Onward Services Guide

Document Information


This Services Guide contains provisions that define, clarify, and govern the scope of the services described in the quote that has been provided to you (the "Quote"), as well as the policies and procedures that we follow (and to which you agree) when we provide a service to you or facilitate a service for you. If you do not agree with the terms of this Services Guide, you should not sign the Quote and you must contact us for more information.

This Services Guide is our "owner's manual" that generally describes all managed services provided or facilitated by Onward Technology Solutions, LLC. ("Onward," "we," "us," or "our"); however, only those services specifically described in the Quote will be facilitated and/or provided to you.

This Services Guide is governed under our Master Services Agreement ("MSA"). You may locate our MSA through the link in your Quote or, if you want, we will send you a copy of the MSA by email upon request. Capitalized terms in this Services Guide will have the same meaning as the capitalized terms in the MSA, unless otherwise indicated below.

Activities or items that are not specifically described in the Quote will be out of scope and will not be included unless otherwise agreed to by us in writing.

Please read this Services Guide carefully and keep a copy for your records.

Initial Audit / Diagnostic Services

In most cases, we will conduct an initial audit of your information technology (IT) environment to determine the readiness for, and compatibility with, our proposed ongoing managed services. This audit may be comprised of some or all the following:
  • Audit to determine general Environment readiness and functional capability
  • Review of hardware and software configurations
  • Review of current vendor service / warranty agreements for Environment hardware and software
  • Basic security vulnerability check
  • Basic backup and file recovery solution audit
  • Speed test and ISP audit
  • Print output audit
  • Office telephone vendor service audit
  • Asset inventory
  • Email and website hosting audit
  • IT support process audit
If deficiencies are discovered during the auditing process (such as outdated equipment or unlicensed software), we will bring those issues to your attention and discuss the impact of the deficiencies on our provision of the Services and provide you with options to correct the deficiencies. Please note, unless otherwise expressly agreed by us in writing, auditing services do not include the remediation of any issues, errors, or deficiencies ("Issues"), and we cannot guarantee that all Issues will be detected during the auditing process. Issues that are discovered in the Environment after the auditing process is completed may be addressed in one or more subsequent quotes.

Onboarding Services

Onboarding is the stage during which we prepare your IT environment for the monthly managed services described in the Quote. During this phase, we will work with your Authorized Contact(s) to review the information we need to prepare the targeted environment, and we may also:
  • Uninstall any monitoring tools or other software installed by previous IT service providers (“Prior Tools”). Please note: If we are unable to uninstall or disable Prior Tools remotely, then an onsite visit may be required for which additional fees, such as travel time, may apply. In any event, if Prior Tools cannot be removed then we will bring that situation to your attention and, to the extent reasonably practicable, quarantine the Prior Tools so they become inoperative. We do not warrant or guarantee that all Prior Tools will be capable of being removed permanently, or that unremovable Prior Tools will become or remain inoperative.
  • Compile a full inventory of all protected servers, workstations, and laptop
  • Uninstall any previous endpoint protection and install our managed security solutions (as indicated in the Quote)
  • Install remote support access agents (i.e., software agents) on each managed device to enable remote support
  • Configure Windows® and application patch management agent(s) and check for missing security updates
  • Uninstall unsafe applications or applications that are no longer necessary
  • Optimize device performance including disk cleanup and endpoint protection scans
  • Review firewall configuration and other network infrastructure devices
  • Review status of battery backup protection on all mission critical devices
  • Stabilize network and assure that all devices can securely access the file server
  • Review and document current server configuration and status
  • Determine existing business continuity strategy and status; prepare backup file recovery and incident response option for consideration
  • Review password policies and update user and device passwords.
  • As applicable, make recommendations for changes that should be considered to the managed environment
This list is subject to change if we determine, at our discretion, that different or additional onboarding activities are required.
If deficiencies are discovered during the onboarding process, we will bring those issues to your attention and discuss the impact of the deficiencies on our provision of our monthly managed services. Please note, unless otherwise expressly stated in the Quote, onboarding-related services do not include the remediation of any issues, errors, or deficiencies (“Issues”), and we cannot guarantee that all Issues will be detected during the onboarding process.
The duration of the onboarding process depends on many factors, many of which may be outside of our control such as product availability/shortages, required third party vendor input, etc. As such, we can estimate, but cannot and do not guarantee, the timing or duration of the onboarding process. Should the onboarding process become protracted due to one or more of these factors, or if Customer fails to cooperate or provide necessary staffing or information required for the proper configuration or implementation of the managed services, then we reserve the right to modify our quoted response times and/or the scope of the managed services as reasonably necessary to accommodate these issues.

Ongoing / Recurring Managed Services

The table below describes all managed services provided or facilitated by Onward; however, only those services specifically described in the Quote will be facilitated and/or provided to you (collectively, the “Services”).  Please review the Quote to determine which of the managed services listed below will be provided to / facilitated for you.
Ongoing/recurring managed services are provided to you or facilitated for you on an ongoing basis and, unless otherwise indicated in a Quote, are billed to you monthly. Some ongoing/recurring services will begin with the commencement of onboarding services; others will begin when the onboarding process is completed. Please direct any questions about start or “go live” dates to your account manager.

Managed Services

(Please refer to the Quote to determine which Managed Services you will be receiving.)
 
 
Services
General Description

Business Continuity and Disaster Recovery

Implementation and facilitation by our designated Third Party Provider of a comprehensive data protection solution, covering supported SaaS platforms, on-premise servers, and designated endpoints, including workstations and laptops that contain essential business data. This service offers automated, SLA-driven backup management with configurable recovery options and compliance-focused data retention for up to 7 years. Designed to minimize manual intervention, this solution leverages advanced technology to ensure data resilience, protect critical business information, and support business continuity.
Comprehensive SaaS Backup: Complete cloud-to-cloud backup for supported SaaS applications, covering email, collaboration tools, file storage, and identity management systems. This includes data backup for user accounts, files, contacts, calendars, messages, audit logs, security policies, applications, and device management configurations.
  • Comprehensive SaaS Backup: Offers cloud-to-cloud backup for supported SaaS applications, covering essential business data and configurations across applications, including email, collaboration tools, file storage, and identity management systems.
  • Data Coverage: Provides comprehensive backup for user accounts, files, contacts, calendars, messages, audit logs, security policies, applications, and device management configurations.
Continuous Backup Monitoring: 24/7 monitoring of all supported backup sources (SaaS, on-premise servers, and endpoints) for real-time detection of backup failures, capacity issues, and other disruptions, with proactive alerting.
  • Proactive Alerting: Provides immediate notifications for any issues in backup operations, enabling prompt resolution to maintain data integrity.
RTO/RPO-Based Backup Scheduling: Customizes backup schedules based on Customer’s Recovery Time Objective (RTO) and Recovery Point Objective (RPO) requirements, allowing for flexible frequency options to meet data protection needs.
  • Continuous Backups: Near-instantaneous recovery points for critical assets, minimizing data loss.
  • High-Frequency Backups (1-3 times per day): Configured for moderately critical assets, allowing recovery within established data loss limits.
  • Daily Backups: Standard daily backups provide data consistency and scheduled recovery points for non-critical assets.
Granular, Point-in-Time Recovery: Enables precise, point-in-time recovery across servers, endpoints, and SaaS applications. Supports restoration of files, messages, services, and virtual machines to selected versions with accuracy.
Cross-Platform Protection & Analytics: Offers comprehensive backup and recovery for critical on-premise servers and designated endpoints, enhancing protection for essential data, applications, and system configurations.
  • Endpoints and Servers: Secures data for critical servers and specified endpoints (e.g., workstations, laptops) according to backup policy and requirements.
Global Storage and Extended Retention: Supports configurable retention policies of up to 7 years to meet regulatory and business requirements. Data storage is available in secure global locations, ensuring compliance with data sovereignty regulations.
Enhanced Security and Encryption: Ensures that backed-up data is encrypted to meet industry security standards and protect confidentiality.
  • Encryption: All data is encrypted in transit and at rest using AES-256 encryption.
  • Physical Security: Backup data facilities implement strict physical security, including controlled access, surveillance, and redundant connectivity with failover capabilities.
Compliance Integration & eDiscovery: Supports compliance and audit readiness with centralized reporting and data retrieval capabilities, aligning with security and compliance frameworks.
  • Monitoring and Logging for Compliance: Provides security monitoring and logging for compliance purposes. Backup logs and activity details are accessible for compliance documentation.
  • eDiscovery & Full-Text Search: Offers eDiscovery and search capabilities across backup environments for quick data retrieval, integrated into Onward’s IT Service Management (ITSM) platform for streamlined reporting.
Backup Retention Options: Provides flexible retention options to support regulatory, industry, and business-specific requirements, with standard and extended configurations.
  • Standard Retention: Default retention is set at 30 days for non-critical data, with options for monthly and annual retention periods.
  • Extended Retention (up to 7 years): Available for industries requiring long-term data preservation due to regulatory mandates. Examples include:
    • Healthcare (HIPAA Compliance): Typically 6 years for patient data and documentation.
    • Financial Services (SEC & FINRA): Up to 7 years for records related to transactions, communications, and compliance.
    • Legal & Government (FOIA and GDPR): 5 to 7 years for records required for disclosure or retention mandates.
    • Manufacturing & Supply Chain: 3 to 5 years for quality control and compliance records.
NOTE: Extended retention may incur additional storage costs. Customers should specify retention needs during configuration to ensure compliance with applicable requirements.

Recovery of Data, Services, and Systems: Provides restoration of backed-up data, applications, and services during standard business hours, with options for prompt response based on availability and backup specifications.

  • Request Methods: Restoration requests may be submitted via:
    • Email: support@onward.solutions
    • Web Portal: Onward PSA Portal
    • Telephone: (239) 984-0580
  • Restoration Time: Restoration will be prioritized based on technician availability and confirmation of recovery points. Services include recovery of files, applications, SaaS data, and other designated assets.
NOTE: Backup & Recovery Services require active Customer cooperation. If Customer provides incomplete, inaccurate, or outdated information, data recovery may be affected. Restoration timelines depend on technician availability and data recovery points. This Service does not guarantee data integrity or recovery for issues outside the control of Onward or its Third Party Provider, such as hardware failures, unauthorized data changes, or third-party service interruptions.

Compliance & Data Retention

Implementation and facilitation by our designated Third Party Provider of a regulatory compliance and data retention management solution. This service assists the Customer in aligning operations with applicable regulatory standards across all managed environments. Services include compliance monitoring, centralized reporting, audit support, and data retention policies tailored to meet industry-specific requirements, including HIPAA, SOC 2, GDPR, and other relevant frameworks. Automated reminders and structured data retention policies are provided to promote a proactive, consistent approach to regulatory compliance.
Comprehensive Compliance Monitoring: Provides continuous oversight and alignment with regulatory frameworks to support adherence to internal policies and external standards applicable to Customer’s business operations.
  • Regulatory Framework Alignment: Monitors and configures compliance policies to meet industry standards such as HIPAA, SOC 2, and GDPR. Adjustments are made based on regulatory changes to facilitate ongoing compliance assessments.
  • Templates and Training Access: Supplies compliance templates, regulatory guidelines, and training resources for Customer’s staff, reinforcing adherence to policies and regulatory requirements.
  • Compliance Dashboards: Real-time dashboards display compliance status across policies and controls, providing compliance officers with immediate insights and highlighting potential compliance gaps.
Automated Compliance & Reporting: Automates compliance activities and consolidates reporting to assist in audit readiness and regulatory alignment.
  • Audit-Ready Documentation: Compiles compliance logs, policy documentation, and procedural records into a centralized repository, facilitating audit preparation with records of compliance activities, policy changes, and training completions.
  • Automated Compliance Reminders: Sends scheduled reminders for compliance actions, such as risk assessments, training updates, and policy reviews. These reminders help the Customer stay on schedule with regulatory timelines.
  • Customizable Reporting: Enables the generation of compliance reports tailored for internal review or external audits. Reports can highlight specific controls, compliance metrics, or regulatory gaps based on audit needs.
eDiscovery & Full-Text Search: Supports regulatory and legal inquiries by enabling efficient data retrieval and improving audit readiness.
  • eDiscovery Tools: Facilitates rapid retrieval of documents, emails, and records pertinent to audits or legal investigations. Supports compliance review and legal inquiries by organizing relevant data for easy access.
  • Full-Text Search: Enables comprehensive search capabilities across stored documentation, allowing the Customer to efficiently locate data required for regulatory or legal obligations.
Data Retention & Compliance Audits: Implements data retention policies aligned with regulatory requirements and conducts scheduled reviews to verify ongoing compliance.
  • Configurable Data Retention Policies: Provides retention schedules aligned with regulatory mandates, supporting data retention for periods of up to 7 years. Settings are customizable to meet industry and jurisdictional requirements.
  • Annual Compliance Reviews: Conducts annual compliance reviews to assess the Customer’s regulatory alignment, with optional quarterly assessments available for enhanced compliance verification.
  • Policy & Procedure Alignment: Updates policies and procedures as regulatory standards evolve, aiming to support the Customer’s continuous compliance alignment.
NOTE: This Service requires Customer’s active cooperation and participation. If the Customer provides incomplete, inaccurate, or outdated information, the effectiveness of this Service may be compromised, and the results should not be solely relied upon. Certification of compliance completion is valid as of the issuance date but does not guarantee ongoing compliance. For consistent regulatory alignment, it is strongly recommended that the Customer maintains this Service without lapses to support the ongoing adherence of operations, processes, and procedures to regulatory standards.

Cybersecurity, Threat Management & Identity Protection

Implementation and facilitation by our designated Third Party Providers of a comprehensive cybersecurity solution, designed to proactively detect, prevent, and respond to digital threats across emails, endpoints, networks, and identities. This service incorporates Zero-Trust principles to establish multi-layered protection with advanced detection capabilities, rapid response, and identity-focused security measures, ensuring that critical systems and data remain secure against evolving cyber threats.
NOTE: This service requires Customer adherence to Onward-specified security policies, including role-based access, MFA, VPN protocols, and compliance with Zero-Trust protections. Non-compliance may increase security risks.
Zero-Trust Security Framework: Establishes Zero-Trust principles as the foundational security model, ensuring strict access control, continuous verification, and least-privilege access across the organization.
  • Identity Verification at Every Access Point: Enforces user identity verification using role-based access, multi-factor authentication (MFA), and location-based policies.
  • Device Compliance Checks: Limits network access to secure, authenticated devices based on health and security criteria.
  • Network Micro-Segmentation: Secures network segments to prevent lateral movement and contain threats within isolated areas.
Identity Services Protection: Manages and monitors identity services, enforcing strict access policies and detecting unusual activity to secure accounts and prevent unauthorized access.
  • Single Sign-On (SSO) Implementation: Configures and supports SSO capabilities to streamline secure access to integrated systems.
  • Multi-Factor Authentication (MFA) Setup & Enforcement: Establishes MFA across all user accounts, providing additional security for sensitive applications.
  • MFA Activity Monitoring: Monitors MFA events to detect compromised accounts, unauthorized logins, and high-risk devices.
  • Role-Based Access Management & Compliance Monitoring: Assigns access based on roles and regularly audits to maintain least-privilege principles.
NOTE: Identity Services Protection is contingent upon Customer’s adherence to MFA, VPN access controls, and role-based access policies. Failure to comply may result in elevated security risks.

Privileged Access Control: Manages elevated access rights across endpoints and cloud services, with strict controls and automated revocation upon task completion.

  • Endpoint Privilege Management: Limits administrator privileges, allowing elevated permissions only through controlled, automated systems.
  • Break-Glass Accounts for Cloud Services: Controls administrative access to cloud services via Onward-managed “break-glass” accounts, restricting elevated permissions to Onward-authorized personnel.
  • Just-In-Time (JIT) Administrative Access: Temporarily grants administrative access for specific tasks, with automatic revocation post-task.
Email Threat Protection: Provides advanced email security measures to defend against phishing, malware, and business email compromise (BEC) threats.
  • Phishing Detection: Blocks suspicious links and attachments commonly used in phishing attacks.
  • Friendly Name Filtering: Detects impersonation attempts by verifying sender name authenticity.
  • Impersonation Defense: Blocks spoofed names and domains, mitigating social engineering risks.
Endpoint Antivirus & Malware Protection: Delivers robust malware and antivirus protection across endpoints, leveraging AI and real-time analysis.
  • Behavior-Based Threat Detection: Blocks suspicious endpoint behaviors before execution.
  • Sandbox Analysis: Isolates potentially harmful applications for secure analysis.
  • Comprehensive Malware Defense: Protects against file-based and fileless threats, with whitelisting for legitimate scripts.
Dark Web Monitoring: Scans dark web sources for exposed organizational credentials, notifying administrators of any detected compromises.
  • Credential Exposure Alerts: Alerts administrators if credentials related to the organization are found on the dark web.
  • End-User Notifications: Prompts affected users to reset credentials, reducing risks of unauthorized access.
Unified Threat Detection & Response (MDR/XDR): Provides 24/7 monitoring, detection, and incident response across email, endpoint, network, and identity layers. MDR/XDR combines Managed Detection and Response (MDR) and Extended Detection and Response (XDR) for a unified, holistic security approach.
  • MDR (Managed Detection & Response): 24/7 monitoring, threat hunting, and incident response, with real-time response from security professionals.
  • XDR (Extended Detection & Response): Correlates data from multiple layers (email, endpoint, network, identity) for in-depth detection and response.
  • On-Demand Endpoint Isolation: Isolates compromised endpoints to prevent spread.
  • Root Cause Analysis and Forensics: Identifies threat origins, with comprehensive forensic data for continuous improvement.
Scope Note: MDR/XDR applies only to supported, integrated systems managed by Onward. Effectiveness may vary depending on integration completeness across the managed environment.

End User Security Awareness Training: Provides training to improve end-user awareness of cybersecurity risks, designed to reduce susceptibility to phishing and other attacks.

  • Online, On-Demand Training: Provides self-paced, multilingual training videos covering essential cybersecurity practices.
  • Quizzes & Retention Verification: Includes interactive quizzes to assess employee understanding of key concepts.
  • Baseline Testing & Phishing Simulations: Assesses user susceptibility to phishing attacks through simulated campaigns and tracks improvement over time.
NOTE: Regular user participation in security awareness training is strongly recommended. Failure to engage in or complete training may elevate organizational risk.

Penetration Testing: Conducts simulated cyberattacks to identify vulnerabilities, aligned with Zero-Trust security principles.

  • External Testing: Evaluates internet-facing systems, firewalls, and applications for exposure to unauthorized access.
  • Internal Testing: Simulates insider threats to test internal defenses.
  • PCI Penetration Testing: Assesses vulnerabilities per PCI standards.
  • Web Application Testing: Conducts tests on web applications following industry-standard frameworks (e.g., OWASP).
NOTE: Penetration Testing includes vulnerability scanning supplemented by targeted attack simulations for a comprehensive assessment. Additional terms for Penetration Testing apply.

Incident Response & Alerting: Provides immediate alerting, incident analysis, and reporting, with escalation based on threat severity.

  • 24/7 Alerting and Escalation: Real-time alerts for suspicious activity, with escalation aligned with risk severity.
  • Incident Reporting and Analysis: Delivers detailed incident reports, including root cause analysis, impact assessment, and recommendations for improved resilience.
  • Data Ingestion and Reporting: Integrates security data into the IT Service Management Platform, enabling centralized access to metrics, alerts, and compliance information.
NOTE: Please refer to Anti-Virus, Anti-Malware, and Breach/Cyber Security Incident Recovery sections for specific remediation details.

Cloud Infrastructure Management

Implementation and facilitation of a comprehensive cloud infrastructure management solution, focusing on the deployment, management, and support of virtual resources within designated cloud platforms. This service provides end-to-end oversight of cloud-based servers, storage, and applications, ensuring scalability, security, and operational efficiency across managed cloud resources. Designed to enable organizations to leverage cloud-native benefits, this solution maintains control over resource utilization, cost optimization, and security standards.
  • Cloud Resource Deployment: Deploys cloud-based resources, including virtual machines, storage accounts, databases, and other cloud-native applications, tailored to support secure and resilient operations based on customer requirements.
  • Provisioning and Configuration Management: Manages configurations, access controls, and permissions for cloud resources, enforcing role-based access control (RBAC) to comply with industry and company standards.
  • Cost Management and Optimization: Monitors cloud usage and optimizes spending across resources. Provides cost allocation and reporting to identify savings opportunities, ensuring cost-effective resource management.
  • Scalability and Performance Optimization: Adjusts scaling and performance settings to maintain optimal service levels, monitoring resource utilization and provisioning adjustments to meet fluctuating demand.
  • Backup and Disaster Recovery: Configures cloud-native backup and disaster recovery for critical resources, ensuring encrypted backups that meet specific recovery point (RPO) and recovery time objectives (RTO).
  • Security and Compliance Management: Applies security configurations, including encryption, access controls, and compliance with regulatory frameworks (e.g., SOC 2, HIPAA) to ensure secure resource management.
  • Monitoring and Alerts: Provides continuous monitoring for performance, availability, and security, with automated alerts routed to the ITSM platform for efficient incident response.
  • Cloud-Based Identity and Access Management (IAM): Configures IAM with multi-factor authentication (MFA) and role-based policies, enhancing security and controlling access to cloud resources.
  • Automation and Infrastructure as Code (IaC): Utilizes IaC to automate deployments and ensure consistent configurations across cloud resources, minimizing manual configuration efforts.
  • Virtual Network Management: Manages secure, cloud-based virtual networks, configuring connectivity across cloud resources, including VPNs and virtual firewalls, for secure, isolated communication within the cloud environment.
NOTE: Cloud Infrastructure Management applies exclusively to resources within supported cloud environments. This service does not include management of physical on-premise infrastructure or hybrid solutions unless explicitly stated in the Quote. Additional charges may apply for complex configurations, specialized integrations, or non-standard resources requiring specific management.
For co-managed customers who procure cloud infrastructure subscriptions through Onward, self-provisioned resources are outside our standard support scope and will incur extra charges for any necessary management, as they may not adhere to Onward’s deployment standards.

Network Infrastructure Management

Implementation and facilitation of a secure, scalable, cloud-managed network infrastructure solution that provides full-stack visibility and centralized management using our designated Third Party Provider. This infrastructure standard ensures efficient, reliable configurations across all network components, including firewalls, switches, access points, VPNs, and cloud-based virtual networks, delivering robust security and performance monitoring.
Note: Onward will only deploy and implement network solutions that meet these requirements to optimize operational reliability and security.  Any networking devices, such as firewalls, switches, wireless access points or routers, that are supplied by Customer cannot be older than five (5) years from the applicable device’s original date of manufacture, and in all cases must be supported by the manufacturer of the device(s).
Cloud-Managed Network Infrastructure: Establishes a centralized, cloud-based environment for managing all network components, enabling control, scalability, and full-stack visibility across on-premise and cloud infrastructures (e.g., virtual networks, SD-WAN).
  • Full-Stack Visibility: Provides continuous visibility into network performance, device health, and security status, enabling proactive management and rapid issue resolution across firewalls, switches, access points, VPNs, and virtual networks.
  • Scalability: Allows seamless network expansion and adjustment to accommodate organizational growth and changing network needs, supporting both on-premise and cloud environments.
  • Centralized Management Console: Provides a single, cloud-managed interface for efficient remote management of all network devices and configurations, simplifying network operations and oversight across on-premise, SD-WAN, and cloud environments.
SD-WAN and Cloud Network Integration: Leverages SD-WAN to enable secure, optimized connectivity across multiple locations and between on-premise and cloud resources.
  • Secure, Reliable Connectivity: Configures SD-WAN capabilities to provide secure, high-performance connections between distributed sites and cloud-based resources.
  • Traffic Prioritization: SD-WAN routes network traffic based on priority, ensuring optimal bandwidth allocation and improved application performance across remote locations.
  • Seamless Cloud Integration: Extends network policies and controls to cloud-based networks, supporting secure, consistent connectivity between on-premise infrastructure and virtual networks.
Network Security Management: Provides centralized security configurations and monitoring across network devices, enforcing policies to protect all network layers and resources.
  • Traffic Monitoring and Filtering: Monitors inbound and outbound traffic to detect unauthorized or malicious activity, enforcing security policies for network integrity.
  • Intrusion Prevention System (IPS): Continuously analyzes network traffic to detect and block known attack signatures and suspicious behavior, helping prevent exploitation of vulnerabilities.
  • DNS Security: Implements DNS-level threat protection to block malicious domains and prevent access to harmful sites, reducing the risk of phishing, malware, and other threats. This provides an additional layer of security by proactively filtering requests before they reach the internal network.
  • Access Control Configuration: Configures role-based access across the network, ensuring access to sensitive resources is limited to authorized personnel only.
  • Encrypted Remote Access (VPN): Configures secure, encrypted VPNs to protect data in transit, maintaining confidentiality for remote and distributed users.
  • Content Filtering and Web Security: Enforces web filtering policies across the network, blocking access to malicious or non-business sites, enhancing productivity and network security.
Unified Threat Detection & Response Across Network Devices: Provides continuous monitoring, real-time detection, and response capabilities across all network devices, including SD-WAN components, to address security threats.
  • 24/7 Network Monitoring: Continuous monitoring of all network devices (firewalls, switches, access points, VPNs, etc.) for real-time threat detection and response.
  • Threat Detection and Incident Response: Delivers real-time alerts and incident escalation based on the severity of detected threats, ensuring prompt attention to critical issues.
  • Automated Firmware and Software Updates: Regularly updates network devices with security patches and firmware to mitigate vulnerabilities and ensure alignment with security standards.
Cloud Network Security: Extends network security policies to cloud-based virtual networks, ensuring consistent security across on-premise and cloud environments, including secure connections between physical and virtual resources.
  • Cloud Virtual Network Integration: Configures and secures virtual network resources in cloud environments, applying access controls, encryption, and segmentation to maintain security.
  • Cross-Environment Access Control: Manages access policies consistently across on-premise and cloud networks, supporting seamless, secure connectivity for distributed environments.
  • Unified Monitoring: Centralizes monitoring of on-premise, SD-WAN, and cloud network segments, enabling integrated threat detection and comprehensive reporting across all network layers.
Wi-Fi Network Management: Ensures secure, reliable wireless connectivity with thorough setup, management, and security monitoring across all customer premises.
  • Wireless Site Survey: Conducts detailed surveys to assess coverage, interference, and performance, optimizing access point placement for consistent connectivity.
  • Wireless Access Point Configuration: Configures secure access points to deliver optimized coverage and seamless user connectivity throughout managed locations.
  • Performance Monitoring: Continuously monitors Wi-Fi performance to proactively detect connectivity or security issues.
  • Standards Compliance: Ensures all Wi-Fi equipment complies with industry standards, supporting compatibility and reliability across device types.
  • Remote Support: Provides remote troubleshooting and support during business hours to address Wi-Fi connectivity and security issues as needed.
Network Security & Compliance: Implements strong data protection and aligns network security configurations with industry standards to meet compliance and regulatory needs.
  • Data Encryption: Encrypts all network transmissions to prevent interception and ensure data confidentiality.
  • Role-Based Access Control: Configures access policies based on user roles, ensuring critical network resources are only accessible to authorized users.
  • Alignment with Security Standards: Configures network security in accordance with industry frameworks (e.g., NIST, CIS Controls) to meet compliance standards relevant to Customer’s industry.
Incident Response & Alerting: Provides continuous monitoring, real-time alerting, and detailed incident reporting for any unusual network activity or security events.
  • 24/7 Monitoring and Alerting: Continuous monitoring of network security across all devices, with real-time alerts for suspicious activity or potential security incidents.
  • Incident Reporting: Provides detailed reports on detected threats, actions taken, and recommendations for future improvements.
NOTE: This Service requires Customer cooperation to ensure that all relevant configurations and access requirements are provided accurately. Onward is not responsible for security incidents arising from third-party integrations or external configurations outside our control. Remediation of network incidents beyond standard monitoring and alerting is provided on a time and materials basis. Please see additional terms for remediation services below.

Remote Monitoring & Management

Implementation and facilitation of a comprehensive Remote Monitoring & Management (RMM) solution from our designated Third Party Provider. This service provides configuration, compliance enforcement, continuous monitoring, and proactive maintenance for endpoints (e.g., workstations, laptops, IoT devices) and servers. The RMM service also includes workforce productivity tracking and reporting to help optimize operational efficiency and support employee productivity.
Note: RMM services apply to all managed endpoints and servers within Onward’s scope. This service excludes peripheral devices such as printers, scanners, and other non-core equipment. Additional configurations may be necessary for specialized or non-standard devices to ensure compatibility with Onward’s RMM framework.
Policy Management & Compliance for Endpoints and Servers: Establishes and enforces policies across all managed devices to ensure security and operational compliance.
  • Policy Configuration for Devices: Configures security and operational policies for endpoints and servers, including access controls, security settings, and usage permissions aligned with corporate policies.
  • Compliance Monitoring & Enforcement: Monitors device compliance with company policies, generating alerts and corrective actions for non-compliance as needed.
  • Device Enrollment & Access Control: Manages device enrollment and access controls, ensuring that only authorized users can access critical systems through centralized policy settings.
Endpoint Coverage: Provides tailored management for different device types to meet specific security and operational requirements.
  • Workstations & Laptops: Manages user-facing devices to ensure policy alignment, security updates, and performance optimization.
  • IoT & Specialized Devices: Configures and monitors specialized endpoints critical to operations, including IoT devices, digital signage, kiosks, and conference units, to maintain consistent performance and security.
  • Servers: Manages production and infrastructure servers to ensure optimal configuration, security compliance, and performance, supporting front-end and backend operations.
  • Device Provisioning Automation: Automates the initial setup and configuration of new devices, ensuring they are equipped with required software, policies, and access permissions in alignment with Customer’s operational needs. This service also covers provisioning for on-site, remote, and hybrid environments.
  • White Glove Finalization & User Training: Completes device provisioning with a “white-glove” service, including personalized setup and detailed user orientation. This includes training on device functionality, access controls, and software usage, ensuring smooth transitions and minimizing support needs during onboarding.
Continuous Monitoring & Performance Management: Offers real-time monitoring and performance optimization for all managed devices to proactively detect and address issues.
  • 24/7 Performance & Health Monitoring: Monitors devices continuously for key indicators (e.g., CPU, memory, disk usage), enabling rapid response to any issues that may arise.
  • Critical Alerts & Escalation: Generates alerts for critical issues, such as hardware failures or low disk space, enabling Onward’s support team to act quickly to prevent disruptions.
  • Capacity Monitoring: Monitors system capacity to proactively address storage constraints or performance degradation before they impact operations.
Patch Management for Endpoints and Servers: Ensures that all managed devices are updated with the latest security patches and firmware updates.
  • Automated Patch Deployment: Schedules and deploys patches across all endpoints, servers, and IoT devices, reducing the risk of security vulnerabilities.
  • Compliance Verification for Patch Management: Verifies patch compliance for all devices, ensuring that updates are correctly applied and align with security standards.
  • Firmware Updates for Devices and Servers: Deploys firmware updates on applicable devices to maintain compatibility, security, and performance.
Note: We will keep all managed hardware and managed software current with critical patches and updates (“Patches”) as those Patches are released generally by the applicable manufacturers. Patches are developed by third party vendors and, on rare occasions, may make the Environment, or portions of the Environment, unstable or cause the managed equipment or software to fail to function properly even when the Patches are installed correctly. We will not be responsible for any downtime or losses arising from or related to the installation or use of any Patch. We reserve the right, but not the obligation, to refrain from installing a Patch if we are aware of technical problems caused by a Patch, or we believe that a Patch may render the Environment, or any portion of the Environment, unstable.
Automated Health Optimization for Devices and Servers: Enhances performance and health across devices using automation.
  • Self-Healing Scripts: Uses automation to address common issues on endpoints and servers without requiring manual intervention.
  • Performance Optimization: Schedules automated performance enhancements for both endpoints and servers, optimizing CPU, memory, and storage efficiency.
  • Disk Cleanup & Optimization: Regularly cleans temporary files and unnecessary data to free up storage and ensure optimal device performance.
Workforce Productivity Tracking: Provides insights into productivity trends and resource utilization to support workforce efficiency and alignment with organizational goals.
  • Usage Analytics: Monitors device usage to track active hours, application usage, and productivity trends to help inform operational decisions.
  • Activity Reporting: Provides activity summaries to management, helping identify productivity patterns and opportunities for operational improvement.
  • Compliance Tracking for Remote Work: Monitors remote work compliance to ensure employees adhere to approved productivity guidelines and policies.
Remote Access & Support: Enables secure remote access and troubleshooting for all managed devices to provide uninterrupted support.
  • Secure Remote Access: Facilitates secure, remote access for troubleshooting across all devices, ensuring data confidentiality and quick issue resolution.
  • Audited Remote Sessions: Logs and audits all remote access sessions to support compliance requirements.
  • End-User Support & Troubleshooting: Provides support for end users during business hours, assisting with device connectivity, configurations, and other technical issues.
Incident Response & Alerting: Delivers immediate alerting and incident response to address unusual device activity or security threats.
  • 24/7 Monitoring and Alerting: Continuous monitoring across all devices for real-time alerts related to suspicious activity or potential security incidents.
  • Incident Reporting: Provides detailed incident reports, including detected threats, corrective actions, and recommendations for improved security.
NOTE: This RMM service applies to devices and servers within Onward’s managed scope. Peripheral devices (e.g., printers, scanners) and non-core equipment are excluded from this service. Specialized or non-standard devices may require additional configurations to ensure full compatibility with Onward’s RMM management framework.

Remote Helpdesk & Onsite Support

Implementation and facilitation of a comprehensive remote helpdesk and onsite support solution. This service provides tiered support for troubleshooting, incident resolution, and escalation across all managed assets. Remote Helpdesk offers responsive, efficient support during standard business hours, while Onsite Support addresses incidents that require physical intervention at the customer’s premises.
Note: Remote Helpdesk and Onsite Support are limited to managed assets within Onward’s service scope. Requests involving non-managed or third-party equipment may incur additional charges or require referral to the original equipment provider.
Remote Helpdesk Support: Offers remote technical support to assist with troubleshooting and issue resolution for managed devices, software, and infrastructure.
  • Scope of Support: Remote Helpdesk is available to address technical issues on managed devices and software within the agreed scope, including troubleshooting hardware and software failures, network connectivity issues, and operational disruptions.
  • Service Hours: Standard Remote Helpdesk support is available Monday through Friday, from 8:00 AM to 5:00 PM Eastern Time, excluding holidays. Support requests outside these hours may be subject to increased rates and require prior scheduling.
  • Support Request Channels: Customers may submit support requests via:
  • Escalation Process: Incidents unresolved within the standard response time will be escalated to senior technicians or specialized teams. Customers will be informed of escalation actions and receive updates on expected resolution timelines.
NOTE: Remote Helpdesk support may involve remote screen-sharing or device access, requiring customer approval for each session. Some issues may require specialized support at an additional charge.

Onsite Support Services: Dispatches certified technicians to the customer’s location for incidents that cannot be resolved remotely.

  • Scope of Onsite Support: Onsite Support is available for managed assets under Onward’s service scope when remote troubleshooting is unsuccessful or physical intervention is required. Common services include hardware repairs, network diagnostics, and server maintenance.
  • Scheduling and Availability: Onsite Support is subject to technician availability and is scheduled based on incident urgency. Standard hours are Monday through Friday, 8:00 AM to 5:00 PM Eastern Time. After-hours and emergency support may incur additional charges.
  • Travel and Onsite Charges: Travel expenses and onsite service charges apply as specified in the agreement. Charges include travel fees, time onsite, and any required materials.
  • Onsite Response Time: Onsite response times and prioritization follow the terms outlined in the Service Level Agreement (SLA).
  • Escalation and Reporting: If the issue persists after the initial visit, technicians coordinate with senior engineers and relevant teams for prompt resolution. A report detailing the onsite service and any recommended follow-up actions will be provided.
NOTE: Onsite Support is limited to managed assets and does not cover third-party or customer-provided equipment. Non-covered equipment may incur additional service charges or require referral to the original equipment provider.

Proactive Support & Issue Prevention: Provides proactive monitoring and periodic checks to minimize recurring issues and system downtime.

  • Health Checks & Preventive Maintenance: Conducts periodic health checks on managed systems to identify and address potential issues before they affect operations.
  • Scheduled Maintenance Windows: Maintenance activities, such as system updates and backups, are scheduled outside regular business hours to minimize operational impact.
  • Customer Notifications: Customers receive advance notification of preventive maintenance, scheduled downtime, or updates to the Helpdesk service scope.
NOTE: Proactive support activities are scheduled based on business needs and may vary depending on system usage patterns, customer requirements, and service agreements.

End-User Support & Training Assistance: Provides basic troubleshooting and user assistance, including training support on common software and systems.

  • Basic Troubleshooting Assistance: Assists end-users in resolving common issues with managed software, device configurations, and connectivity.
  • Guided Walkthroughs: Offers step-by-step guidance for routine tasks, such as accessing shared resources, configuring email, and connecting to VPN.
  • User Training Sessions: Arranges user training sessions on key systems or applications upon request, subject to technician availability.
NOTE: End-user support is limited to managed systems and does not include specialized application training unless expressly included in the service agreement.

Incident Reporting and Documentation: Provides detailed documentation and reporting for incidents, ensuring full visibility into issue resolution and support activity.

  • Incident Documentation: All support requests are documented in the ticketing system, including issue descriptions, resolution steps, and any follow-up actions.
  • Service Reports: Monthly reports summarizing support activity, response times, and common incidents are available upon request, providing insight into system health and support efficiency.
  • Customer Feedback & Quality Assurance: Customers are encouraged to provide feedback on support interactions. Feedback is reviewed to improve service quality.
NOTE: Documentation and reporting cover managed services and do not include third-party or unsupported systems unless otherwise specified in the agreement.

Co-Managed Services

Onward’s Co-Managed IT Services provide an adaptable IT management framework, enhancing the capabilities of the Customer’s IT team through shared responsibilities, specialized expertise, and access to essential tools and support functions. This service includes dedicated resources for IT strategy, infrastructure management, and support assistance, allowing the Customer to maintain operational control while benefiting from Onward’s technical and governance expertise.
  • Collaborative Support Framework: Onward assists the Customer’s IT team with support responsibilities, providing guidance and escalation resources for day-to-day technical issues. While the Customer’s team retains primary control over user support, Onward offers structured assistance, including remote troubleshooting, escalation management, and periodic support for complex technical issues that exceed the standard scope.
  • IT Infrastructure Management: Onward manages and supports key IT infrastructure components, including provisioning, configuration, and maintenance of servers, cloud environments, and network devices. Infrastructure services are tailored to align with Customer goals, ensuring efficient deployment and management of critical IT resources.
  • Change and Incident Coordination: Onward oversees change management processes, handling requests, approvals, and communications for major updates or new technologies introduced within the managed environment. For incidents that impact IT services, Onward collaborates with the Customer’s team to expedite resolution, providing a systematic approach to incident handling and response.
  • Strategic IT Guidance: Onward provides regular consultation sessions to review IT strategy, offering insights and recommendations to align IT services with Customer business objectives. This includes semi-annual or annual strategic reviews to assess long-term goals and the current IT environment.
  • ITSM Platform Access and Reporting: Customers receive access to Onward’s IT Service Management (ITSM) platform, which includes tools for asset tracking, ticket management, and compliance reporting. This platform integrates analytics and dashboards for visibility into IT operations, empowering the Customer’s team with actionable insights and efficient tracking of service performance.
  • Asset and Lifecycle Management: Onward provides asset lifecycle services, including provisioning, tracking, and maintenance. This structured approach ensures that IT assets remain secure, up-to-date, and compliant with organizational standards, supporting smooth operation throughout each asset’s lifecycle.
Note: The Co-Managed IT Services are intended to provide supplementary support and expertise. Customer retains primary responsibility for in-house user support and daily IT operations, with Onward acting as a technology advisor and resource to ensure effective, compliant IT management. Refer to the Co-Managed Services Policy section for details on roles, responsibilities, and escalation protocols specific to co-managed environments.

IT Service Management (ITSM) Platform

Implementation and facilitation of a comprehensive IT Service Management (ITSM) platform by Onward, designed to enhance service delivery, operational transparency, and support efficiency for Customer’s IT environment. This service includes a centralized portal, asset management, ticketing, reporting, and automated workflows, providing end-users and management with easy access to IT support and insights into service metrics.
Note: Onward administers the ITSM platform, offering training and guidance on its effective use. Customer’s IT personnel are responsible for adhering to internal procedures and protocols for ITSM utilization.
Customer Portal Access: Provides a secure, accessible portal for Customer to submit, track, and monitor IT service requests, with tools for automation and reporting dashboards.
  • Ticket Submission and Tracking: Permits end-users to log IT support requests and monitor resolution status.
  • Service Request Monitoring: Enables Customer to view updates and timelines for ongoing service requests.
  • Automation Access: Allows authorized end-users to initiate pre-approved automated tasks, such as password resets or account unlocks, as enabled by Onward.
  • Managerial Dashboards: Provides Customer’s managers and executives with real-time access to IT service metrics, SLA compliance data, and performance analytics.
Ticketing and Incident Management: Centralized logging, prioritization, and AI-assisted management of IT support requests for consistent service delivery.
  • AI-Driven Ticket Classification: Automatically categorizes support requests by issue type and urgency to prioritize effectively.
  • Automated Ticket Routing: Assigns tickets to appropriate teams based on classification, priority level, and service-level targets.
  • Response Time Protocols: Aligns ticket handling with designated priority levels to meet SLA requirements.
  • Escalation Procedures: Escalates incidents that exceed standard resolution times to senior technicians, with Customer notified of escalation steps.
Asset Management and Integration: Maintains records of IT assets, including hardware, software, and licenses, with real-time data updates.
  • Live Asset Data: Integrates with vendor platforms for accurate, real-time asset tracking.
  • User-to-Asset Mapping: Tracks asset assignments to end-users for accountability and visibility.
  • Lifecycle and Location Status: Manages asset lifecycle stages, including status updates for production, reprovisioning, and decommissioning.
Project Tracking and Business Review Reports: Tracks IT project milestones and provides regular reviews to assess IT support effectiveness.
  • Project Status Tracking: Monitors ongoing IT projects, including milestones, resource allocations, and deadlines.
  • Monthly Reports: Summarizes IT activity, SLA adherence, and resolution metrics.
  • IT Service Recommendations: Offers recommendations based on periodic reviews, aimed at improving IT support quality and efficiency.
Dashboards and Reporting: Offers detailed reporting tools to support oversight and performance evaluation.
  • Managerial Dashboards: Access for leadership to monitor metrics such as resolution times, resource usage, and performance data.
  • Custom Reports: Customer may generate reports tailored to specific IT metrics, SLA achievements, or compliance needs.
NOTE: SLA management terms apply as outlined in this Guide. Requests for modifications to SLA targets or escalation paths may require adjustments to the service scope.

Orchestration and Automation Platform

Implementation and facilitation of an Orchestration and Automation Platform by Onward, aimed at automating business and system processes within Customer’s managed IT environment. This platform evaluates and integrates compatible cloud services and systems to streamline operations, reduce manual effort, and enhance operational consistency. The platform functions under Onward’s management scope, aligning with DevOps principles and practices when applicable, as outlined in the DevOps Addendum.
Note: Automation solutions apply to systems and services within Onward’s managed scope. Identification, evaluation, and execution of automation opportunities require collaboration with Onward’s DevOps team to ensure compatibility and alignment with Customer’s operational needs.
Process Evaluation & Automation Identification: Identifies automation opportunities within Customer’s business and IT processes, focusing on compatibility with the Customer’s managed environment.
  • Automation Feasibility Assessment: Evaluates business and system processes to determine their potential for automation within the Customer’s IT infrastructure.
  • Integration with Managed Services: Ensures that proposed automations align with Onward’s supported infrastructure, cloud services, and policy standards.
  • Collaboration with DevOps for Complex Workflows: Complex automations requiring advanced workflows or multi-system integrations are executed in collaboration with Onward’s DevOps service.
Workflow Automation Implementation: Deploys rule-based workflows to automate recurring tasks, minimizing manual involvement and supporting operational efficiency.
  • Automated Task Execution: Configures automated workflows for routine tasks (e.g., exception handling, data synchronization) across approved environments.
  • Onboarding/Offboarding Automation: Automates key steps in employee onboarding and offboarding, streamlining account setup, permissions configuration, and device allocation for new hires. For offboarding, this includes secure access revocation, device reset, and data backup. This automation reduces manual work, enhances security, and ensures compliance with HR and IT policies.
  • Self-Service Automation: Publishes specific automations to the Customer’s ITSM portal, enabling authorized end-users to initiate actions independently.
  • Event-Triggered and Scheduled Automations: Enables event-triggered and scheduled automations for consistent workflow execution aligned with business timelines.
System and Cross-Platform Integration: Integrates supported applications and IT systems to synchronize data and execute orchestrated workflows.
  • Data Synchronization Across Systems: Automates data updates and ensures data consistency across systems under Onward’s management.
  • Application Compatibility and Integration: Facilitates seamless operations by integrating compatible business applications within the managed IT environment.
  • API-Based Data Ingestion: Leverages API connections to pull real-time data from approved platforms, enhancing accuracy and reliability.
Comprehensive Monitoring & Analytics: Provides visibility into active automations, offering insights for performance assessment and optimization.
  • Real-Time Workflow Tracking: Monitors workflow status, completion times, and task outcomes for operational oversight.
  • Performance Analytics: Tracks efficiency metrics, completion rates, and task durations to identify bottlenecks and optimization opportunities.
  • Customizable Reporting: Generates tailored reports on workflow performance, automation impact, and resource utilization to support decision-making.
End-User Access and Permissions: Manages access permissions, ensuring authorized users interact with published automations.
  • Role-Based Access Control: Configures permissions to restrict access to specific users based on their roles and responsibilities.
  • Audit Trail and Accountability: Logs user interactions with automation workflows, providing a record of task initiations and completions.
  • Training and Support for Authorized Users: Provides training and resources to ensure end-users engage with automations effectively and securely.
NOTE: This service requires Customer’s active cooperation by providing access to necessary systems and process details. Automations are restricted to Onward’s managed environment. Expansion of scope may incur additional fees or require updates to the existing service agreement.

Virtual Chief Information Officer (vCIO) / Virtual Chief Technology Officer (vCTO)

Implementation and facilitation of strategic IT leadership through a Virtual Chief Information Officer (vCIO) or Virtual Chief Technology Officer (vCTO). This service empowers Customer to align IT objectives with business goals, optimize technology investments, and leverage data-driven planning for growth and operational efficiency.IT Strategy Development: Collaborates with Customer’s executive team to develop an IT strategy aligned with business goals and industry standards.
  • IT Strategy Development: Collaborates with Customer’s executive team to craft an IT strategy aligned with business objectives and industry standards.
  • Technology Roadmap Planning: Develops a roadmap outlining critical projects, upgrades, and improvements aligned with evolving business needs.
  • Quarterly Business Reviews (QBRs) and Risk Assessments: Conducts QBRs and risk assessments to evaluate IT performance, identify vulnerabilities, and recommend necessary actions.
  • Budgeting and Forecasting: Provides strategic budgeting and financial forecasting to align technology investments with organizational goals.
  • Contract Management: Oversees technology-related contracts, including review, negotiation, and renewal planning, ensuring effective resource allocation.
  • Recommendation Planning: Delivers customized recommendations on technology improvements, vendor partnerships, and operational efficiencies based on performance and strategic goals.
  • IT Strategic Planning Platform Access: Provides access to Onward’s IT Strategic Planning Platform for real-time data on QBRs, budgeting forecasts, contract status, and risk assessments.
NOTE: Access to the IT Strategic Planning Platform requires an additional fee. This access enables Customer to utilize the platform for strategic insights, real-time updates, and proactive management of IT assets and contracts.
  • Vendor Management: Manages third-party vendor relationships to ensure compliance, performance, and alignment with Customer’s strategic goals.
  • Flexible Cadence Calls: Regular cadence calls are available on a weekly, biweekly, or monthly basis, based on Customer’s needs, to discuss operational adjustments, strategic progress, and immediate concerns.
  • Annual Strategic Review (Upon Request): Available upon Customer’s request, this review assesses the strategic alignment of IT services with business goals and discusses necessary large-scale initiatives or adjustments.
NOTE: Customer’s active participation in scheduled reviews and use of the IT Strategic Planning Platform is encouraged to enhance strategic alignment. Non-participation may result in missed improvement opportunities and impact IT strategy alignment.

Wireless Network Gateway (HaaS) Subscription

Implementation and facilitation of a managed wireless network gateway solution utilizing high-speed satellite-based units. This subscription provides options for Standard or High Performance models based on specific site connectivity needs and includes comprehensive storm servicing, mounting hardware, installation, and optional cloud-managed firewall/router or uplink aggregator for multi-unit setups. Ideal for remote sites without cable access and/or as a failover connection to a primary business-class circuit, this solution ensures seamless connectivity and redundancy.
  • Satellite-Based Unit Deployment: Supplies either Standard or High Performance satellite units tailored to site requirements, providing high-speed internet access in areas lacking traditional cable infrastructure.
  • Mounting Hardware and Installation: Professional installation includes mounting hardware to ensure optimal unit placement and secure, reliable connectivity at each site.
  • Storm Servicing: Proactive maintenance during adverse weather conditions, including hardware inspections and remote monitoring to minimize weather-related connectivity disruptions.
  • Cloud-Managed Firewall/Router (Optional): Offers a cloud-managed firewall or router for enhanced security, allowing centralized traffic control, access management, and policy enforcement.
  • Uplink Aggregation (Optional): Configures an uplink aggregator for sites requiring multiple units, delivering redundancy and increased bandwidth as needed.
  • Failover Connectivity for Business-Class Circuits: Configures the unit as a failover connection to existing business-class circuits, providing reliable backup connectivity in the event of primary circuit downtime.
  • Secure Remote Management and Monitoring: Centralized management of network configurations and unit performance, with real-time status alerts and proactive troubleshooting.
  • Real-Time Network Health Monitoring: Continuous monitoring of network performance, including connectivity status and immediate alerts for any issues.
  • Comprehensive Site Assessment: Conducts an assessment to determine the optimal configuration, equipment placement, and installation strategy to align with specific site requirements.
NOTE: Onward will handle deployment, mounting, and ongoing maintenance of the wireless network gateway solution, including satellite units and related equipment to ensure reliable connectivity. Additional site assessments, optional configurations, or specific customer requirements may incur additional charges based on the service scope.

Optional Add-Ons

  • Guest Network Configuration: Establishes a secure guest network to manage visitor access while maintaining the integrity of the primary network.
  • Hardware and Software Updates: Regular firmware updates for the satellite unit, firewall, router, and associated devices, ensuring compliance with the latest security and performance standards.
  • Network Expansion Services: Enables expansion with additional units or components as Customer’s needs evolve, configured according to established security and performance protocols.
NOTE: This Wireless Network Gateway Subscription covers only devices and services within Onward’s management scope. Connectivity or security issues related to third-party devices or configurations outside of this scope are not covered by Onward’s responsibilities within this subscription.

Fleet Management

Implementation and facilitation of a comprehensive Fleet Management solution that enables real-time GPS tracking for a diverse set of assets, including vehicles, boats, trailers, and mobile devices. This service includes OBD-II tracking devices for vehicles, compatible fleet telematic units for specialized assets, and secure mobile applications for iOS and Android devices managed under Onward’s Mobile Device Management (MDM) platform. Fleet Management delivers location tracking, route optimization, and operational insights to support efficient fleet utilization, compliance, and security.
Features
  • Real-Time GPS Tracking: Provides continuous location tracking for vehicles, boats, trailers, and managed iOS/Android devices, delivering an integrated view of all fleet and mobile assets in motion.
  • Diverse Asset Compatibility: Includes OBD-II devices for standard vehicle diagnostics and fleet telematic tracking units for specialized assets (e.g., boats, trailers), ensuring comprehensive tracking across the fleet.
  • Mobile Application for Managed Devices: Extends tracking capabilities to iOS and Android devices, allowing managers to monitor team locations and usage of mobile devices within the fleet framework.
  • Route Optimization: Recommends efficient routes based on real-time data, reducing fuel consumption, travel time, and enhancing overall fleet productivity.
  • Geo-Fencing Capabilities: Enables customizable geo-fenced zones with alerts for entry and exit, improving security and supporting compliance for assets in sensitive or restricted locations.
  • Activity Monitoring: Records data on asset usage, including location, speed, idle time, and duration of stops, supporting operational insights and safety tracking.
  • Historical Data & Reporting: Stores detailed trip history and utilization data for reporting on asset efficiency, compliance, and driver/operator patterns.
  • Maintenance Alerts: Provides automated reminders based on mileage, hours of use, or specific conditions, helping prevent costly repairs and extend asset lifespan.
  • Driver and Operator Behavior Analytics: Monitors behaviors such as speeding, hard braking, and rapid acceleration to support safety policies and reduce risk.
  • Integrated Mobile Device Tracking: Allows iOS and Android devices to be tracked as part of the fleet under Onward’s MDM, with secure data access and device permissions to ensure compliance with organizational security policies.
NOTE: Fleet Management encompasses GPS tracking for vehicles, boats, trailers, and compatible mobile devices managed by Onward. Additional or custom assets may require special integration agreements or incur extra fees.
  • Enhanced Analytics & Dashboards: Offers advanced dashboards with detailed insights into fleet metrics, usage patterns, and cost analysis.
  • Third-Party System Integration: Supports integration with logistics or asset management systems, consolidating fleet data across platforms for unified management.
  • Custom Alerts and Notifications: Configurable alerts for specific events, including unauthorized usage, off-hours operation, or prolonged idle times.
NOTE: Fleet Management services are limited to Onward-managed assets. Requests to add non-standard assets or integrate additional third-party systems may require additional fees or agreements.

VOIP Management

Implementation and facilitation of a robust cloud-based VOIP management solution, designed to enhance communication, streamline administration, and provide data-driven insights for quality improvement. This service encompasses full deployment, user management, and proactive monitoring of VOIP systems across desktop, mobile, and web platforms, creating a scalable communication framework tailored to diverse operational needs. An optional Quality Management and Analytics platform is also available to offer advanced insights and detailed performance tracking.
  • Cloud-Based VOIP System Deployment: Deploys a cloud-based VOIP solution that supports voice, video, and messaging capabilities across multiple access points, including desktop, mobile, and web applications, for seamless, flexible communication.
  • User Configuration and Management: Manages all aspects of VOIP user setup and access, including number assignments, extension configurations, and permission settings, tailored to the specific communication requirements of the organization.
  • Device Flexibility: Offers support for multiple device types, including softphones, desktop handsets, and mobile applications, ensuring flexible communication options that adapt to users’ preferences and organizational needs.
  • Automated Call Routing and IVR Setup: Configures sophisticated call routing rules and auto-attendant functionalities, including IVR systems, call forwarding, and priority call routing to optimize call flow and minimize disruptions.
  • Integration with Collaboration Platforms: Seamlessly integrates with productivity tools and collaboration platforms, enhancing workflows and unifying communications within the existing IT infrastructure.
  • Scalability and Adaptability: Designed to support remote, hybrid, and in-office environments, with capabilities to adjust user counts and service features as the organization grows or changes.
  • Standard Analytics and Reporting: Provides valuable metrics and insights on call patterns, call duration, and usage to aid performance monitoring, resource planning, and operational oversight.
  • Security and Compliance: Implements secure data encryption protocols, both in transit and at rest, ensuring compliance with relevant voice and communication data standards across industries.
  • Quality of Service (QoS) Monitoring: Continuously monitors call quality parameters such as bandwidth usage and latency to maintain high audio and video standards, ensuring a consistent user experience.
NOTE: VOIP Management & Analytics services apply exclusively to cloud-based VOIP systems and do not cover legacy PBX or analog systems. Certain features may necessitate additional training for administrators or subscription adjustments, depending on the customer’s specific requirements. There are additional terms related to the VoIP service, including your use of E911 features, toward the end of this Services Guide. Please read them carefully. You may be required to sign an additional consent form indicating your understanding and acceptance of the limitations of 911 dialing using the VoIP services.

Optional Add-On: Quality Management and Analytics Platform

  • Enhanced Quality Management: Deploys a comprehensive Quality Management platform that tracks communication-related key performance indicators (KPIs) to monitor quality, call handling, and user satisfaction levels.
  • Advanced Analytics and Reporting: Provides detailed call analytics, with access to custom dashboards and department-specific reporting, allowing for granular performance assessments and actionable insights.
  • Customizable Performance Metrics: Enables the configuration of specific quality metrics to monitor call performance, service levels, and productivity benchmarks, empowering organizations to set and track targeted quality standards.
NOTE: The Quality Management and Analytics Platform is available as an optional add-on and may require additional licensing or subscriptions. Please contact Onward for further details on pricing and customization options.

Web Development and Hosting

Implementation and facilitation of a reliable, scalable website hosting and development solution from our designated Third Party Provider. This service includes managed hosting, ongoing maintenance, and technical support to ensure your website (“Website”) remains operational, updated, and compliant with security standards. The Website will be available on a 24×7 basis, excluding scheduled downtime or force majeure events. Each Website is hosted on a shared server environment, with a unique address assigned to each customer.
  • Web Development and Technical Maintenance: Provides ongoing maintenance of the Website, including plugin updates, configuration adjustments, and support for technical integrations (e.g., APIs, third-party software). This service ensures that the Website operates efficiently and remains compatible with necessary integrations. Creative design work, such as custom graphics or website layout redesign, is outside the scope of this service and will be provided through a designated third-party.
  • Migration of Servers: As part of regular operations, Onward or our designated Third Party Provider may migrate the servers hosting the Website to maintain optimal performance and security. This migration process will not impact the continuity of the hosting services; however, due to the potential for migration, a permanent or dedicated IP address is not guaranteed.
  • Administration: Access is provided to a secure dashboard where customers may make configuration adjustments to the hosted environment. We strongly advise customers to refrain from making changes without Onward’s guidance, as Onward cannot assume responsibility for issues arising from customer-directed adjustments. Onward will remediate issues caused by customer changes only if made under our guidance or written direction.
  • Resource and Load Balancing: Bandwidth is shared across all hosted websites and is monitored to ensure fair distribution among all Onward customers. Onward reserves the right to load-balance bandwidth or restrict access if a customer’s website activity disproportionately impacts the network, creating potential limitations for other users.
  • Backup Services: Daily backups are conducted as part of the Standard Backup Service, covering basic data protection for the Website. This backup is intended as a standard security measure and does not replace a comprehensive backup and disaster recovery solution. Customers are encouraged to maintain a separate backup and recovery solution for more extensive protection.
  • Storage and Security: Onward, alongside our third-party providers, applies industry-standard security measures to safeguard the Website and hosted environment against unauthorized access. While Onward takes reasonable precautions, no system can guarantee absolute security, and we cannot warrant that the hosted environment will remain entirely free from unauthorized access or malware.
NOTE: Customer, as well as any visitors to the Website, must comply with our Acceptable Use Policy, located at the end of this Services Guide. This policy outlines acceptable usage guidelines and restrictions to maintain service quality and security across Onward’s managed hosting environment.

Print Management

Implementation and facilitation of a Print Management solution in collaboration with a designated Third Party Provider. This service covers the logical configuration, network integration, and deployment of Print Management Platforms by Onward. The Third Party Provider is responsible for the hardware provisioning, physical servicing, and management of consumables, ensuring seamless and efficient print operations.
  • Centralized Print Management: Implements centralized control over print activities, including monitoring, user access, and secure print release, through supported Print Management Platforms.
  • Network Integration and Cloud Printing: Configures print servers and integrates cloud solutions like Microsoft Universal Print to support secure, flexible printing across on-premise and cloud environments.
  • Remote Monitoring and Usage Analytics: Provides real-time tracking of device status, usage, and performance metrics, allowing proactive management and consumable planning.
  • End-User and IT Support: Assists users with accessing print services, resolving permissions, and addressing connectivity issues as part of Onward’s support scope.
  • Onward’s Responsibilities
  • Logical and Network Configuration: Configures the network settings, print servers, and access controls for secure, efficient print operations across all managed workstations and cloud environments.
  • Specialty Printer Configuration: Directly provisions and configures specialty printers, such as label and unique format printers, to meet Customer’s operational needs.
  • Print Management Platform Implementation: Deploys and configures print management solutions, such as PaperCut and PrinterLogic, to enable centralized control over permissions, print release, and user access.
  • Cloud Printing Solutions: Implements Microsoft Universal Print for eligible environments, providing cloud-based printing capabilities that eliminate the need for on-premise print servers.
  • Integration with Cost Recovery Systems: Sets up cost recovery features within print management platforms to track and allocate print expenses by user or department, supporting budgeting and resource management.
  • Third Party Provider’s Responsibilities
    • Hardware Provisioning and Physical Maintenance: Supplies and services the multi-function printers, 3D printers, and imaging devices, performing routine maintenance, repairs, and any physical device servicing.
    • Consumable Management: Monitors usage levels for consumables (e.g., ink, toner, and paper) and manages refills to ensure uninterrupted print service.
    • Hardware and Device Support: Provides support for physical device issues beyond logical or network-related configurations.

DevOps BI & Data Integration

Implementation and facilitation of a DevOps solution from Onward, designed to automate, integrate, and streamline software development, deployment, and data management processes. Onward’s DevOps service incorporates industry-standard tools to enable continuous delivery, version control, and collaboration, while also providing comprehensive Data Integration & Business Intelligence (BI) capabilities to enhance data-driven decision-making. Our services cover the entire lifecycle of DevOps, from planning and development to maintenance, ensuring secure and scalable solutions.
  • Data Integration & Business Intelligence (BI)
    • Data Ingestion and ETL Processes: Onward configures and manages secure data pipelines for data ingestion, transformation, and integration from multiple sources, ensuring data accuracy and consistency.
    • Business Intelligence Dashboards and Reporting: Onward implements BI dashboards and reporting solutions to provide real-time insights, customized metrics, and on-demand visualizations that support strategic decision-making.
    • ERP System Integration: Onward facilitates ERP integration with other business systems, providing performance monitoring and routine maintenance to ensure consistent data flow.
    • Data Security and Governance: Onward applies security measures and governance protocols to ensure data integrity, compliance, and controlled access across platforms.
  • Azure DevOps Management
    • CI/CD Pipelines Configuration: Onward configures and manages Continuous Integration/Continuous Delivery (CI/CD) pipelines within Azure DevOps to automate the build, testing, and deployment cycles. This enhances speed, reliability, and stability in releasing software updates.
    • Project and Sprint Management: Onward assists in organizing and managing project backlogs, sprint planning, and task assignments, using Azure DevOps Boards to streamline development workflows and enhance team productivity.
    • Automated Testing and Quality Assurance: Onward implements and monitors automated testing procedures within Azure DevOps to ensure code quality and application performance standards are met throughout the development lifecycle.
    • Release Management and Versioning: Onward establishes and maintains a versioned release process using Azure DevOps, providing clear visibility into release stages and deployment histories for improved change control.
  • Git-Based Version Control
    • Repository Management: Onward configures and manages Git repositories, implementing branch strategies and access controls to maintain secure, efficient version control and collaboration.
    • Code Review and Collaboration: Onward enables structured code review workflows within Git, including pull requests and approval protocols, to enhance collaboration and maintain code quality.
    • Branching Strategies and Workflow Customization: Onward implements branching strategies tailored to the project’s needs (e.g., feature branching, Gitflow), facilitating structured and efficient development workflows.
    • Integration with CI/CD Pipelines: Onward integrates Git repositories with CI/CD pipelines to ensure code changes are automatically tested and deployed, aligning with DevOps best practices.
  • Core DevOps Services
    • Infrastructure as Code (IaC): Onward configures infrastructure through code, enabling repeatable environment setups and version control to support scalability and consistency.
    • Monitoring and Feedback Loops: Onward provides continuous monitoring and feedback, supporting rapid detection and resolution of issues to maintain performance. Dashboards and analytics are made accessible to authorized stakeholders.
    • Collaboration and Governance: Onward facilitates collaboration between development and IT operations teams, establishing protocols, governance standards, and KPIs for performance tracking.
NOTE: Not all listed services may be included in the standard DevOps engagement. Services are implemented selectively and tailored to align with the Customer’s environment and business requirements. For further details on specific responsibilities and expectations, refer to the DevOps Addendum. Additional requests outside the defined scope may require adjustments to service costs.

Policies and Procedures Applicable to Services

Software Licensing: All software provided to you by or through Onward is licensed, not sold, to you (“Software”). In addition to any Software-related requirements described in Onward’s Master Services Agreement, Software may also be subject to end user license agreements (EULAs), acceptable use policies (AUPs), and other restrictions all of which must be strictly followed by you and any of your authorized users.
 
When installing/implementing software licenses in the managed environment or as part of the Services, we may accept (and you agree that we may accept) any required EULAs or AUPs on your behalf. You should assume that all Software has an applicable EULA and/or AUP to which your authorized users and you must adhere. If you have any questions or require a copy of the EULA or AUP, please contact us.
 
Hardware as a Service (HaaS): The following applies to all hardware, devices, and accessories that are provided to you on a “hardware as a service” basis (“HaaS Equipment”).
 
• Deployment. We will deploy HaaS Equipment within the timeframe stated in the Quote, provided that you promptly provide all information that we reasonably request from you to complete deployment. This deployment guaranty does not apply to any software, other managed services, or hardware devices other than the HaaS Equipment. In addition, this deployment time frame may be extended as necessary to accommodate delays that are outside of our reasonable control, such as embargoes, labor or supply chain shortages, or other force majeure events. If you wish to delay the deployment of the HaaS Equipment, then you may do so if you give us written notice of your election to delay no later than five (5) days following the date you sign the Quote. Deployment shall not extend beyond two (2) months following the date on which you sign the Quote. You will be charged at the rate of fifty percent (50%) of the monthly recurring fees for the HaaS-related services during the period of delay. Following deployment, we will charge you the full monthly recurring fee (plus other usage fees as applicable) for the full term indicated in the Quote.
 
  • Repair/replacement of HaaS Equipment. Onward will endeavor to repair or replace HaaS Equipment within five (5) business days following the business day on which the applicable problem is identified by, or reported to, Onward and has been determined by Onward to be incapable of being remediated remotely. This warranty does not include the time required to rebuild your system, such as the time required to configure a replacement device, rebuild a RAID array, reload the operating system, reload and configure applications, and/or restore from backup (if necessary).
 
• Technical Support for HaaS Equipment. We will provide technical support for HaaS Equipment in accordance with the Service Levels listed in this Services Guide.
 
• Usage. You will use all HaaS Equipment for your internal business purposes only. You shall not sublease, sublicense, rent or otherwise make the HaaS Equipment available to any third party without our prior written consent. You agree to refrain from using the HaaS Equipment in a manner that unreasonably or materially interferes with our other hosted equipment or hardware, or in a manner that disrupts or that is likely to disrupt the services that we provide to our other Customers. We reserve the right to throttle or suspend your access and/or use of the HaaS Equipment if we believe, in our sole but reasonable judgment, that your use of the HaaS Equipment violates the terms of the Quote, this Services Guide, or the Agreement.
 
• Return of HaaS Equipment. Unless we expressly direct you to do so, you shall not remove or disable, or attempt to remove or disable, any software agents installed in the HaaS Equipment. Doing so could result in network vulnerabilities and/or the continuation of license fees for the software agents for which you will be responsible, and/or the requirement that we remediate the situation at our then-current hourly rates, for which you will also be responsible. Within ten (10) days after the termination of HaaS-related Services, Customer will provide Onward access to the premises at which the HaaS Equipment is located so that all such equipment may be retrieved and removed by us. If you fail to provide us with timely access to the HaaS Equipment or if the equipment is returned damaged (normal wear and tear excepted), then we will have the right to charge you, and you hereby agree to pay, the replacement value of all such unreturned or damaged equipment.
DevOps. If DevOps (or “DevOps as a Service”) is listed in the Quote, then we will provide such services in the scope, manner, and timing described in the DevOps Addendum, below.
 
Covered Environment. Services will be applied to the number of devices indicated in the Quote (“Covered Hardware”). The list of Covered Hardware may be modified by mutual consent (email is sufficient for this purpose); however, we reserve the right to modify the list of Covered Hardware at any time if we discover devices that were not previously included in the list of Covered Hardware and which are receiving Services, or as necessary to accommodate changes to the quantity of Covered Hardware.
Unless otherwise stated in the Quote, Covered Devices will only include technology assets (such as computers, servers, and networking equipment) owned by Customer’s organization. As an accommodation, Onward may provide guidance in connecting a personal device to Customer’s organization’s technology, but support of personal devices is generally not included in the Scope of Services.
If the Quote indicates that the Services are billed on a “per user” basis, then the Services will be provided for up to two (2) Business Devices used by the number of users indicated in the Quote. A “Business Device” is a device that (i) is owned or leased by Customer and used primarily for business, (ii) is regularly connected to Customer’s managed network, and (iii) has installed on it a software agent through which we (or our designated Third Party Providers) can monitor the device.
 
We will provide support for any software applications that are licensed through us. Such software (“Supported Software”) will be supported on a “best effort” basis only and any support required beyond Level 2-type support will be facilitated with the applicable software vendor/producer. Coverage for non-Supported Software is outside of the scope of the Quote and will be provided to you on a “best-effort” basis and a time and materials basis with no guarantee of remediation. Should our technicians provide you with advice concerning non-Supported Software, the provision of that advice should be viewed as an accommodation and not an obligation to you.
 
If we are unable to remediate an issue with non-Supported Software, then you will be required to contact the manufacturer/distributor of the software for further support. Please note: Manufacturers/distributors of such software may charge fees, some of which may be significant, for technical support; therefore, we strongly recommend that you maintain service or support contracts for all non-Supported Software (“Service Contract”). If you request that we facilitate technical support for non-Supported Software and if you have a Service Contract in place, our facilitation services will be provided to you at our then-current hourly rates.
 
In this Services Guide, Covered Hardware and Supported Software will be referred to as the “Environment” or “Covered Equipment.”
Physical Locations Covered by Services. Services will be provided remotely unless, in our discretion, we determine that an onsite visit is required. Onward visits will be scheduled in accordance with the priority assigned to the issue (below) and are subject to technician availability. Unless we agree otherwise, all onsite Services will be provided at Customer’s primary business location. Additional fees may apply for onsite visits: Please review the Service Level section below for more details.
 
Minimum Requirements / Exclusions. The scheduling, fees and provision of the Services are based upon the following assumptions and minimum requirements, all of which must be provided/maintained by Customer at all times:
• Server hardware must be under current warranty coverage
• All equipment with Microsoft Windows® operating systems must be running then-currently supported versions of such software and have all the latest Microsoft service packs and critical updates installed.
• All software must be genuine, licensed, and vendor- or OEM-supported.
• Server file systems and email systems (if applicable) must be protected by licensed and up-to-date virus protection software.
• The managed environment must have a currently licensed, vendor-supported server-based backup solution that can be monitored.
• All wireless data traffic in the managed environment must be securely encrypted.
• All servers must be connected to working UPS devices.
• Recovery coverage assumes data integrity of the backups or the data stored on the backup devices. We do not guarantee the integrity of the backups or the data stored on the backup devices. Server restoration will be to the point of the last successful backup.
• Customer must provide all software installation media and key codes in the event of a failure.
• Any costs required to bring the Environment up to these minimum standards are not included in this Services Guide.
  • Customer must provide us with exclusive administrative privileges to the Environment.
  • Customer must not affix or install any accessory, addition, upgrade, equipment, or device on to the firewall, server, or NAS appliances (other than electronic data) unless expressly approved in writing by us.
 
Exclusions. Services that are not expressly described in the Quote will be out of scope and will not be provided to Customer unless otherwise agreed, in writing, by Onward. Without limiting the foregoing, the following services are expressly excluded, and if required to be performed, must be agreed upon by Onward in writing:
  • Support for applications, platforms, and/or operating systems that are not present in the Environment at the commencement of the Services.
  • Support for applications, platforms, and/or operating systems that are not supported by their respective manufacturers.
  • Customization of third party applications, or programming of any kind.
  • Support for operating systems, applications, or hardware no longer supported by the manufacturer.
  • Data/voice wiring or cabling services of any kind.
  • Battery backup replacement.
  • Equipment relocation.
  • The cost to bring the managed environment
  • The cost of repairs to hardware or any supported equipment or software, or the costs to acquire parts or equipment, or shipping charges of any kind.
Service Levels. Automated monitoring is provided on an ongoing (i.e., 24x7x365) basis. Response, repair, and/or remediation services (as applicable) will be provided only during our business hours (currently M-F, 8 AM – 5 PM Eastern Time, excluding legal holidays and Onward-observed holidays as listed below), unless otherwise specifically stated in the Quote or as otherwise described below.
 
We will respond to problems, errors, or interruptions in the provision of the Services in the timeframe(s) described below. Severity levels will be determined by Onward in our discretion after consulting with Customer. All remediation services will initially be attempted remotely; Onward will provide onsite service only if remote remediation is ineffective and, under all circumstances, only if covered under the Service plan selected by Customer.
 
Trouble / Severity
Response Time
Critical / Service Not Available
(e.g., all users and functions unavailable)
 
Response within two (2) business hours after notification.
 
Significant Degradation
(e.g., large number of users or business critical functions affected)
 
Response within four (4) business hours after notification.
 
Limited Degradation
(e.g., limited number of users or functions affected, business process can continue).
 
Response within eight (8) business hours after notification.
 
Small Service Degradation
(e.g., business process can continue, one user affected).
Response within two (2) business days after notification.
Long Term Project, Preventative Maintenance
Response within four (4) business days after notification.

* All time frames are calculated as of the time that we are notified of the applicable issue / problem by Customer through our designated support portal, help desk, or by telephone at the telephone number listed in the Quote. Notifications received in any manner other than described herein may result in a delay in the provision of remediation efforts.

Support During Off-Hours/Non-Business Hours: Technical support provided outside of our normal business hours is offered on a case-by-case basis and is subject to technician availability. Response times are not guaranteed for off-hours/non-business hours services. If Onward agrees to provide off-hours/non-business hours support (“Non-Business Hour Support”), and unless you and Onward agree otherwise, such support will be provided on a time and materials basis (which is not covered under any Service plan), and will be billed to Customer at a flat rate of $395/incident, regardless of duration.
Onward-Observed Holidays: Onward observes the following holidays:
  • Memorial Day
  • Independence Day
  • Labor Day
  • Thanksgiving Day
  • The day following Thanksgiving Day
  • Christmas Eve
  • Christmas Day
  • New Year’s Eve
  • New Year’s Day
 
Service Credits: Our service level target is 90% as measured over a calendar month (“Target Service Level”). If we fail to adhere to the Target Service Level and Customer timely brings that failure to our attention in writing (as per the requirements of our Master Services Agreement), then Customer will be entitled to receive a pro-rated service credit equal to 1/30 of that calendar month’s recurring service fees (excluding hard costs, licenses, etc.) for each day on which the Target Service Level is missed. Under no circumstances shall credits exceed 30% of the total monthly recurring service fees under an applicable Quote.
Fees. The fees for the Services will be as indicated in the Quote.
 
Reconciliation. Fees for certain Third Party Services that we facilitate or resell to you may begin to accrue prior to the “go-live” date of other applicable Services. (For example, Microsoft Azure or AWS-related fees begin to accrue on the first date on which we start creating and/or configuring certain hosted portions of the Environment; however, the Services that rely on Microsoft Azure or AWS may not be available to you until a future date). You understand and agree that you will be responsible for the payment of all fees for Third Party Services that are required to begin prior to the “go-live” date of Services, and we reserve the right to reconcile amounts owed for those fees by including those fees on your monthly invoices.
 
Changes to Environment. Initially, you will be charged the monthly fees indicated in the Quote. Thereafter, if the managed environment changes, or if the number of authorized users accessing the managed environment changes, then you agree that the fees will be automatically and immediately modified to accommodate those changes.
 
Travel Time. If onsite services are provided, we will travel up to 45 minutes from our office to your location at no charge. Time spent traveling beyond 45 minutes (e.g., locations that are beyond 45 minutes from our office, occasions on which traffic conditions extend our drive time beyond 45 minutes one-way, etc.) will be billed to you at our then current hourly rates. In addition, you will be billed for all tolls, parking fees, and related expenses that we incur if we provide onsite services to you.
 
Appointment Cancellations. You may cancel or reschedule any appointment with us at no charge by providing us with notice of cancellation at least one business day in advance. If we do not receive timely a notice of cancellation/re-scheduling, or if you are not present at the scheduled time or if we are otherwise denied access to your premises at a pre-scheduled appointment time, then you agree to pay us a cancellation fee equal to two (2) hours of our normal consulting time (or non-business hours consulting time, whichever is appropriate), calculated at our then-current hourly rates.
 
Access Licensing. One or more of the Services may require us to purchase certain “per seat” or “per device” licenses (often called “Access Licenses”) from one or more Third Party Providers. (Microsoft “New Commerce Experience” licenses as well as Cisco Meraki “per device” licenses are examples of Access Licenses.) Access Licenses cannot be canceled once they are purchased and often cannot be transferred to any other customer. For that reason, you understand and agree that regardless of the reason for termination of the Services, fees for Access Licenses are non-mitigatable and you are required to pay for all applicable Access Licenses in full for the entire term of those licenses. Provided that you have paid for the Access Licenses in full, you will be permitted to use those licenses until they expire.
 
Term; Termination. The Services will commence, and billing will begin, on the date indicated in the Quote (“Commencement Date”) and will continue through the initial term listed in the Quote (“Initial Term”). We reserve the right to delay the Commencement Date until all onboarding/transition services (if any) are completed, and all deficiencies / revisions identified in the onboarding process (if any) are addressed or remediated to Onward’s satisfaction.
The Services will continue through the Initial Term until terminated as provided in the Agreement, the Quote, or as indicated in this Service Guide (the “Service Term”).
Per Seat/Per Device Licensing: Regardless of the reason for the termination of the Services, you will be required to pay for all per seat or per device licenses that we acquire on your behalf. Please see “Access Licensing” in the Fees section above for more details.
Removal of Software Agents; Return of Firewall & Backup Appliances: Unless we expressly direct you to do so, you will not remove or disable, or attempt to remove or disable, any software agents that we installed in the managed environment or any of the devices on which we installed software agents. Doing so without our guidance may make it difficult or impracticable to remove the software agents, which could result in network vulnerabilities and/or the continuation of license fees for the software agents for which you will be responsible, and/or the requirement that we remediate the situation at our then-current hourly rates, for which you will also be responsible. Depending on the particular software agent and the costs of removal, we may elect to keep the software agent in the managed environment but in a dormant and/or unused state.
Within ten (10) days after being directed to do so, you must remove, package and ship, at your expense and in a commercially reasonable manner, all hardware, equipment, and accessories leased, loaned, rented, or otherwise provided to you by Onward “as a service.” If you fail to timely return all such equipment to us, or if the equipment is returned to us damaged (normal wear and tear excepted), then we will have the right to charge you, and you hereby agree to pay, the replacement value of all such unreturned or damaged equipment.
Offboarding. Subject to the requirements in the MSA, Onward will off-board Customer from Onward’s services by performing one or more of the following:
• Removal / disabling of monitoring agents in the Environment.
• Removal / disabling of endpoint software from the Environment.
• Removal / disabling of Microsoft 365 from the Environment (unless the licenses for Microsoft 365 are being transferred to your incoming provider; please speak to your technician for details.)
• Termination of SQL or Remote Desktop licenses provided by Onward.
• Removal of credentials from the Environment.
• Removal of backup software from the Environment.

Additional Policies

The following additional policies (“Policies”) apply to Services that we provide or facilitate under a Quote. By accepting a Service for which one or more of the Policies apply, you agree to the applicable Policy.

Authenticity

Everything in the managed environment must be genuine and licensed, including all hardware, software, etc. If we ask for proof of authenticity and/or licensing, you must provide us with such proof. All minimum hardware or software requirements as indicated in a Quote or this Services Guide (“Minimum Requirements”) must be implemented and maintained as an ongoing requirement of us providing the Services to you.

Monitoring Services; Alert Services

Unless otherwise indicated in the Quote, all monitoring and alert-type services are limited to detection and notification functionalities only. Monitoring levels will be set by Onward, and Customer shall not modify these levels without our prior written consent.

Configuration of Third Party Services

Certain third party services provided to you under a Quote may provide you with administrative access through which you could modify the configurations, features, and/or functions (“Configurations”) of those services. However, any modifications of Configurations made by you without authorization could disrupt the Services and/or cause a significant increase in the fees charged for those third party services. For that reason, we strongly advise you to refrain from changing the Configurations unless we authorize those changes. You will be responsible for paying any increased fees or costs arising from or related to changes to the Configurations.

Modification of Environment

Changes made to the Environment without our prior authorization or knowledge may have a substantial, negative impact on the provision and effectiveness of the Services and may impact the fees charged under the Quote. You agree to refrain from moving, modifying, or otherwise altering any portion of the Environment without our prior knowledge or consent. For example, you agree to refrain from adding or removing hardware from the Environment, installing applications on the Environment, or modifying the configuration or log files of the Environment without our prior knowledge or consent. Unauthorized changes, configurations made contrary to Onward’s recommendations, or changes implemented at Customer’s explicit request despite Onward’s advisement against them may result in affected systems being excluded from Onward’s support scope. In these cases, Onward will not be liable for the results or outcomes of such modifications. Any work required to restore or remediate issues arising from these changes will incur additional costs. Compliance with Onward’s security and management protocols is essential for maintaining the integrity and reliability of services. Failure to adhere to these protocols may delay service resolution and increase costs associated with the Services.

Anti-Virus; Anti-Malware

Our anti-virus / anti-malware solution will generally protect the Environment from becoming infected with new viruses and malware (“Malware”); however, Malware that exists in the Environment at the time that the security solution is implemented may not be capable of being removed without additional services, for which a charge may be incurred. We do not warrant or guarantee that all Malware will be detected, avoided, or removed, or that any data erased, corrupted, or encrypted by Malware will be recoverable. The effectiveness of Onward’s security measures, including anti-virus and anti-malware solutions, depends on Customer’s active compliance with Onward’s recommendations, guidelines, and security protocols. Failure to adhere to these recommendations may reduce service effectiveness and incur additional costs if recovery services are necessary. To improve security awareness, you agree that Onward or its designated third party affiliate may transfer information about the results of processed files, information used for URL reputation determination, security risk tracking, and statistics for protection against spam and malware. Any information obtained in this manner does not and will not contain any personal or confidential information.

Breach/Cyber Security Incident Recovery

Unless otherwise expressly stated in the Quote, the scope of the Services does not include the remediation and/or recovery from a Security Incident (defined below). In the event of a Security Incident, Customer’s adherence to Onward’s recommended security protocols and configurations will play a crucial role in minimizing incident response times and associated costs. Additional fees will apply for recovery efforts necessitated by non-compliance with Onward’s security protocols, and Onward’s ability to remediate such incidents may be impacted. Such services, if requested by you, will be provided on a time and materials basis under our then-current hourly labor rates. Given the varied number of possible Security Incidents, we cannot and do not warrant or guarantee (i) the amount of time required to remediate the effects of a Security Incident (or that recovery will be possible under all circumstances), or (ii) that all data or systems impacted by the incident will be recoverable or remediated. For the purposes of this paragraph, a Security Incident means any unauthorized or impermissible access to or use of the Environment, or any unauthorized or impermissible disclosure of Customer’s confidential information (such as user names, passwords, etc.), that (i) compromises the security or privacy of the information or applications in, or the structure or integrity of, the managed environment, or (ii) prevents normal access to the managed environment, or impedes or disrupts the normal functions of the managed environment.

Environmental Factors

Exposure to environmental factors, such as water, heat, cold, or varying lighting conditions, may cause installed equipment to malfunction. Unless expressly stated in the Quote, we do not warrant or guarantee that installed equipment will operate error-free or in an uninterrupted manner, or that any video or audio equipment will clearly capture and/or record the details of events occurring at or near such equipment under all circumstances.

Fair Usage Policy

Our Fair Usage Policy (“FUP”) applies to all services that are described or designated as “unlimited” or which are not expressly capped in the number of available usage hours per month. An “unlimited” service designation means that, subject to the terms of this FUP, you may use the applicable service as reasonably necessary for you to enjoy the use and benefit of the service without incurring additional time-based or usage-based costs. However, unless expressly stated otherwise in the Quote, all unlimited services are provided during our normal business hours only and are subject to our technicians’ availabilities, which cannot always be guaranteed. In addition, we reserve the right to assign our technicians as we deem necessary to handle issues that are more urgent, critical, or pressing than the request(s) or issue(s) reported by you. Consistent with this FUP, you agree to refrain from (i) creating urgent support tickets for non-urgent or non-critical issues, (ii) requesting excessive support services that are inconsistent with normal usage patterns in the industry (e.g., requesting support in lieu of training), (iii) requesting support or services that are intended to interfere, or may likely interfere, with our ability to provide our services to our other customers.

Hosted Email

You are solely responsible for the proper use of any hosted email service provided to you (“Hosted Email”). Hosted Email solutions are subject to acceptable use policies (“AUPs”), and your use of Hosted Email must comply with those AUPs. In all cases, you agree to refrain from uploading, posting, transmitting or distributing (or permitting any of your authorized users of the Hosted Email to upload, post, transmit or distribute) any prohibited content, which is generally content that (i) is obscene, illegal, or intended to advocate or induce the violation of any law, rule or regulation, or (ii) violates the intellectual property rights or privacy rights of any third party, or (iii) mischaracterizes you, and/or is intended to create a false identity or to otherwise attempt to mislead any person as to the identity or origin of any communication, or (iv) interferes or disrupts the services provided by Onward or the services of any third party, or (v) contains Viruses, trojan horses or any other malicious code or programs. In addition, you must not use the Hosted Email for the purpose of sending unsolicited commercial electronic messages (“SPAM”) in violation of any federal or state law. Onward reserves the right, but not the obligation, to suspend Customer’s access to the Hosted Email and/or all transactions occurring under Customer’s Hosted Email account(s) if Onward believes, in its discretion, that Customer’s email account(s) is/are being used in an improper or illegal manner.

Backup (BDR) Services

All data transmitted over the Internet may be subject to malware and computer contaminants such as viruses, worms and trojan horses, as well as attempts by unauthorized users, such as hackers, to access or damage Customer’s data. Neither Onward nor its designated affiliates will be responsible for the outcome or results of such activities.
BDR services require a reliable, always-connected internet solution. Data backup and recovery time will depend on the speed and reliability of your internet connection. Internet and telecommunications outages will prevent the BDR services from operating correctly. In addition, all computer hardware is prone to failure due to equipment malfunction, telecommunication-related issues, etc., for which we will be held harmless. Due to technology limitations, all computer hardware, including communications equipment, network servers and related equipment, has an error transaction rate that can be minimized, but not eliminated. Onward cannot and does not warrant that data corruption or loss will be avoided, and Customer agrees that Onward shall be held harmless if such data corruption or loss occurs. Customer is strongly advised to keep a local backup of all of stored data to mitigate against the unintentional loss of data.

Procurement

Equipment and software procured by Onward on Customer’s behalf (“Procured Equipment”) may be covered by one or more manufacturer warranties, which will be passed through to Customer to the greatest extent possible. By procuring equipment or software for Customer, Onward does not make any warranties or representations regarding the quality, integrity, or usefulness of the Procured Equipment. Certain equipment or software, once purchased, may not be returnable or, in certain cases, may be subject to third party return policies and/or re-stocking fees, all of which shall be Customer’s responsibility in the event that a return of the Procured Equipment is requested. Onward is not a warranty service or repair center. Onward will facilitate the return or warranty repair of Procured Equipment; however, Customer understands and agrees that (i) the return or warranty repair of Procured Equipment is governed by the terms of the warranties (if any) governing the applicable Procured Equipment, for which Onward will be held harmless, and (ii) Onward is not responsible for the quantity, condition, or timely delivery of the Procured Equipment once the equipment has been tendered to the designated shipping or delivery courier.

Business Review / IT Strategic Planning Meetings

We strongly suggest that you participate in business review/strategic planning meetings as may be requested by us from time to time. These meetings are intended to educate you about recommended (and potentially crucial) modifications to your IT environment, as well as to discuss your company’s present and future IT-related needs. These reviews can provide you with important insights and strategies to make your managed IT environment more efficient and secure. You understand that by suggesting a particular service or solution, we are not endorsing any specific manufacturer or service provider.

VCTO or VCIO Services

The advice and suggestions provided by us in our capacity as a virtual chief technology or information officer (if applicable) will be for your informational and/or educational purposes only. Onward will not hold an actual director or officer position in Customer’s company, and we will neither hold nor maintain any fiduciary relationship with Customer. Under no circumstances shall Customer list or place Onward on Customer’s corporate records or accounts.

Sample Policies, Procedures.

From time to time, we may provide you with sample (i.e., template) policies and procedures for use in connection with Customer’s business (“Sample Policies”). The Sample Policies are for your informational use only, and do not constitute or comprise legal or professional advice, and the policies are not intended to be a substitute for the advice of competent counsel. You should seek the advice of competent legal counsel prior to using or distributing the Sample Policies, in part or in whole, in any transaction. We do not warrant or guarantee that the Sample Policies are complete, accurate, or suitable for your (or your customers’) specific needs, or that you will reduce or avoid liability by utilizing the Sample Policies in your (or your customers’) business operations.

Penetration Testing; Vulnerability Scanning

You understand and agree that security devices, alarms, or other security measures, both physical and virtual, may be tripped or activated during the penetration testing and/or vulnerability scanning processes, despite our efforts to avoid such occurrences. You will be solely responsible for notifying any monitoring company and all law enforcement authorities of the potential for “false alarms” due to the provision of the penetration testing or vulnerability scanning services, and you agree to take all steps necessary to ensure that false alarms are not reported or treated as “real alarms” or credible threats against any person, place, or property. Some alarms and advanced security measures, when activated, may cause the partial or complete shutdown of the Environment, causing substantial downtime and/or delay to your business activities. We will not be responsible for any claims, costs, fees, or expenses arising or resulting from (i) any response to the penetration testing or vulnerability scanning services by any monitoring company or law enforcement authorities, or (ii) the partial or complete shutdown of the Environment by any alarm or security monitoring device.

No Third Party Scanning

Unless we authorize such activity in writing, you will not conduct any test, nor request or allow any third party to conduct any test (diagnostic or otherwise), of the security system, protocols, processes, or solutions that we implement in the managed environment (“Testing Activity”). Any services required to diagnose or remediate errors, issues, or problems arising from unauthorized Testing Activity are not covered under the Quote, and if you request us (and we elect) to perform those services, those services will be billed to you at our then-current hourly rates.

Obsolescence

If at any time any portion of the managed environment becomes outdated, obsolete, reaches the end of its useful life, or acquires “end of support” status from the applicable device’s or software’s manufacturer (“Obsolete Element”), then we may designate the device or software as “unsupported” or “non-standard” and require you to update the Obsolete Element within a reasonable time period. If you do not replace the Obsolete Element reasonably promptly, then in our discretion we may (i) continue to provide the Services to the Obsolete Element using our “best efforts” only with no warranty or requirement of remediation whatsoever regarding the operability or functionality of the Obsolete Element, or (ii) eliminate the Obsolete Element from the scope of the Services by providing written notice to you (email is sufficient for this purpose). In any event, we make no representation or warranty whatsoever regarding any Obsolete Element or the deployment, service level guarantees, or remediation activities for any Obsolete Element.

Licenses

If we are required to re-install or replicate any software provided by you as part of the Services, then it is your responsibility to verify that all such software is properly licensed. We reserve the right, but not the obligation, to require proof of licensing before installing, re-installing, or replicating software into the managed environment. The cost of acquiring licenses is not included in the scope of the Quote unless otherwise expressly stated therein.

VOIP – Dialing 911 (Emergency) Services

The following terms and conditions apply to your use of any VoIP service that we facilitate for you or that is provided to you by a third party provider of such service. Please note, by using VoIP services you agree to the provisions of the waiver at the end of this section. If you do not understand or do not agree with any of the terms below, you must not subscribe to, use, or rely upon any VoIP service and, instead, you must contact us immediately.
There is an important difference in how 9-1-1 (i.e., emergency) services can be dialed using a VoIP service as compared to a traditional telephone line. Calling emergency services using a VoIP service is referred to as “E911.”
Registration: You are responsible for activating the E911 dialing feature by registering the address where you will use the VoIP service. This will not be done for you, and you must take this step on your own initiative. To do this, you must log into your VoIP control panel and provide a valid physical address. If you do not take this step, then E911 services may not work correctly, or at all, using the VoIP service. Emergency service dispatchers will only send emergency personnel to a properly registered E911 service address.
Location: The address you provide in the control panel is the location to which emergency services (such as the fire department, the police department, etc.) will respond. For this reason, it is important that you correctly enter the location at which you are using the VoIP services. PO boxes are not proper addresses for registration and must not be used as your registered address. Please note, even if your account is properly registered with a correct physical address, (i) there may be a problem automatically transmitting a caller’s physical location to the emergency responders, even if the caller can reach the 911 call center, and (ii) a VoIP 911 call may go to an unstaffed call center administrative line or be routed to a call center in the wrong location. These issues are inherent to all VoIP systems and services. We will not be responsible for, and you agree to hold us harmless from, any issues, problems, incidents, damages (both bodily- and property-related), costs, expenses, and fees arising from or related to your failure to register timely and correctly your physical location information into the control panel.
Address Change(s): If you change the address used for E911 calling, the E911 services may not be available and/or may operate differently than expected. Moreover, if you do not properly and promptly register a change of address, then emergency services may be directed to the location where your services are registered and not where the emergency may be occurring. For that reason, you must register a change of address with us through the VoIP control panel no less than three (3) business days prior to your anticipated move/address change. Address changes that are provided to us with less than three (3) business days notice may cause incorrect/outdated information to be conveyed to emergency service personnel. If you are unable to provide us with at least three (3) business days notice of an address change, then you should not rely on the E911 service to provide correct physical location information to emergency service personnel. Under those circumstances, you must provide your correct physical location to emergency service dispatchers if you call them using the VoIP services.
If you do not register the VoIP service at your location and you dial 9-1-1, that call will be categorized as a “rogue 911 call.” If you are responsible for dialing a rogue 911 call, you will be charged a non-refundable and non-disputable fee of $250/call.
Power Loss: If you lose power or there is a disruption to power at the location where the VoIP services are used, then the E911 calling service will not function until power is restored. You should also be aware that after a power failure or disruption, you may need to reset or reconfigure the device prior to utilizing the service, including E911 dialing.
Internet Disruption: If your internet connection or broadband service is lost, suspended, terminated or disrupted, E911 calling will not function until the internet connection and/or broadband service is restored.
Account Suspension: If your account is suspended or terminated, then all E911 dialing services will not function.
Network Congestion: There may be a greater possibility of network congestion and/or reduced speed in the routing of E911 calls as compared to 911 dialing over traditional public telephone networks.
Messaging: All messages sent through the VoIP service must conform to the following requirements and restrictions:
  • Recipients must give their consent to receive text messages from you. This can be direct consent or, depending on the circumstances, implied consent (such as a pre-existing business relationship, contact initiated by the recipient, etc.).
  • Recipients must be provided with an opt-out mechanism to avoid receiving future text messages from you.
  • You shall not mis-identify yourself or cause the message to appear as if it was sent from a telephone number other than the number assigned to you by the VoIP service.
  • All messaging-related activities must strictly comport with the requirements and restrictions of the Telephone Consumer Protection Act (47 USC §227) (“TCPA”). You agree to indemnify and hold us harmless from any costs, fees, expenses, and/or penalties that we incur because of your failure to abide strictly by the TCPA. If, in our reasonable judgment, we believe that your activities violate the TCPA, we reserve the right to suspend the messaging service until we receive reasonable assurances that the activity has stopped and will not be repeated. Repeated violation of the TCP is a material breach of your agreement with us.
WAIVER: You hereby agree to release, indemnify, defend, and hold us and our officers, directors, representatives, agents, and any third party service provider that furnishes VoIP-related services to you, harmless from any and all claims, damages, losses, suits or actions, fines, penalties, costs and expenses (including, but not limited to, attorneys’ fees), whether suffered, made, instituted or asserted by you or by any other party or person (collectively, “Claims”) arising from or related to the VoIP services, including but not limited to any failure or outage of the VoIP services, incorrect routing or use of, or any inability to use, E911 dialing features. The foregoing waiver and release shall not apply to Claims arising from our gross negligence, recklessness, or willful misconduct.

Co-Managed Services Policy

Onward’s Role: In co-managed situations (i.e., situations in which Onward is providing services alongside another IT vendor, IT manager/department, or a third party solution provider that is providing different, complementary, or overlapping services), Onward serves as the technology subject matter expert, responsible for the overall management, provisioning, and governance of the IT Services covered by the Quote. While Onward establishes and enforces the standards and key performance indicators (KPIs) necessary to ensure service quality and compliance, Onward does not assume responsibility for any services or systems Customer independently decides to develop or implement outside the scope of the Quote. Such initiatives must be standardized and formally incorporated into the scope for Onward to manage or support them.
Service Provisioning: Onward is responsible for deploying, configuring, and maintaining the IT infrastructure necessary for the IT Services under the Quote. This responsibility extends to ensuring that the infrastructure aligns with Customer’s business needs and adheres to the Service Level Agreements (SLAs) outlined in in this Guide. If Customer provisions services on Onward’s cloud-hosted infrastructure, Onward provides best-effort support but does not assume responsibility for their management or performance unless specifically agreed upon, which may require an adjustment to fees.
Change Management: Onward will oversee the change management process, including handling change requests, approvals, and communication related to significant updates or the introduction of new technologies within the managed IT environment. This ensures that all changes are managed systematically to minimize disruption and align with business objectives.
Incident and Problem Management: Onward shall manage critical incidents and problem management processes within the co-managed environment. This includes coordinating with Customer’s IT team to help ensure timely resolution of issues.
Customer’s Role and Collaboration:  Customer is responsible for managing internal processes, communicating with end-users, and assisting with day-to-day IT support under Onward’s guidance. Customer must ensure that its IT personnel adhere to the ITSM processes, standards, and KPIs defined by Onward. This includes maintaining adequate IT staffing levels to ensure they can effectively collaborate within the co-managed environment. Onward is not responsible for any gaps in support or service that arise from inadequate staffing on Customer’s part. Such gaps, should they occur, may cause the Services to be delayed, adjusted by Onward, and/or may require Customer to pay additional fees and costs to accommodate the gaps in Customer’s personnel or staffing.
Expertise and Support: Onward provides the technical expertise necessary for specialized IT deployments, governance, and strategy development. This includes ensuring compliance with industry standards, implementing best practices, and supporting Customer in complex technical initiatives.
Support and Guidance: Onward will offer guidance and support to both Customer’s IT team and end-users for the services covered under the Quote. This includes helping the IT team effectively utilize the ITSM platform and adhere to established protocols. Onward will also provide end-user support for IT services and systems managed by Onward, though comprehensive training on all Customer applications is outside the scope.
Tools, Business Intelligence, and Resources: Onward will provide tools, resources, and business intelligence related to ITSM to facilitate IT management for Customer’s IT team. These tools include automated workflows, templates, and documentation to streamline processes and improve efficiency.
Strategic Consultation: Onward will engage in regular reviews and strategic consultations with Customer to align IT services with Customer’s business goals. This includes recommending improvements and adjustments to the IT environment as needed.
Shared Responsibility: The co-managed IT model relies on effective collaboration between Onward and Customer. While Onward provides the framework, tools, and expert guidance, Customer’s IT personnel are expected to actively participate in the ongoing management and support of their IT systems, following Onward’s standards and KPIs.
Exclusion from Co-Management: If Customer’s IT personnel do not meet the required proficiency levels or fail to adhere to the established ITSM protocols, Onward may limit their involvement in co-management activities. In such cases, Onward will retain greater control over the management process to ensure service quality. If Customer’s IT personnel later meet the necessary standards, their involvement in co-management may be reinstated upon mutual agreement.

Acceptable Use Policy

The following policy applies to all hosted services provided to you, including but not limited to (and as applicable) hosted applications, hosted websites, hosted email services, and hosted infrastructure services (“Hosted Services”).
Onward does not routinely monitor the activity of hosted accounts except to measure service utilization and/or service uptime, security-related purposes and billing-related purposes, and as necessary for us to provide or facilitate our managed services to you; however, we reserve the right to monitor Hosted Services at any time to ensure your compliance with the terms of this Acceptable Use Policy (this “AUP”) and our master services agreement, and to help monitor and ensure the safety, integrity, reliability, or security of the Hosted Services.
Similarly, we do not exercise editorial control over the content of any information or data created on or accessible over or through the Hosted Services. Instead, we prefer to advise our customers of inappropriate behavior and any necessary corrective action. If, however, Hosted Services are used in violation of this AUP, then we reserve the right to suspend your access to part or all of the Hosted Services without prior notice.
Violations of this AUP: The following constitute violations of this AUP:
· Harmful or illegal uses: Use of a Hosted Service for illegal purposes or in support of illegal activities, to cause harm to minors or attempt to contact minors for illicit purposes, to transmit any material that threatens or encourages bodily harm or destruction of property or to transmit any material that harasses another is prohibited.
· Fraudulent activity: Use of a Hosted Service to conduct any fraudulent activity or to engage in any unfair or deceptive practices, including but not limited to fraudulent offers to sell or buy products, items, or services, or to advance any type of financial scam such as “pyramid schemes,” “Ponzi schemes,” and “chain letters” is prohibited.
· Forgery or impersonation: Adding, removing, or modifying identifying network header information to deceive or mislead is prohibited. Attempting to impersonate any person by using forged headers or other identifying information is prohibited. The use of anonymous remailers or nicknames does not constitute impersonation.
· SPAM: Onward has a zero tolerance policy for the sending of unsolicited commercial email (“SPAM”). Use of a Hosted Service to transmit any unsolicited commercial or unsolicited bulk e-mail is prohibited. You are not permitted to host, or permit the hosting of, sites or information that is advertised by SPAM from other networks. To prevent unnecessary blacklisting due to SPAM, we reserve the right to drop the section of IP space identified by SPAM or denial-of-service complaints if it is clear that the offending activity is causing harm to parties on the Internet, if open relays are on the hosted network, or if denial of service attacks are originated from the hosted network.
· Internet Relay Chat (IRC): The use of IRC on a hosted server is prohibited.
· Open or “anonymous” proxy: Use of open or anonymous proxy servers is prohibited.
· Cryptomining: Using any portion of the Hosted Services for mining cryptocurrency or using any bandwidth or processing power made available by or through a Hosted Services for mining cryptocurrency, is prohibited.
· Hosting spammers: The hosting of websites or services using a hosted server that supports spammers, or which causes (or is likely to cause) our IP space or any IP space allocated to us or our customers to be listed in any of the various SPAM databases, is prohibited. Customers violating this policy will have their server immediately removed from our network and the server will not be reconnected until such time that Customer agrees to remove all traces of the offending material immediately upon reconnection and agree to allow Onward to access the server to confirm that all material has been completely removed. Any subscriber guilty of a second violation may be immediately and permanently removed from the hosted network for cause and without prior notice.
· Email/message forging: Forging any email message header, in part or whole, is prohibited.
· Unauthorized access: Use of the Hosted Services to access, or to attempt to access, the accounts of others or to penetrate, or attempt to penetrate, Onward’s security measures or the security measures of another entity’s network or electronic communications system, whether or not the intrusion results in the corruption or loss of data, is prohibited. This includes but is not limited to accessing data not intended for you, logging into or making use of a server or account you are not expressly authorized to access, or probing the security of other networks, as well as the use or distribution of tools designed for compromising security such as password guessing programs, cracking tools, or network probing tools.
· IP infringement: Use of a Hosted Service to transmit any materials that infringe any copyright, trademark, patent, trade secret or other proprietary rights of any third party, is prohibited.
· Collection of personal data: Use of a Hosted Service to collect, or attempt to collect, personal information about third parties without their knowledge or consent is prohibited.
· Disruptive Activity: Use of the Hosted Services for any activity which affects the ability of other people or systems to use the Hosted Services or the internet is prohibited. This includes “denial of service” (DOS) attacks against another network host or individual, “flooding” of networks, deliberate attempts to overload a service, and attempts to “crash” a host.
· Distribution of malware: Intentional distribution of software or code that attempts to and/or causes damage, harassment, or annoyance to persons, data, and/or computer systems is prohibited.
· Excessive use or abuse of shared resources: The Hosted Services depend on shared resources. Excessive use or abuse of these shared network resources by one customer may have a negative impact on all other customers. Misuse of network resources in a manner which impairs network performance is prohibited. You are prohibited from excessive consumption of resources, including CPU time, memory, and session time. You may not use resource-intensive programs which negatively impact other customers or the performances of our systems or networks.
· Allowing the misuse of your account: You are responsible for any misuse of your account, even if the inappropriate activity was committed by an employee or independent contractor. You shall not permit your hosted network, through action or inaction, to be configured in such a way that gives a third party the capability to use your hosted network in an illegal or inappropriate manner. You must take adequate security measures to prevent or minimize unauthorized use of your account. It is your responsibility to keep your account credentials secure.
To maintain the security and integrity of the hosted environment, we reserve the right, but not the obligation, to filter content, Onward requests, or website access for any web requests made from within the hosted environment.
Revisions to this AUP: We reserve the right to revise or modify this AUP at any time. Changes to this AUP shall not be grounds for early contract termination or non-payment.

DevOps Addendum

Our development operations services (or “DevOps”) help automate and integrate the processes between software development and information technology (IT) operations teams. Generally, DevOps entails five principles:
  • Collaboration: DevOps assists the development and operations team to communicate and collaborate, fostering shared responsibility and collaboration.
  • Automation: DevOps uses automated solutions to streamline the software development cycle, from building and testing to deployment and monitoring.
  • Continuous Integration & Continuous Delivery (“CI/CD”): CI/CD pipelines automate the process of building, testing, and deploying code changes, enable frequent, stable, and reliable code releases.
  • Infrastructure as Code (“IaC”): This involves managing and provisioning infrastructure through code, making both processes repeatable and version-controlled.
  • Monitoring & Feedback: Continuous monitoring and feedback loops help identify and address issues quickly, helping to ensure overall stability and performance.
To ensure the principles of DevOps are fully implemented, DevOps requires Customer’s cooperation and Customer’s participation in certain shared responsibilities. To that end, Customer must:
  • Employ a Senior IT Leader: Customer should designate a senior IT leader (e.g., a Director of IT, IT Manager, or Chief Information Officer) with relevant experience in IT management, operations, or DevOps practices. This individual will serve as the primary point of contact and Authorized Representative (as defined in the MSA) for DevOps-related matters.
  • Co-Managed DevOps: If Customer is participating in a co-managed DevOps engagement (as described in the Co-Managed Services section of this Services Guide), Customer must also maintain a qualified IT team to support DevOps activities. At a minimum, this team should include:
  • IT Support Personnel: Staff with experience in systems administration, network management, or cloud services, capable of addressing technical issues related to DevOps.
  • Business Analysts: Analysts with familiarity in DevOps workflows and process automation, responsible for aligning business needs with DevOps objectives.
  • All members of Customer’s DevOps team should be readily available to Onward during normal business hours to ensure responsive support and alignment with DevOps goals.
  • Establish and Maintain IT Protocols: Customer must create, document, and enforce IT protocols aligned with DevOps practices, which will be subject to Onward’s review and approval to ensure best practices.
Customer’s failure to fulfill and maintain the above-listed requirements may result in a delay in the provision of DevOps for which Onward will not be responsible, or in cases where the failure substantially impacts Onward’s ability to perform, may result in Onward (in its sole discretion) (i) terminating the DevOps for cause, (ii) amending the scope of the DevOps to accommodate the failure, or (iii) increasing the monthly fee to cover Onward’s increased costs and time.
Both Onward’s technicians and Customer will be involved in the following DevOps stages:
  • Planning & Development: Onward and Customer’s DevOps Team will work together to plan and design applications and infrastructure.
  • Testing: Onward and Customer’s DevOps Team will be involved in testing at various stages of the DevOps process, including automated testing and performance testing. It is crucial that Customer’s DevOps Team provide prompt and complete feedback in response to testing activities.
  • Deployment: Onward and Customer’s DevOps Team will collaborate to automate and streamline deployment of developed applications and processes.
  • Monitoring & Maintenance: During the term of the DevOps service, Onward will monitor overall performance of developed applications and processes, and remediate issues that are reported (and which are capable of being observed in Onward’s laboratory or similar technical setting). Customer’s DevOps Team will monitor the performance and effectiveness of the developed applications and processes, and promptly report any deviations, errors, or suspected deficiencies to Onward for further evaluation.
If Customer fails to participate in any of the steps or stages described above, DevOps may be delayed, canceled for cause, or result in increased monthly fee to cover Onward’s increased costs and time.
Service Hours: DevOps will be provided during our normal business hours, which are currently 8 AM through 5 PM Eastern Time, Monday through Friday, excluding the following Onward-recognized holidays:
  • New Year’s Eve
  • New Years Day
  • Christmas Eve through the day after Christmas
  • Thanksgiving Day and the day after Thanksgiving
  • Labor Day
  • Memorial Day
  • Independence Day
Services may be available during non-business hours on a case-by-case basis, subject to technician availability and additional fees. (Emergency incidents will be invoiced at $350 per incident regardless of the length of service. All after-hours or emergency-related services require Customer’s prior approval before being implemented.)
Exclusions: The following are out-of-scope of DevOps and, if provided, will require Customer’s approval and will be subject to additional fees:
  • Projects or services that are not included in the scope of the Quote (such as New DevOps Projects / Add-Ons, described below);
  • Off-hours/emergency services (described above);
  • Support for line-of-business software that does not have a then-current support contract from the software manufacturer, it being understood that if Onward provides such support it will be on a “best efforts” and “as is” basis with no warranty or guaranty whatsoever; and,
  • Installation, implementation, and/or maintenance of new line-of-business platforms, module installations, migrations of data, software, or equipment, or software upgrades.
New DevOps projects that require consultation, design planning, or support efforts, as well as major changes to Customer’s then existing IT hardware or software environment or active user account increases, can be accommodated but will require Customer’s prior approval and will require the payment of additional fees and costs.
Hourly Work: Any services performed or provided by Onward on an hourly basis will be billed in fifteen (15) minute increments for MSA agreements, and thirty (30) minute increments for DevOps or Contract agreements, with partial increments being rounded up to the next highest increment. In additional to hourly services described elsewhere in this Addendum, all travel time to and from Customer’s location outside of Lee County will be billed as hourly work, as will any time spent setting up, configuring, or maintaining out-of-scope services or changes.
New DevOps Projects / Add-Ons: If Customer or Onward identifies a new business need that necessitates a change to the existing technology hardware or software (such as a new line-of-business application, new office space opening, increased staffing levels, business acquisition), then Onward will following the following procedure:
  • Customer and Onward will collaborate to validate all requirements for additional hardware or software needed to support the identified business need before making any purchases.
  • For software add-ons, Customer will designate a software application owner from Customer’s DevOps Team (“Project Owner”). Onward will work with the Project Owner to install a demo of the software (if available) and assess its features and benefits before making any purchases. Once the software is confirmed to meet business requirements, Project Owner will inform Customer and Customer’s DevOp’s Team of the demo results.
  • Onward will determine and notify the Customer’s business principal of any required additional hardware purchases to support the new software before any purchases are made.
  • Onward validates the installation and ongoing support requirements for any additional hardware and/or software and presents the increase in monthly Onward Managed DevOps Services fees to the Project Owner before making any purchases. If approved, all time spent procuring, installing, and maintaining the additional hardware and/or software will be covered under the Onward Managed DevOps then-current services quote. If the increase in monthly fees is not approved, the support provided will be offered on a best-effort basis and invoiced according to Onward’s then-current hourly rates.
  • Onward reserves the right to determine and adjust the vendors, technologies, and third-party providers that support our managed services based on evolving industry standards, compatibility with Customer environments, and continuous improvement in service quality. Supported vendors and technologies will be selected at Onward’s discretion to ensure alignment with service delivery goals. Onward will notify Customers of any major changes that may impact service outcomes or Customer responsibilities.

Last updated: October 17, 2023