects the communication silos where institutional intelligence resides and applies identity-driven governance to maintain firm-wide standards.
Investment

$60 per unit / month
with annual commitment
5 users min. on first order
Any applicable one-time, per-org ecosystem or virtualization foundations are ordered separately.



Check our Service Blueprints for more information.

Note: This mandate is restricted to mobile and web-only use. Stewardship does not include physical hardware coverage or the 1.20 Readiness Standard for personal computer management.

Note: Desktop as a Service and Virtual App Delivery available as add-ons on any monitor size (see add-ons section below)

Commitment
USD  Monthly | Yearly | 2-Year
EUR  Monthly | Yearly | 2-Year
Concierge Cloud Workroom
Virtual Windows App Delivery
Description
The Surgical Clean Room. Secure virtual application delivery for contractors and BYOD users. A tightly scoped, on-your-soil digital environment delivered natively through the Chrome browser that enables external talent to access critical Line-of-Business apps within your firm's high-governance ecosystem on any device, company-owned or not, without the complexity of a full virtual desktop.

To understand how app streaming achieves Zero-Trust isolation on unmanaged devices, see Why Virtualization?
Investment

$115 per unit / month
with annual commitment
10 users min. on first order
$4500 one-time VAD foundation per org.



Check our Service Blueprints for more information.

Note: Includes one primary application. Additional apps: $100/unit/org./m with yearly commitment.
Commitment
USD  Monthly | Yearly | 2-Year
EUR  Monthly | Yearly | 2-Year

Persona Mandate Add-ons

Virtual Desktop Add-on (DaaS) High-Governance, Performance, and Continuity
Description
Each virtual desktop is a governed, isolated environment with controlled data egress, centralized logging, and a consistent security baseline across every session regardless of the device or location from which the user connects. For organizations with compliance obligations, it enables the auditability and access controls that a physical workstation estate alone cannot guarantee uniformly. For users with demanding workloads, the compute tier scales independently of local hardware, accommodating resource-intensive applications without capital expenditure at the desk.

Beyond the stewardship of a regular managed endpoint, this mandate covers the platform-side discipline specific to virtual desktops: image configuration and lifecycle, policy correctness, controlled patching, profile reliability at scale, and response to platform-wide issues that may affect many users at once.

For a deeper look at the architecture behind virtual desktops and how isolation boundaries enforce compliance, see Why Virtualization?
Investment


Note: A Virtual Desktop functions as a distinct, enterprise-grade endpoint within your environment. To maintain platform integrity, each instance requires the same security and management posture as a physical workstation. This fee is commensurate with the essential licensing and tooling required to secure and manage this secondary environment.

Note: This mandate is delivered using Azure Virtual Desktop (AVD), Windows 365, or a private VDI environment to meet your firm's governance, security, and data residency requirements. See Virtualization Costs in Context for a comparative breakdown of the underlying infrastructure economics.

Commitment
Virtual App Delivery Add-on Windows App Streaming on Any Device
Description
For environments requiring secure access to business-critical Windows applications on any device, Virtual App Delivery (VAD) streams a Digital Clean Room natively to the browser or a local client. This allows for high-performance streaming of individual apps while maintaining absolute data sovereignty and global access from any hardware without the operational overhead of a full virtual desktop. Our VAD implementation integrates directly with your host operating system and cloud storage to ensure these applications feel local and respond intuitively to your existing workflow.

To understand how app streaming achieves data sovereignty and Zero-Trust isolation on unmanaged devices, see Why Virtualization?
Investment


Note: Includes one primary application. Additional apps: $100/unit/org./m with yearly commitment.
Commitment
The Managed Outlier Cross-Platform Endpoint Stewardship
Description
This mandate governs non-native hardware exceptions with the exact rigor of your primary architecture. Joining a Mac to a Microsoft environment, or a PC to a Google one, requires complex initial engineering; securing it thereafter demands a distinct management plane and specialized tooling. That is a parallel security burden, and this mandate absorbs it entirely. Following the initial architectural bridge, which delivers Platform SSO and cryptographic escrow, every device is continuously hardened. We enforce automated patching, strict compliance monitoring, and active MDR/SOC telemetry on the same uncompromising schedule as your core fleet. Billed as a single mandate per machine, whether actively assigned or held in reserve. No hardware exception can dilute your security posture.
Investment


Note: This mandate, along with its hardening fee, is entirely waived for auxiliary machines covered under your 20% Spare Device Allowance (up to 20% of your active fleet, capped at ten). Covered spares are provisioned and stewarded to the exact same standard at no cost.

Commitment
Unit Provisioning and Hardening Security Enrollment and Configuration for Windows PCs
Description
Hardening is required for all Windows personal computers, including primary workstations, hot spares, secondary computers, and silent infrastructure like lobby or conference room terminals. This mandate establishes Shields Up stewardship through a protocol of hardware verification, security enrollment, and application configuration. This thorough preparation ensures that every asset is delivered fully patched, tested, and documented for a frictionless handoff the moment it is activated. This mandate also applies to hardware acquisitions that fall outside the initial order of a Full Concierge mandate or outside of our One-In, One-Out maintenance absorption policy for the replacement of vetted assets by vetted assets. Common examples include a transition from a virtual environment to physical hardware or the replacement of a legacy device that was never vetted.
Investment


Note: This hardening fee is waived for auxiliary machines covered under your 20% Spare Device Allowance (up to 20% of your active fleet, capped at ten). Covered spares are provisioned and stewarded to the exact same standard at no cost.

Commitment

One-time Per-org Tenant Hardening Fees

Microsoft 365 Foundation Required for All Personas except Google Single-Cloud
Description
Microsoft 365 Tenant Architecture and Security Hardening establishes the governance and security foundation required before a single persona can be managed with integrity. This one-time engineering engagement hardens the Entra ID identity layer, designs the Conditional Access architecture, deploys the Intune device compliance framework, activates your threat detection posture, and locks down your collaboration perimeter across Exchange, Teams, and SharePoint. The baseline that remains is documented, audit-ready, and aligned to the CIS Microsoft 365 Foundations Benchmark.
Investment
Commitment
macOS Foundation Required for macOS Fleets
Description
Apple Fleet MDM Architecture and Identity Integration establishes a native standard of governance that works directly with the platform. This one-time engineering engagement builds the device management and identity foundation for your Mac fleet. We bind your organization to Apple Business Manager, design your MDM policy framework for zero-touch enrollment, and integrate Platform SSO with your primary identity provider. Encryption, privacy, and application control policies are enforced to enterprise security standards. The fleet then provisions itself, stays aligned, and behaves like a first-class citizen on your network.
Investment
Commitment
Google Workspace Foundation Required for Mandates That Include Google Workspace
Description
Google Workspace Tenant Architecture and Security Hardening closes the gap between convenience-focused factory defaults and a properly governed enterprise environment. This one-time engineering engagement secures your email domains against spoofing and structures your administrative console so that security policies and access levels apply accurately to specific user roles. It enforces context-aware authentication that binds every session to explicit identity and device posture. We lock down data boundaries across email and cloud storage, regulate third-party application permissions, and establish court-ready retention protocols in Google Vault. The result is a documented tenant aligned with the CIS Google Workspace Benchmark.
Investment
Commitment
ChromeOS Foundation Required for Enterprise ChromeOS Fleets
Description
The Zero-Surface Baseline. The build starts with the Admin Console architecture for your ChromeOS fleet. It is structured around a deliberate Organizational Unit hierarchy, so policies apply precisely to the right devices and users. Your Chrome Enterprise baseline is deployed and hardened. Chrome Enterprise Premium security controls are optionally activated, covering data loss prevention, context-aware access, and real-time threat intelligence. Device authentication is federated with your primary identity provider, ensuring every Chrome session is governed by your firm's identity and access policy. Where Windows application delivery through the browser is required, the integration groundwork is laid as part of this engagement. The result is a fleet that requires almost no endpoint intervention while maintaining an uncompromising security posture.
Investment
Commitment
Microsoft Virtual Desktop Foundation Required for Federated Enterprise Mandate, Workspace, and DaaS Add-on
AVD or Windows 365
Description
The architecture underneath a Digital Clean Room decides what it can promise. We design and deploy your Azure Virtual Desktop environment from the ground up. It establishes your Azure resource architecture and configures optimized host pools. The process also builds a documented golden image maintenance pipeline and deploys FSLogix profile containers for persistent, portable user identities. It thoroughly engineers your network topology for strict performance and security. Conditional Access policies are systematically wired through every session. Finally, autoscaling, monitoring, alerting, and full disaster recovery procedures are validated before handoff. The ongoing stewardship of this environment, covering golden image lifecycle, policy correctness, patching, profile reliability, and platform-wide incident response, is functionally distinct from end-user support and is covered by the monthly Virtual Desktop add-on cost.
Investment


Note: This mandate is delivered using either Azure Virtual Desktop (AVD) or Windows 365. See Virtualization Costs in Context for a comparative breakdown of the underlying infrastructure economics.

Commitment
Self-hosted Virtual Desktop (VDI) Foundation Required for Federated Enterprise Mandate and DaaS Add-on
Proxmox or Nutanix
Description
This mandate establishes the orchestration layer that runs a platform of dedicated Windows 11 virtual machines on an existing hyperconverged cluster and sustains its performance at scale. It covers the connection broker, through which each user authenticates via Entra ID (SSO and MFA) and is routed to their own machine. On-demand power management starts and stops each virtual machine as users connect and disconnect. At its core is the building of a full golden image from which individual desktops are provisioned. Around this sits the ongoing stewardship that keeps the estate healthy: golden image lifecycle, platform policy correctness, controlled patching, profile reliability at scale, and response to platform-wide issues that may affect many users at once. This ongoing stewardship is functionally distinct from end-user support and is covered by the monthly Virtual Desktop add-on cost.
Investment


Note: This mandate is delivered using either Proxmox or Nutanix. See Virtualization Costs in Context for a comparative breakdown of the underlying infrastructure economics.

Commitment
Virtual App Delivery Foundation Required for Workroom and VAD Add-on
App Session-level Orchestration
Description
We deploy a session-level delivery layer that streams critical legacy or server-resident systems directly through any web browser, so the hardware in front of the user stops mattering. By containerizing individual applications, this architecture guarantees complete session isolation and local user experience parity while preventing corporate files from ever being stored on unmanaged local drives. Your people work in a flexible, highly compliant environment that preserves firm-wide data sovereignty and authenticates every interaction against your primary governance baseline.
Investment
Commitment
Zoho Workplace Foundation Required for Enterprise Mandates with Zoho
Description
Zoho Workplace Tenant Setup and Security Hardening supplies the governance a freshly provisioned nine-app suite does not ship with. We configure your email domains against spoofing in Zoho Mail's Admin Console and structure Zoho Directory so that security policies and access levels reflect actual organizational roles. Conditional access then evaluates every login against identity, device, location, and time-of-day signals. WorkDrive data boundaries are locked down with automated DLP classification. Third-party OAuth permissions are governed from the Zoho One admin panel, and court-ready retention policies and legal holds are stood up in the built-in eDiscovery portal. Every layer of the Workplace stack ends up hardened, and documented.
Investment
Commitment

Infrastructure Asset Mandates (Managed Assets)

The Managed Asset Add-on Device Stewardship beyond Your 20% Buffer
Description
"Shields Up" Stewardship for the "silent infrastructure" that anchors your office: hot spares, secondary workstations, lobby terminals, conference room hardware, and home office. This mandate ensures every unmanned device remains patched, hardened, monitored, documented, and ready for work the moment it is activated.
Investment

$80 per unit / month
with annual commitment
$250 asset hardening / PC
Check our Service Blueprints for more information.



Note: Managed assets carry the identical remote telemetry, patching, and MDR/SOC licensing burden as a primary endpoint. Because secondary and shared devices often introduce unique vulnerabilities, they demand equal, continuous oversight and hardening.

Note: This mandate, along with its hardening fee, is entirely waived for auxiliary machines covered under your 20% Spare Device Allowance (up to 20% of your active fleet, capped at ten). Covered spares are provisioned and stewarded to the exact same standard at no cost.

Commitment
USD  Monthly | Yearly | 2-Year
EUR  Monthly | Yearly | 2-Year
The Managed Server Server Stewardship for On-Site or Cloud-Hosted Systems
Description
Comprehensive oversight for your firm's server infrastructure. This mandate provides expert setup, provisioning, and administration for physical and virtual servers, on-site or in the cloud. Every environment, including Windows, Linux, Docker, and LAMP stacks, is built to published CIS security benchmarks. Systems are monitored around the clock and re-verified on a schedule so their hardening cannot quietly erode. As CIS releases new benchmark updates, we evaluate and apply the latest recommendations to keep your defenses current. This stewardship extends upward to installed applications, ensuring continuous hardening, updates, and maintenance for line-of-business software, databases, web platforms, and your Zero-Trust or backup infrastructure. Backups are encrypted, held off-site, and proven by actual restores rather than assumed. Infrastructure remains hardened, documented, and under your total sovereignty.
Investment

$200 per server / month
with annual commitment
$1200 one-time build / hardening
Check our Service Blueprints for more information.



Note: Software licensing and third-party hosting fees not included. They are delivered as pure MSRP pass-throughs.

Commitment
USD  Monthly | Yearly | 2-Year
EUR  Monthly | Yearly | 2-Year
Cloud Workload Protection Optional Add-on to The Managed Server Mandate
Description
Active compliance and hardening for Linux and Windows server workloads exposed to the public internet when needed. This mandate installs and tunes the specialized tools and OSSEC rules required to satisfy stringent data security and privacy standards. Stewardship ensures infrastructure remains audit-ready through continuous monitoring and defensive hardening. Supported frameworks include NIST 800-171, JSIG, PCI DSS, GLBA, GDPR, HIPAA, and others.
Investment


Note: This protection is available for new servers and as a standalone service for self-managed or Legacy Sustainment assets.

Note: This add-on mandate covers the management and tuning of your security architecture. Because application and compliance requirements demand a highly tailored solution, the underlying software licenses and infrastructure for the protection itself are procured separately.

Commitment
The Managed Network Stewardship for Sites beyond Your Primary Office
Description

Office Connectivity Stewardship. Comprehensive oversight for your office connectivity infrastructure. This mandate covers the setup and administration of the stateful gateway, firewalls, and switching fabric. Stewardship applies to services such as Multi-WAN routing, VLAN segmentation, VPN access, and IDS/IPS for one physical /24 subnet. Expert management of the gateway ensures the network remains secure, optimized, and under your total sovereignty.

When a network is still required. Zero-Trust removes the perimeter for people and their applications. It does not remove it for everything else. Printers, cameras, phones, door controllers, payment terminals, and medical, lab or building equipment cannot run an agent or be patched on demand, so the network is the only place they can be contained. Legacy applications tied to a local server, and requirements such as PCI segmentation or data residency, call for it outright. And the building itself still needs Wi-Fi, cabling, and the switch that powers the locks and the cameras.

Investment

$350 per unit / month
with annual commitment
$2500 one-time build / hardening
Check our Service Blueprints for more information.



Note: The build/hardening fee is waived for preexisting, remotely manageable networks running Ubiquiti UniFi or Netgate infrastructure, provided the hardware has not reached End-of-Life (EOL) and administrative control is fully transferable.

Commitment
USD  Monthly | Yearly | 2-Year
EUR  Monthly | Yearly | 2-Year
The Sovereign Network Enclave Zero-Trust Access and Sovereign Network Fabric
Zero-Trust
Description
Today's workforce and applications operate beyond physical perimeters. Zero-Trust Network Access eliminates implicit trust entirely: every connection requires continuous, identity-first verification. We enforce this mandate across two planes:

The North-South Perimeter (People-to-Systems): We project your applications securely onto the internet through a centralized, high-speed identity gateway that replaces vulnerable traditional access methods. This sovereign perimeter enforces identity-first validation for personnel, it retrofits modern Single Sign-On (SSO) and MFA protection onto legacy or non-compliant applications, and it grants clientless, scoped access for third-party vendors.

The East-West Overlay Mesh (System-to-System): Across your servers, cloud environments, databases, and endpoints, we weave an encrypted virtual backplane. Traffic routing and micro-segmentation run on infrastructure you own and control, keeping the data plane sovereign. This software-defined mesh darkens communication paths between disparate locations, eliminating the risk of lateral threat movement.
Investment
Commitment
The Hyperconverged Cluster (HCI) Scalable Private Cloud for Your Core Applications and Remote Workspaces (VDI)
Datacenter
Description
We architect and oversee a resilient, software-defined platform for workloads where the public cloud is not cost-effective, not suitable, or not yet viable. This mandate builds robust on-premises data center infrastructure on a redundant three-server cluster that unifies compute, storage, and networking into a single scalable high-availability system.

This platform is purpose-built to host stateful line-of-business applications and persistent virtual desktops with predictable performance. This sovereign architecture replaces volatile, consumption-based cloud billing with a durable, fixed-cost asset. It reduces long-term spend and gives you a resilient foundation for projecting these workloads across the local network and the global edge.

For comprehensive data protection, we strongly advise provisioning a fourth, storage-optimized server to act as a dedicated local backup repository. Because backup workloads require disk capacity rather than high compute power, this node can be provisioned with reduced specifications, providing an isolated, cost-effective rapid recovery target for your virtual desktops, servers, and container snapshots.
Investment


Note: This mandate is delivered using either Proxmox or Nutanix. See Virtualization Costs in Context for a comparative breakdown of the underlying infrastructure economics.

Note: For VDI environments, a Virtual Desktop Foundation is required to establish the orchestration layer that runs dedicated Windows virtual machines and sustains their performance at scale.

Note: Management of the backup node incurs no additional labor fees; it is covered under this Cluster Stewardship mandate.

Commitment
The Concierge Cloud Vault Provisioned within Any of Our Full Concierge Mandates
Credential Governance
Description
Collaborative enterprise vault. Self-hosted and single-tenant, this multi-user system handles shared credential management for your entire team. It extends beyond standard web passwords to act as an encrypted repository for API keys, database connection strings, software license keys, PINs, and secure notes. The zero-knowledge OpenPGP architecture ensures passwords remain private even from your Steward, while allowing for instant user revocation. GDPR compliant, tracker-free, and accessible via any device or browser.

Organizations with advanced regulatory needs should consider the Compliance Edition, which adds a hardened Business-core layer and full activity logging to satisfy SOC 2 and industry-specific audits.
Investment


Note: This standard edition of the Concierge Cloud Vault is provisioned and managed within our Full Concierge mandates.

Commitment

Legacy Asset Mandates (Business Continuity)

Active Directory Domain Controller(s) and Member(s)
Description
Stewardship of your legacy AD/DS or hybrid AD Domain Controller(s). On-premises or cloud-hosted. Administration and cyber-protection while we move your environment to M365 or as a permanent solution when M365 is not suitable. FOSS option available.
Investment


Note: Per Microsoft Specification, 3 Domain Controllers are required for high Availability.

Note: Build waived for preexisting server. Microsoft Licenses not included.

Commitment
Legacy File Server
Description
Stewardship of your legacy workgroup on-premises File Server. Administration and cyber-protection while we move your files to SharePoint or Google Drive or as a permanent solution when cloud storage is not suitable. Microsoft Licenses not included. FOSS option available.
Investment


Note: Per Microsoft Specification, 2-node Failover cluster is required for high Availability.

Note: Build waived for preexisting server. Microsoft Licenses not included.

Commitment

Strategic Project Mandates (Prepaid Blocks)

The Genesis Mandate Discovery Audit and Sovereignty Initialization
Description

For prospective clients seeking complete visibility into their digital estate, we offer a comprehensive diagnostic engagement at a discounted package rate. This includes a thorough infrastructure inventory and our Sovereignty Snapshot security assessment (below), as well as the identification of strategic opportunities and pre-existing technical debt.

Following the audit, we provide a detailed report and a Hardening Roadmap estimating the hours required for our Principal and Technical Fellows to resolve any technical debt. When you transition to an ongoing stewardship mandate, we will proactively manage and evolve your environment based on the scope of that mandate. However, resolving pre-existing technical debt remains a separate mission, billed outside the mandate at our standard principal consulting rate.

If significant technical debt is discovered, whether during an initial audit or an active mandate, we reserve the right to limit or suspend certain performance and security guarantees until a foundational Baseline of Sovereignty is properly established.

Investment

Standard: $12,500 up to 50 users, one tenant, up to 15 applications
Extended: $25,000 up to 150 users, multi-tenant, up to 40 applications



Note: To maximize your investment, clients who initiate an ongoing Stewardship Mandate concurrently with their audit immediately unlock our 15% Preferred Partner Discount (Code: INNET). This preferred rate applies directly to the Discovery Audit itself, as well as any subsequent engineering labor required to resolve legacy technical debt. By running both engagements in parallel, we secure your daily operations immediately while systematically hardening your underlying architecture.

Commitment
Cloud Migrations Provisioned within Full Concierge Mandates
Description
Moving your firm's digital foundation, whether shifting to the cloud, transitioning between platforms, or repatriating data to your private HCI cluster, is a high-stakes engineering event that requires patience and precision. We manage the entire technical lifecycle, from mapping complex identity permissions and executing DNS cutovers to navigating vendor throttling and platform constraints, all while ensuring bit-perfect data integrity. While we handle the underlying complexity, our focus remains on your Business Continuity. We keep the firm working through the cutover, and the hours normally lost stay billable. Whether you are seeking better cost predictability or a hardened security posture, we ensure your migration is a strategic upgrade you can measure on your bottom line.
Investment


Note: Initial user migrations are included in our Full Concierge mandates with one and two-year commitments.

Note: for the virtualization of legacy servers or specialized applications, please call to discuss your specific architecture.

Commitment
IT Consulting: Principal Steward
Description
Offered in discrete hourly blocks, this engagement is fractional CIO leadership for specialized projects, technical due diligence, or complex troubleshooting. The Principal Steward functions as both a fiduciary advisor and a lead engineer, translating high-level business goals into a technical reality. This is a standalone service for high-stakes objectives requiring deep technical skill and architectural oversight. We ensure your technology is secure and performant on a per-project basis, with no long-term stewardship mandate required.
Investment


Note: Strategic Mandates of 40 hours or more qualify for a 10% Governance Credit, providing a pre-paid value bonus and priority scheduling for large-scale advisory and engineering projects.

Note: Use Code INNET for 15% off project labor, reflecting the management overhead already satisfied by your Full Concierge monthly mandate.

Commitment
IT Consulting: Technical Fellow (Senior Engineer)
Description
Offered in discrete hourly blocks. The Technical Fellow brings specialized engineering depth to advanced infrastructure builds, including server hardening, complex networking, and virtualization. This role executes high-level technical specifications to transform strategy into a functional reality. The Technical Fellow is the expert craftsman of our Guild.
Investment


Note: Strategic Mandates of 40 hours or more qualify for a 10% Governance Credit.

Note: Use Code INNET for 15% off, reflecting that we already own the documentation and access through your monthly mandate.

Commitment
IT Consulting: Remediation / B-F
Description
Offered in discrete hourly blocks on a best-effort basis. Your mandates are priced on a standardized estate: the toolchain we selected, hardware that meets our standards, and recommendations that were acted on. This rate covers what falls outside it. That includes the hands-on repair of systems suffering from neglect or a disregard for established security standards, time spent working in tools that duplicate our own, and work on consumer-grade, personal, third-party-owned or out-of-warranty equipment. The same may apply to unvetted hardware acquired during the engagement. It also covers damage arising from administrative elevation, break-glass access or a late offboarding notice, and cleanup after a declined recommendation. Because this work sits outside the standards our mandates are priced on, and is often unscheduled, it carries a premium rate and lacks the priority status or service guarantees provided under those mandates.
Investment


Note: Remediation services are strictly excluded from all discounts and volume credits.

Commitment
The Sovereignty Snapshot Security Assessment
Description
Before committing to a long-term mandate, many partners begin with this high-impact diagnostic of their current risk posture. We utilize a non-invasive, read-only handshake to perform a no-credential-storage scan of your Microsoft 365 environment. We identify immediate gaps in MFA coverage, privileged account risks, and Entra ID configuration issues. This deep-dive includes a Shadow IT Discovery and a Domain Spoofing check to ensure your brand isn't being weaponized by external actors. We also enumerate every application, vendor and automation holding standing access to your tenant, including the MSP tooling that could let an AI model ingest proprietary data. We then supplement this cloud data with a "Principal's Walk-Through" of your physical infrastructure to identify the legacy hardware "ghosts" and connectivity bottlenecks that a remote scan cannot see. The result is a clear Sovereignty Scorecard: a strategic roadmap that separates your stable assets from those requiring urgent remediation.
Investment

$3000 per unit



Note: If you transition to a Persona Mandate within 30 days of your Snapshot, 50% of the fee is credited toward your first three months of service.

Commitment
USD  Deploy
EUR  Deploy
Compliance Governance (WISP and HIPAA)
Description
Regulatory compliance is not a "set and forget" project; it is the practice of maintaining a defensible position. We specialize in the development and governance of mandated Written Information Security Plans (WISP) and specialized HIPAA/Regulatory procedural documentation. Rather than providing generic templates, we translate abstract federal requirements into a practical "Operating Manual" for your firm. This engagement satisfies the documentary standards required for Cyber Insurance renewals, HIPAA Security Rule audits, and FTC Safeguards compliance. By aligning your technical controls with formal policy, we ensure that your "Baseline of Sovereignty" is not just implemented, but legally documented and audit-ready.
Investment


Note: Strategic Mandates of 40 hours or more qualify for a 10% Governance Credit.

Note: Use Code INNET for 15% off, reflecting that we already own the documentation and access through your monthly mandate.

Commitment
Structured Cabling Systems
Description
Design and installation of IEEE 802.3 structured cabling systems in Cat6 and high-performance Cat6A standards. This service includes professional termination, comprehensive performance testing, and updated as-built network drawings to ensure a fully documented physical layer. Baseline rates apply to standard commercial environments with accessible drop-ceilings. Adjustments are required for hard-lid ceilings, cable runs exceeding 100 feet, plenum-rated requirements, after-hours labor, and the architectural complexities of historical or industrial facilities.
Investment


Note: Use Code INNET for 15% off project labor, reflecting the management overhead already satisfied by your monthly mandate.
Commitment

The Stewardship Toolkit

TimeSqueeze Universal Activity Tracking Endpoint
Description
TimeSqueeze is the "Activity Intelligence Layer" Windows never had. It runs at system level and captures a second-by-second record of digital work. It automatically organizes apps, files, websites, and sessions into a defensible timeline so nobody reconstructs a week from memory at month end. That matters more as AI compresses the visible effort behind a deliverable. Built for professional service firms, TimeSqueeze powers our internal Settlement Ledger. Peer-to-peer support inside the mesh is logged and settled without anyone filing paperwork. Whether used for precise billing, workflow forensics, or operational analytics, TimeSqueeze keeps a complete, local-first history of work that integrates with your existing enterprise systems.
Investment


Note: This mandate includes the software license, deployment, API integration, and continuous system/user stewardship. For self-managed environments, standalone licenses are available via the Microsoft Store or directly through timesqueeze.net.

Commitment
GWSL Graphical Linux Bridge Automated X-Server and Linux Integration
Description
GWSL is an automation layer designed to run graphical Linux applications directly on Windows 10 and 11. Engineered to support local WSL (1 and 2) environments and remote Linux servers or workstations via SSH, it replaces per-application X-server setup with a single launch action. GWSL puts Linux applications in the Windows Start menu and on the taskbar where they open in ordinary windows and behave like any other program. Developers run Linux IDEs and specialized toolsets at native stability. GWSL has become the standard graphical layer between Windows endpoints and Linux infrastructure.
Investment


Note: This mandate includes the software license, deployment, and continuous system/user stewardship. For self-managed environments, standalone licenses are available via the Microsoft Store.

Commitment
OpenInWSL Integration Utility Native Linux File-Handler for Windows
Description
OpenInWSL registers Linux applications as Windows file handlers. Open a file or folder in Windows File Explorer and it arrives directly in a Linux IDE or utility. No path translation, no shell session in between. It operates alongside GWSL, which supplies the graphical layer, and it removes the context switch that otherwise accompanies every file crossing between the two environments.
Investment


Note: This mandate includes the software license, deployment, and continuous system/user stewardship. For self-managed environments, standalone licenses are available via the Microsoft Store.

Commitment

Auxiliary mandates and stewardship extensions.

The Concierge AI agent Server and User-Side Agentic AI Stewardship
Description
Sovereign Agentic Infrastructure. We build a dual-node AI architecture that automates challenging or repetitive intellectual work without exposing your data. A high-compute local node runs advanced open-weight reasoning models on private silicon while a cloud coordination server handles connections to your external tools and services. You direct the agent in plain language through a messaging app; it executes multi-step digital workflows in the background and reports back only when a job is done or a decision is needed. All execution is strictly confined within an isolated runtime sandbox powered by NVIDIA to block unauthorized network egress and eliminate data exfiltration risks. Routine operations run free on your local hardware while novel or complex problems autonomously escalate to a frontier model like Anthropic's Opus. Once the problem is solved, the agent saves the procedure as a reusable, plain-text "skill." Your firm stops renting temporary intelligence, slashes overhead, and builds compounding proprietary equity that works 24/7.

User-Side Stewardship. We govern the human and operational boundaries of your automated workforce to keep it controlled and secure. Strict profile isolation lets multiple executives or departments use the system simultaneously without cross-contaminating their workflows or memories. We maintain a centralized, human-readable "Shared Playbook," a secure repository where the agent's generated procedures are reviewed and curated before they become standard practice. And we enforce strict approval protocols: the agent must request explicit human sign-off, via chat or mobile push, before executing any high-risk action. We operationalize the intelligence, ensuring it remains a strictly governed, highly efficient extension of your organization.
Investment


Note: Agentic AI remains experimental. While the sandbox secures the host, opening API tunnels to external tools introduces risk. An AI hallucination could execute unintended commands on connected systems, making human-in-the-loop oversight critical.

Commitment
The Concierge Cloud Atelier AI-Shielded Zero-Trust Zero-Knowledge Productivity Suite
Description
Sovereign Collaborative Suite. A dedicated, single-tenant Cryptpad server instance for your most sensitive R&D and management workflows. The atelier hosts Google-level real-time collaboration, including Docs, Sheets, Kanban, and Whiteboards using browser-side OpenPGP encryption to secure data before it ever reaches the server. As your Steward, we manage the infrastructure while your data remains mathematically invisible to us and immune to big-tech AI training scans. This GDPR-compliant "secure enclave" gives you managed Shared Drives and external sharing without the privacy risks or vendor lock-in of the public cloud.

A secure enclave is only as strong as its access protocols. Our user-side stewardship enforces that boundary. We integrate your team into zero-knowledge workflows, architect precise permissions, and anchor your intellectual property within organizationally controlled Team Drives. Should team composition change, we execute immediate server-side access revocation. The departing user is cryptographically locked out of the workspace while your firm's data remains accessible and the zero-knowledge perimeter unbroken.
Investment
Commitment
The Concierge Cloud Vault: Compliance Edition Add-on to Our Full Concierge Mandates
Description
Audit-Grade Credential Stewardship. For firms requiring SOC 2 or high-compliance governance, our Compliance Edition adds granular activity logging and enforced security policies. Unlike standard password managers, this mandate builds the "Chain of Custody" auditors require, including automated user provisioning, hardened MFA enforcement, and a managed physical escrow for organizational recovery. As your Steward, we maintain the audit trail and the infrastructure, ensuring your credentials are not just secure, but compliant. We deploy each vault as a private, single-tenant residency, architecturally isolating your credentials from the systemic vulnerabilities inherent in commercial mass-market password managers.
Investment


Note: The standard edition of the Concierge Cloud Vault is provisioned and managed within our Full Concierge mandates.

Commitment
The Immutable Forensic Archive Tenant Audit Log Retention and Legal Hold
Description
Sovereign Audit Retention. If opposing counsel issues a subpoena, an insurer demands post-breach forensics, or a departing employee steals proprietary data, you will need access logs from months prior. Most firms cannot produce them. Microsoft 365 and Google Workspace clear most tenant audit logs at 180 days, so the record is routinely gone before the investigation arrives.

We engineer an automated pipeline that exports every tenant audit log into a write-once archive. Depending on your regulatory profile, we deploy this inside your existing cloud for certified compliance, or to independent flat-rate storage to eliminate hyperscaler retrieval penalties. The archive operates under a locked retention policy that no administrator can shorten or delete. Each export is cryptographically stamped on arrival, making any tampering instantly provable. As your Steward, we monitor the pipeline for gaps, maintain chain of custody documentation, and produce the extract when counsel, an insurer, or an auditor asks for it.

Your forensic history remains entirely under your ownership and freely accessible to local AI sandboxes. MSPs trap your logs inside their own vendor subscriptions, forcing you to rent access to your own evidence and risk losing it entirely if you leave them. We build the vault in your name, ensuring you never lose your history.
Investment


A Note on Telemetry Depth: While this Archive guarantees the survival of your evidence, the depth of that evidence depends on your Microsoft or Google license. Standard tiers track logins, file creations, and downloads. If your risk profile requires granular incident response data, such as proving whether an intruder actually opened a specific email, an add-on will be required on top of your users' monthly cloud licensing fees.

Note: Dedicated flat-rate storage and extraction are fully bundled in our fee. If your regulatory profile (e.g., HIPAA/BAA, SOC 2, FINRA) requires the immutable archive to reside inside your own Azure, Google or AWS boundary, the vault is engineered directly in your cloud, and underlying raw storage (typically pennies per month) is billed directly to your cloud provider.

Commitment

Architectural governance, continued

Where organizational scale and go-to-market strategy demand it, you may also embrace a company-wide Dual-Ecosystem to unlock best-of-breed capabilities, support highly specialized workflows, and effectively integrate with external clients' and partners' ecosystems.

Ordering, governance & fee policy

Marginal Scaling: We apply Scaled Stewardship Credits to every progressive tier of your estate: 5% (units 10 to 25), 10% (units 26 to 100), and 15% (units 101 to 400). This ensures your average cost per unit decreases as your operational maturity increases, reflecting the architectural efficiencies gained as you scale.

The 1.20 Readiness Standard: Our 1.20 Readiness Standard maintains both a 20% hardware buffer and an emergency virtual desktop to ensure a 15-minute return to billability. To support this physical redundancy, we steward auxiliary computers up to 20% of your active PC and Mac fleet, up to a maximum of 10 machines, at no cost. These covered units incur no one-time hardening or recurring mandates. Machines beyond this allowance take a Managed Asset or Managed Outlier mandate, while spare Chromebooks require no hardening and remain entirely exempt from the count.

The Genesis Mandate: To give you complete visibility into your infrastructure before beginning a possible long-term residency, we invite you to undergo a comprehensive Discovery Audit. This initial project maps your digital estate to identify vulnerabilities, strategic opportunities, and pre-existing technical debt. While our ongoing mandates focus strictly on the buildup and proactive evolution of your environment, the audit provides a clear diagnostic of your starting point. You can explore this engagement in the Project section above.

Foundations: These one-time, organization-level engineering charges cover the architectural build, configuration, and hardening of your cloud, virtual, and hardware environments. A separate Foundation applies to each ecosystem you introduce (e.g., a multi-cloud estate requires both the Microsoft and Google Foundations, while the presence of Macs necessitates the macOS Foundation).

Licensing: Wherever applicable, our persona mandates include a premium productivity suite, such as Microsoft 365 Business Premium or Google Workspace Business Plus. Where a persona does not need a full suite, that becomes a Frontline license, Teams or equivalent. ChromeOS personas include Chrome Enterprise. For a plan-by-plan breakdown of what each Microsoft license actually contains, see M365 Maps.

Asset Hardening Fees: These setup charges apply per-device to ensure provisioning, persona alignment, and architectural security. When subscribing to our persona mandates, manually select the quantity in the dropdown to match your hardware count. Additional setups for subsequent adjustments or replacements are available in the Add-ons section above.

Maintenance Absorption: Assets vetted by a Principal Steward qualify for our "One-In, One-Out" policy. This ensures that any approved Windows device replaced during a Persona mandate is hardened and integrated at no additional cost for the remainder of that term. Both the replaced and replacement PCs must be vetted.

The Managed Outlier: Any device that falls outside your primary cloud ecosystem (such as a Mac in a Microsoft estate or a PC or Mac in a Google estate) is considered Foreign. Because this hardware requires its own separate management plane, identity bridge, and monitoring system, it cannot be stewarded under standard terms. Therefore, barring your 20% auxiliary allowance, every Foreign machine must take The Managed Outlier add-on mandate.

ACH Stewardship Discount: Partners who remit via ACH bank transfer receive a 1.5% recurring discount applied automatically to their mandate. This reflects the elimination of card network interchange fees, a cost we pass directly back to you rather than absorbing into our pricing. To get the discount, check out using a verified bank account and apply the matching code:

  • ACH for recurring mandates
  • ACH-ONETIME for single charges

If you are currently paying by card and would like to switch, contact your Principal Steward or update your method through the Payment Portal.

Once you have deployed your order, please register and log into this site to manage your onboarding. Your Principal Steward will guide you through your first deployments, onboardings, and offboardings.


Spotlight

Automates knowledge work on your secure infrastructure, ensuring IP protection, departmental privacy, human-in-the-loop control, and know-how that accrues to your firm rather than a vendor. All agent execution is confined to an isolated runtime sandbox that blocks unauthorized network egress.
A "Digital Clean Room" for secure Windows access from any device. This maintains your firm’s sovereignty while offering a reliable failover solution should a physical device become unavailable. Beyond security, DaaS can function as an on-demand high-performance workstation; it allows users to access specialized, resource-heavy applications like CAD at lightning speed. See our Azure Virtual Desktop and Gartner on AVD brochures for technical details.
Secure streaming of critical Windows applications delivered natively through the browser on any hardware without the operational overhead of a full virtual desktop. Our VAD implementation integrates directly with your host operating system and cloud storage to ensure these applications feel local and respond intuitively to your existing workflow. Alternatively, strict Data Loss Prevention (DLP) policies can isolate corporate data by forcing all file saves to managed cloud environments.
A private Collaborative Suite for board papers, R&D and anything you would rather was not scanned to train someone else’s AI. Google‑level real‑time collaboration, including Docs, Sheets, Kanban and Whiteboards, with every document encrypted in your browser before it reaches the server.