Trust
Security
How TKG Edge protects client access, client data and this website, and how to report a vulnerability.
Last updated October 6, 2026
When you give an IT partner access to your systems, you’re trusting them with the keys to your business. Here’s how TKG Edge protects that access, and your data, every day.
How we protect our own operations
- Multi-factor authentication is required on every TKG account and every tool we use to manage client systems.
- Credentials are stored in an encrypted documentation vault, never in email, tickets or spreadsheets. Access is limited to the people who need it.
- Least-privilege access. Technicians get only the permissions their role requires, and access is removed promptly when someone changes roles or leaves.
- Every action is tracked. Work on client systems is tied to a ticket in our service platform, so there is a record of who did what and when.
- Our own endpoints run the same protection we deploy for clients: managed patching, endpoint detection and response, and 24/7 security monitoring.
- Security awareness training and phishing simulations for every TKG team member.
- Background checks for staff with access to client systems.
- Independent penetration testing and a formal compliance program to track our controls, policies and evidence.
How we protect client environments
Every TKG Edge client runs on the same standardized, enterprise-grade stack, which is how we keep protection consistent and support it well:
- Continuous monitoring, patching and remote management
- Endpoint detection and response, backed by a 24/7 security operations center
- Advanced email security, plus security awareness training and phishing simulations
- Multi-factor authentication and conditional access through Microsoft Entra ID
- Immutable backup and recovery, with scheduled restore testing
- Documented, tested disaster recovery plans for Strategic-tier clients
The exact services each client receives are set out in their service agreement.
How we protect this website
- Hosted on WP Engine managed WordPress hosting, with daily backups and platform-level security monitoring.
- Encrypted with HTTPS on every page.
- Forms are protected from spam and abuse with Google reCAPTCHA, and submissions go directly to our CRM.
See our Privacy Policy for how we handle information collected through this site.
If something goes wrong
We maintain an incident response process. If we discover a security incident affecting a client’s data, we notify that client promptly, as required by their agreement and applicable law.
Report a vulnerability
If you believe you’ve found a security vulnerability in this website or a TKG system, please email [email protected] with:
- A description of the issue and where you found it
- Steps to reproduce it
- Your contact information, if you’d like us to follow up
Please don’t access, change or delete data that isn’t yours, disrupt our services, or share the issue publicly before we’ve had a chance to fix it. We’ll acknowledge your report within two business days and won’t pursue action against anyone who reports in good faith and follows these guidelines.