Security you can audit, not just read about.

SKYTEK operates under a SOC 2 Type II attestation and an ISO/IEC 27001-aligned information security management system. Every control described on this page is tested by independent auditors and applied uniformly to every client we serve.

Assurance registerReviewed annually
SOC 2 Type IIAICPA Trust Services Criteria
Independent CPA examination of control design and operating effectiveness over the audit period
Attestation current
ISO/IEC 27001:2022Information security management system
Risk-based ISMS aligned to the standard, with a Statement of Applicability across Annex A
ISMS aligned
Microsoft Azure Expert MSPMicrosoft partner program
Third-party audit of cloud operations, security and service delivery, renewed annually
Audit current
MISA memberMicrosoft Intelligent Security Association
Membership for organizations building on Microsoft security technology
Active
Reports and audit letters are shared with clients and prospects under NDA.

Two frameworks, two different questions answered.

SOC 2 answers whether the controls actually operated over a period of time. ISO 27001 answers whether there is a management system that keeps them operating. SKYTEK maintains both.

SOC 2TYPE II

SOC 2 Type II attestation

Examined by an independent CPA firm under AICPA standards

A Type II report is not a checklist. The auditor tests that each control was in place and operating effectively across the entire observation period, and reports any exceptions. It is the document your vendor-risk team will ask for first.

What is tested
Control design and operating effectiveness against the Trust Services Criteria
Period
Continuous observation period, examined annually
Report contents
Auditor opinion, system description, control matrix, test results, exceptions and management responses, complementary user-entity controls
Availability
Full report under NDA; bridge letter available between audit periods
ISO27001

ISO/IEC 27001-aligned ISMS

Risk-based management system built to ISO/IEC 27001:2022

ISO 27001 governs how security is managed: leadership accountability, a maintained risk register, documented policies, internal audit, and continual improvement on a defined cycle. SKYTEK's ISMS is structured to the 2022 revision and its Annex A control set.

Scope
Managed IT, cloud and cybersecurity service delivery and the systems that support it
Annex A
Statement of Applicability across all four control themes: organizational, people, physical, technological
Governance
Risk register owned by leadership; treatment plans tracked to closure; annual management review
Documentation
Controlled policy, standard, incident response and business continuity documents under version control
SecurityRequired common criteria. Protection against unauthorized access, use and disclosure.
AvailabilitySystems are available for operation and use as committed.
ConfidentialityInformation designated confidential is protected as committed.
Processing integrityProcessing is complete, valid, accurate, timely and authorized.
PrivacyPersonal information is collected, used and retained per commitments.

Highlighted criteria are the categories most relevant to managed-service delivery. The criteria in scope for SKYTEK's report are stated in the report itself.

The controls the auditors test are the controls your engineers will see.

Assurance only matters if it describes daily operations. These are the controls that sit in front of every SKYTEK engineer before they touch a client system.

Privileged Identity Management

No standing administrative access anywhere. Engineers request access at the start of a shift; a SKYTEK operations lead approves it for that shift only; Microsoft Entra PIM revokes it automatically at shift end. Every activation records the engineer, the ticket, the approver and the time window.

There is no dormant admin account in your environment to compromise, and every privileged session traces to a person and an approval.

SKYTEK Landing Zone

A hardened, audited jump host in SKYTEK's Azure subscription is the only path into client environments. Sessions are logged and monitored centrally. Engineers never connect from their own machines.

One controlled entry point, one complete log of who accessed what and when.

Conditional Access

Entra ID evaluates the device before a sign-in is trusted: SKYTEK-managed, Intune-compliant, antivirus and EDR healthy, disk encrypted, operating system patched, multifactor authentication satisfied. Sign-in is restricted to SKYTEK-managed laptops.

A stolen password alone cannot reach your systems. The device itself has to pass.

Credential protection

Credentials used on client systems are 100 characters, complex and unique per system. They are generated and stored only in IT Glue, an ISO 27001-certified documentation platform, which is reachable only from the Landing Zone. Credentials are never placed in tickets, email or chat.

Engineers retrieve credentials; they never know them. Offboarding cannot leak what was never memorized.

Security awareness

KnowBe4 phishing simulation runs continuously across the company. Our CISO leads quarterly live awareness training. New engineers complete security training before any client access is granted.

The human layer is measured and reported on, not assumed.

Vulnerability and incident management

Continuous vulnerability scanning, patch governance and a defined penetration-test remediation program. A documented incident response plan with the CISO as single point of contact and client notification commitments.

If something happens, you hear from a named person, on a defined timeline, following a tested plan.

Control mapping for your security team.

Where each SKYTEK control lands against the SOC 2 Trust Services Criteria and ISO/IEC 27001:2022 Annex A, and what evidence supports it.

Control domainSOC 2 TSCISO 27001:2022 Annex ASKYTEK implementationEvidence
Logical access and privilegeCC6.1 – CC6.3A.5.15 – A.5.18, A.8.2Entra PIM per-shift approval, zero standing privilege, MFA on activationPIM audit log, access reviews
Endpoint and device securityCC6.6 – CC6.8A.8.1, A.8.7, A.8.9Conditional Access with Intune compliance: EDR, encryption, patch levelPolicy export, compliance report
Credential and secret managementCC6.1, CC6.7A.5.17, A.8.24100-character unique credentials in IT Glue, reachable only via Landing ZoneCredential standard, retrieval log
Logging and monitoringCC7.2A.8.15, A.8.16Central Azure logging of sign-ins, PIM activity and jump-host sessions; alertingLog retention, alert rules
Vulnerability and patch managementCC7.1A.8.8Continuous scanning, patch governance, penetration-test remediation programScan reports, remediation tracker
Incident responseCC7.3 – CC7.5A.5.24 – A.5.28Documented plan; CISO as single point of contact; client notificationIncident response plan, tabletop records
Change managementCC8.1A.8.32Ticket-referenced, approved changes; project work separately scopedChange tickets, approvals
Business continuityA1.2 – A1.3A.5.29, A.5.30Documented continuity plan; Azure-hosted tooling with resilient designContinuity plan, test results
Security awarenessCC1.4, CC2.2A.6.3KnowBe4 simulations; quarterly CISO-led training; onboarding gateCompletion and phish-prone metrics
Third-party and vendor riskCC9.2A.5.19 – A.5.21Assessment of platforms in the delivery chain (Microsoft, N-able, IT Glue)Vendor SOC and ISO reports

TSC references follow the AICPA 2017 Trust Services Criteria with 2022 points of focus. Annex A references follow ISO/IEC 27001:2022. The complete mapping is maintained in SKYTEK's Statement of Applicability.

Request the evidence package.

Vendor due diligence should not take weeks. Tell us which documents your security or procurement team needs and we will return them under a mutual NDA, typically within two business days.

Request evidence under NDA

What the package contains

  • SOC 2 Type II report and current bridge letter
  • ISO 27001 Statement of Applicability and ISMS scope statement
  • Microsoft Azure Expert MSP audit confirmation
  • Information security policy, credential standard, incident response and business continuity plans
  • Client access model: PIM, Landing Zone and Conditional Access architecture
  • Completed security questionnaires (SIG Lite, CAIQ) on request

Documents are provided for the requesting organization's internal due diligence and are not for redistribution.

Questions security teams ask us.

Is SKYTEK ISO 27001 certified or aligned?+

SKYTEK operates an information security management system aligned to ISO/IEC 27001:2022, with a Statement of Applicability across Annex A and an annual internal audit and management review cycle. Our independent third-party attestation is SOC 2 Type II. Both documents are available under NDA.

Can we see the SOC 2 report before signing?+

Yes. The full Type II report is shared with prospects under a mutual NDA during evaluation, so your vendor-risk team can review it before any commercial agreement.

Do the same controls apply to every client?+

Yes. PIM, the Landing Zone, Conditional Access, credential handling and awareness training are how SKYTEK operates, not per-client configuration. Enterprise clients can add reporting cadence and division-level authorization matrices on top of the standard model.

Where is our data processed and stored?+

Client documentation and credentials live in IT Glue and SKYTEK's Microsoft 365 and Azure tenants, hosted in United States regions. Nothing is copied to engineer devices or to external services.

How is AI used in service delivery?+

Only Microsoft 365 Copilot, inside the SKYTEK tenant, for documentation and reporting: meeting notes, onsite work summaries, ticket categorization and hours utilization reporting. AI is not used to access, configure or change client systems, and consumer AI services are blocked by policy and technical control.

Who do we contact about a security concern?+

SKYTEK's CISO is the single point of contact for security matters and incident communication. Contact details are provided at onboarding and in the evidence package.

Bring your security team to the conversation.

We are happy to walk your CISO or vendor-risk function through the control environment, the audit reports and the access model before you decide.