ACCEPTABLE USE POLICY
Managed IT Services
Issued by St. Aubin Technologies, Inc. (SAT)
Version / Effective date 1.0 / September 15, 2026
Applies to Covered Users receiving managed IT services under an SAT MSA and SOW
Posted at: st-aubin.com/aup
Help desk: 305-247-2227
Purpose: This online Policy gives Covered Users basic rules for safe use of company systems supported by SAT. It is incorporated through the agreement between SAT and the Client. The Client is responsible for making this Policy available to Covered Users and requiring compliance. No Covered User signature or separate assent to SAT is required. This Policy does not expand SAT’s Services, warranties, liability, backup obligations, compliance duties, or other responsibilities beyond the applicable Master Services Agreement and Statement of Work. If there is a conflict, the MSA and applicable SOW control.
1. Accounts and Access
-
Use only accounts assigned to you. Do not share passwords, MFA codes, authentication prompts, or recovery information. SAT will not ask for your password.
-
Use the company-approved password manager, unique work passwords, and MFA. Deny and report unexpected MFA prompts.
-
Lock your screen when away. Do not access systems, accounts, or data without authorization.
2. Devices and Security Controls
-
Use company-managed devices for company work unless your company approves another arrangement.
-
Do not remove, disable, bypass, test, or interfere with RMM, EDR, MFA, Conditional Access, DNS filtering, backup, encryption, web filtering, or other controls.
-
Do not connect unapproved equipment or storage to company systems. Keep devices secure, allow required updates, and restart when requested.
-
Personal-device use requires company approval. Company access or data may be removed when access ends or a device is lost, stolen, or compromised, using available platform capabilities.
3. Software and Changes
-
Do not install software, extensions, remote-access tools, or apps without company or SAT approval.
-
Do not use administrator rights or change security, network, identity, backup, or system settings unless authorized.
-
Do not use pirated, unlicensed, unsupported, or end-of-life software.
-
Do not allow anyone to connect remotely to your device unless you initiated the support request through the SAT help desk or your company otherwise verified and approved the connection.
4. Email, Internet, and Communications
-
Use reasonable care with links, attachments, login requests, payment instructions, and urgent messages. Verify payment or banking changes through a trusted method.
-
Report suspicious messages through an approved reporting feature or the SAT help desk.
-
Do not forward company email outside the company or use personal email for company business unless approved.
-
Do not use company systems for illegal activity, unauthorized access, harassment, threats, discrimination, spam, copyright infringement, cryptocurrency mining, peer-to-peer sharing, personal servers, or material prohibited by your company.
5. Company Data and AI Tools
-
Store company data only in company-approved locations. SAT backup applies only to systems and data expressly included in the applicable SOW. Approved storage does not itself guarantee backup or recovery.
-
Do not copy company data to personal email, storage, devices, removable media, or unapproved services.
-
Do not enter company, customer, employee, privileged, confidential, or regulated information into an AI tool, chatbot, website, or app unless your company has approved both the tool and the use.
-
Do not delete or alter information subject to a legal hold, retention requirement, investigation, audit, or preservation instruction.
6. Regulated and Sensitive Data
-
Do not store, send, or process regulated data unless your company has authorized it and confirmed that required SOW terms and additional agreements with SAT are in place.
-
Follow all additional company instructions for confidential, privileged, regulated, or professionally protected information.
7. Monitoring and Privacy
-
Company systems are controlled by your company. To the extent permitted by law and company policy, activity may be logged, monitored, reviewed, preserved, or disclosed for security, support, operations, compliance, legal, or investigative purposes.
-
SAT uses information available through its tools to provide Services, protect the supported environment, and follow authorized Client instructions. SAT does not employ Covered Users or make employment or disciplinary decisions.
8. Report Problems Promptly
-
Report suspected incidents, data loss, unusual system behavior, lost or stolen devices, unexpected MFA prompts, exposed credentials, suspicious clicks, and requests to bypass this Policy promptly, and in any event within 24 hours after discovery.
-
Report to the SAT help desk and your company’s designated contact. A user report is operational notice and does not determine whether a legally reportable breach occurred.
9. Response to Misuse
-
SAT may take commercially reasonable steps within systems it manages to contain an actual or reasonably suspected threat or material violation, including temporarily disabling an account, isolating a device, or blocking access. SAT will notify the Client as soon as reasonably practical.
-
Work caused by misuse, unauthorized changes, unapproved software, disabled controls, or data outside the supported scope may be Out-of-Scope Services under the MSA and SOW.
-
Any employment or disciplinary action is solely the Client’s decision.
10. Policy Administration
-
The Client is responsible for making this Policy available to Covered Users and requiring compliance. Any acknowledgment process is solely between the Client and its Covered Users.
-
SAT may update this Policy as permitted by MSA Section 18.3 and will give the Client reasonable written notice of a material update.
-
No update will retroactively impose additional monetary charges, materially reduce contracted Services during the current Term, or modify a signed SOW except as permitted by the MSA or SOW.
