Onward Services Guide
This Services Guide contains provisions that define, clarify, and govern the scope of the services described in the quote that has been provided to you (the "Quote"), as well as the policies and procedures that we follow (and to which you agree) when we provide a service to you or facilitate a service for you. If you do not agree with the terms of this Services Guide, you should not sign the Quote and you must contact us for more information.
This Services Guide is our "owner's manual" that generally describes all managed services provided or facilitated by Onward Technology Solutions, LLC. ("Onward," "we," "us," or "our"); however, only those services specifically described in the Quote will be facilitated and/or provided to you.
This Services Guide is governed under our Master Services Agreement ("MSA"). You may locate our MSA through the link in your Quote or, if you want, we will send you a copy of the MSA by email upon request. Capitalized terms in this Services Guide will have the same meaning as the capitalized terms in the MSA, unless otherwise indicated below.
Activities or items that are not specifically described in the Quote will be out of scope and will not be included unless otherwise agreed to by us in writing.
Please read this Services Guide carefully and keep a copy for your records.
Initial Audit / Diagnostic Services
In most cases, we will conduct an initial audit
of your information technology (IT) environment to determine the readiness for, and compatibility with,
our proposed ongoing managed services. This audit may be comprised of some or all the following:
- Audit to determine general
Environment readiness and functional capability
- Review of hardware and software
configurations
- Review of current vendor service /
warranty agreements for Environment hardware and software
- Basic security vulnerability check
- Basic backup and file recovery
solution audit
- Speed test and ISP audit
- Print output audit
- Office telephone vendor service
audit
- Asset inventory
- Email and website hosting audit
- IT support process audit
If deficiencies are discovered during the
auditing process (such as outdated equipment or unlicensed software), we will bring those issues to your
attention and discuss the impact of the deficiencies on our provision of the Services and provide you
with options to correct the deficiencies. Please note, unless otherwise
expressly agreed by us in writing, auditing services do not include the remediation of any issues, errors, or deficiencies
("Issues"), and we cannot guarantee that all Issues will be detected during the auditing
process. Issues that are discovered in the Environment after the auditing process is
completed may be addressed in one or more subsequent quotes.
Onboarding Services
Onboarding is the stage during which we prepare
your IT environment for the monthly managed services described in the Quote. During this phase, we will
work with your Authorized Contact(s) to review the information we need to prepare the targeted
environment, and we may also:
- Uninstall any monitoring tools or
other software installed by previous IT service providers (“Prior Tools”). Please
note: If we are unable to uninstall or disable Prior Tools remotely, then an
onsite visit may be required for which additional fees, such as travel time, may apply. In any
event, if Prior Tools cannot be removed then we will bring that situation to your attention and, to
the extent reasonably practicable, quarantine the Prior Tools so they become inoperative. We do not
warrant or guarantee that all Prior Tools will be capable of being removed permanently, or that
unremovable Prior Tools will become or remain inoperative.
- Compile a full inventory of all
protected servers, workstations, and laptop
- Uninstall any previous endpoint
protection and install our managed security solutions (as indicated in the Quote)
- Install remote support access
agents (i.e., software agents) on each managed device to
enable remote support
- Configure Windows® and application
patch management agent(s) and check for missing security updates
- Uninstall unsafe applications or
applications that are no longer necessary
- Optimize device performance
including disk cleanup and endpoint protection scans
- Review firewall configuration and
other network infrastructure devices
- Review status of battery backup
protection on all mission critical devices
- Stabilize network and assure that
all devices can securely access the file server
- Review and document current server
configuration and status
- Determine existing business
continuity strategy and status; prepare backup file recovery and incident response option for
consideration
- Review password policies and
update user and device passwords.
- As applicable, make
recommendations for changes that should be considered to the managed environment
This list is subject to change if we determine,
at our discretion, that different or additional onboarding activities are required.
If deficiencies are discovered during the
onboarding process, we will bring those issues to your attention and discuss the impact of the
deficiencies on our provision of our monthly managed services. Please
note, unless otherwise expressly stated in the Quote, onboarding-related services do not include the remediation of any issues, errors, or deficiencies
(“Issues”), and we cannot guarantee that all Issues will be detected during the onboarding
process.
The duration of the onboarding process depends
on many factors, many of which may be outside of our control such as product availability/shortages,
required third party vendor input, etc. As such, we can estimate, but cannot and do not guarantee, the
timing or duration of the onboarding process. Should the onboarding process become protracted due to one
or more of these factors, or if Customer fails to cooperate or provide necessary staffing or information
required for the proper configuration or implementation of the managed services, then we reserve the
right to modify our quoted response times and/or the scope of the managed services as reasonably
necessary to accommodate these issues.
Ongoing / Recurring Managed Services
The table below describes all
managed services provided or facilitated by Onward; however, only those services specifically described
in the Quote will be facilitated and/or provided to you (collectively, the “Services”). Please review the Quote to determine which of the managed services
listed below will be provided to / facilitated for you.
Ongoing/recurring managed services are provided
to you or facilitated for you on an ongoing basis and, unless otherwise indicated in a Quote, are billed
to you monthly. Some ongoing/recurring services will begin with the commencement of onboarding services;
others will begin when the onboarding process is completed. Please direct any questions about start or
“go live” dates to your account manager.
Managed Services
(Please refer
to the Quote to determine which Managed Services you will be receiving.)
|
|
|
|
Business Continuity and Disaster Recovery
|
Implementation and facilitation by our
designated Third Party Provider of a comprehensive data protection solution,
covering supported SaaS platforms, on-premise servers, and designated
endpoints, including workstations and laptops that contain essential
business data. This service offers automated, SLA-driven backup management
with configurable recovery options and compliance-focused data retention for
up to 7 years. Designed to minimize manual intervention, this solution
leverages advanced technology to ensure data resilience, protect critical
business information, and support business continuity.
Comprehensive
SaaS Backup: Complete cloud-to-cloud backup for supported SaaS
applications, covering email, collaboration tools, file storage, and
identity management systems. This includes data backup for user accounts,
files, contacts, calendars, messages, audit logs, security policies,
applications, and device management configurations.
- Comprehensive SaaS Backup: Offers
cloud-to-cloud backup for supported SaaS applications, covering
essential business data and configurations across applications,
including email, collaboration tools, file storage, and identity
management systems.
- Data Coverage: Provides
comprehensive backup for user accounts, files, contacts, calendars,
messages, audit logs, security policies, applications, and device
management configurations.
Continuous
Backup Monitoring: 24/7 monitoring of all supported backup
sources (SaaS, on-premise servers, and endpoints) for real-time detection of
backup failures, capacity issues, and other disruptions, with proactive
alerting.
- Proactive Alerting: Provides
immediate notifications for any issues in backup operations, enabling
prompt resolution to maintain data integrity.
RTO/RPO-Based
Backup Scheduling: Customizes backup schedules based on
Customer’s Recovery Time Objective (RTO) and Recovery Point Objective (RPO)
requirements, allowing for flexible frequency options to meet data
protection needs.
- Continuous Backups:
Near-instantaneous recovery points for critical assets, minimizing data
loss.
- High-Frequency Backups (1-3 times per
day): Configured for moderately critical assets, allowing
recovery within established data loss limits.
- Daily Backups: Standard daily
backups provide data consistency and scheduled recovery points for
non-critical assets.
Granular,
Point-in-Time Recovery: Enables precise, point-in-time recovery
across servers, endpoints, and SaaS applications. Supports restoration of
files, messages, services, and virtual machines to selected versions with
accuracy.
Cross-Platform
Protection & Analytics: Offers comprehensive backup and
recovery for critical on-premise servers and designated endpoints, enhancing
protection for essential data, applications, and system configurations.
- Endpoints and Servers: Secures
data for critical servers and specified endpoints (e.g., workstations,
laptops) according to backup policy and requirements.
Global Storage
and Extended Retention: Supports configurable retention policies
of up to 7 years to meet regulatory and business requirements. Data storage
is available in secure global locations, ensuring compliance with data
sovereignty regulations.
Enhanced
Security and Encryption: Ensures that backed-up data is encrypted
to meet industry security standards and protect confidentiality.
- Encryption: All data is encrypted
in transit and at rest using AES-256 encryption.
- Physical Security: Backup data
facilities implement strict physical security, including controlled
access, surveillance, and redundant connectivity with failover
capabilities.
Compliance
Integration & eDiscovery: Supports compliance and audit
readiness with centralized reporting and data retrieval capabilities,
aligning with security and compliance frameworks.
- Monitoring and Logging for
Compliance: Provides security monitoring and logging for
compliance purposes. Backup logs and activity details are accessible for
compliance documentation.
- eDiscovery & Full-Text Search:
Offers eDiscovery and search capabilities across backup environments for
quick data retrieval, integrated into Onward’s IT Service Management
(ITSM) platform for streamlined reporting.
Backup
Retention Options: Provides flexible retention options to support
regulatory, industry, and business-specific requirements, with standard and
extended configurations.
- Standard Retention: Default
retention is set at 30 days for non-critical data, with options for
monthly and annual retention periods.
- Extended Retention (up to 7
years): Available for industries requiring long-term data
preservation due to regulatory mandates. Examples include:
- Healthcare (HIPAA
Compliance): Typically 6 years for patient data and
documentation.
- Financial Services (SEC &
FINRA): Up to 7 years for records related to
transactions, communications, and compliance.
- Legal & Government (FOIA and
GDPR): 5 to 7 years for records required for
disclosure or retention mandates.
- Manufacturing & Supply
Chain: 3 to 5 years for quality control and
compliance records.
NOTE: Extended retention may
incur additional storage costs. Customers should specify retention
needs during configuration to ensure compliance with applicable
requirements.
Recovery of Data, Services, and
Systems: Provides
restoration of backed-up data, applications, and services during
standard business hours, with options for prompt response based on
availability and backup specifications.
- Request Methods: Restoration
requests may be submitted via:
- Email:
support@onward.solutions
- Web Portal: Onward PSA
Portal
- Telephone: (239) 984-0580
- Restoration Time: Restoration will
be prioritized based on technician availability and confirmation of
recovery points. Services include recovery of files, applications, SaaS
data, and other designated assets.
NOTE: Backup & Recovery
Services require active Customer cooperation. If Customer provides
incomplete, inaccurate, or outdated information, data recovery may
be affected. Restoration timelines depend on technician availability
and data recovery points. This Service does not guarantee data
integrity or recovery for issues outside the control of Onward or
its Third Party Provider, such as hardware failures, unauthorized
data changes, or third-party service interruptions.
|
|
Compliance & Data Retention
|
Implementation and facilitation by our
designated Third Party Provider of a regulatory compliance and data
retention management solution. This service assists the Customer in aligning
operations with applicable regulatory standards across all managed
environments. Services include compliance monitoring, centralized reporting,
audit support, and data retention policies tailored to meet
industry-specific requirements, including HIPAA, SOC 2, GDPR, and other
relevant frameworks. Automated reminders and structured data retention
policies are provided to promote a proactive, consistent approach to
regulatory compliance.
Comprehensive
Compliance Monitoring: Provides continuous oversight and
alignment with regulatory frameworks to support adherence to internal
policies and external standards applicable to Customer’s business
operations.
- Regulatory Framework Alignment:
Monitors and configures compliance policies to meet industry standards
such as HIPAA, SOC 2, and GDPR. Adjustments are made based on regulatory
changes to facilitate ongoing compliance assessments.
- Templates and Training Access:
Supplies compliance templates, regulatory guidelines, and training
resources for Customer’s staff, reinforcing adherence to policies and
regulatory requirements.
- Compliance Dashboards: Real-time
dashboards display compliance status across policies and controls,
providing compliance officers with immediate insights and highlighting
potential compliance gaps.
Automated
Compliance & Reporting: Automates compliance activities and
consolidates reporting to assist in audit readiness and regulatory
alignment.
- Audit-Ready Documentation:
Compiles compliance logs, policy documentation, and procedural records
into a centralized repository, facilitating audit preparation with
records of compliance activities, policy changes, and training
completions.
- Automated Compliance Reminders:
Sends scheduled reminders for compliance actions, such as risk
assessments, training updates, and policy reviews. These reminders help
the Customer stay on schedule with regulatory timelines.
- Customizable Reporting: Enables
the generation of compliance reports tailored for internal review or
external audits. Reports can highlight specific controls, compliance
metrics, or regulatory gaps based on audit needs.
eDiscovery
& Full-Text Search: Supports regulatory and legal inquiries
by enabling efficient data retrieval and improving audit readiness.
- eDiscovery Tools: Facilitates
rapid retrieval of documents, emails, and records pertinent to audits or
legal investigations. Supports compliance review and legal inquiries by
organizing relevant data for easy access.
- Full-Text Search: Enables
comprehensive search capabilities across stored documentation, allowing
the Customer to efficiently locate data required for regulatory or legal
obligations.
Data Retention
& Compliance Audits: Implements data retention policies
aligned with regulatory requirements and conducts scheduled reviews to
verify ongoing compliance.
- Configurable Data Retention
Policies: Provides retention schedules aligned with
regulatory mandates, supporting data retention for periods of up to 7
years. Settings are customizable to meet industry and jurisdictional
requirements.
- Annual Compliance Reviews:
Conducts annual compliance reviews to assess the Customer’s regulatory
alignment, with optional quarterly assessments available for enhanced
compliance verification.
- Policy & Procedure Alignment:
Updates policies and procedures as regulatory standards evolve, aiming
to support the Customer’s continuous compliance alignment.
NOTE: This Service requires
Customer’s active cooperation and participation. If the Customer
provides incomplete, inaccurate, or outdated information, the
effectiveness of this Service may be compromised, and the results
should not be solely relied upon. Certification of compliance
completion is valid as of the issuance date but does not guarantee
ongoing compliance. For consistent regulatory alignment, it is
strongly recommended that the Customer maintains this Service
without lapses to support the ongoing adherence of operations,
processes, and procedures to regulatory standards.
|
|
Cybersecurity, Threat Management & Identity
Protection
|
Implementation and facilitation by our
designated Third Party Providers of a comprehensive cybersecurity solution,
designed to proactively detect, prevent, and respond to digital threats
across emails, endpoints, networks, and identities. This service
incorporates Zero-Trust principles to establish multi-layered protection
with advanced detection capabilities, rapid response, and identity-focused
security measures, ensuring that critical systems and data remain secure
against evolving cyber threats.
NOTE: This service requires
Customer adherence to Onward-specified security policies, including
role-based access, MFA, VPN protocols, and compliance with
Zero-Trust protections. Non-compliance may increase security risks.
Zero-Trust
Security Framework: Establishes Zero-Trust principles as the
foundational security model, ensuring strict access control, continuous
verification, and least-privilege access across the organization.
- Identity Verification at Every Access
Point: Enforces user identity verification using role-based
access, multi-factor authentication (MFA), and location-based policies.
- Device Compliance Checks: Limits
network access to secure, authenticated devices based on health and
security criteria.
- Network Micro-Segmentation:
Secures network segments to prevent lateral movement and contain threats
within isolated areas.
Identity
Services Protection: Manages and monitors identity services,
enforcing strict access policies and detecting unusual activity to secure
accounts and prevent unauthorized access.
- Single Sign-On (SSO)
Implementation: Configures and supports SSO capabilities to
streamline secure access to integrated systems.
- Multi-Factor Authentication (MFA) Setup
& Enforcement: Establishes MFA across all user accounts,
providing additional security for sensitive applications.
- MFA Activity Monitoring: Monitors
MFA events to detect compromised accounts, unauthorized logins, and
high-risk devices.
- Role-Based Access Management &
Compliance Monitoring: Assigns access based on roles and
regularly audits to maintain least-privilege principles.
NOTE: Identity Services
Protection is contingent upon Customer’s adherence to MFA, VPN
access controls, and role-based access policies. Failure to comply
may result in elevated security risks.
Privileged Access Control:
Manages elevated access rights across endpoints and cloud services, with
strict controls and automated revocation upon task completion.
- Endpoint Privilege Management:
Limits administrator privileges, allowing elevated permissions only
through controlled, automated systems.
- Break-Glass Accounts for Cloud
Services: Controls administrative access to cloud services
via Onward-managed “break-glass” accounts, restricting elevated
permissions to Onward-authorized personnel.
- Just-In-Time (JIT) Administrative
Access: Temporarily grants administrative access for specific
tasks, with automatic revocation post-task.
Email Threat
Protection: Provides advanced email security measures to defend
against phishing, malware, and business email compromise (BEC) threats.
- Phishing Detection: Blocks
suspicious links and attachments commonly used in phishing attacks.
- Friendly Name Filtering: Detects
impersonation attempts by verifying sender name authenticity.
- Impersonation Defense: Blocks
spoofed names and domains, mitigating social engineering risks.
Endpoint
Antivirus & Malware Protection: Delivers robust malware and
antivirus protection across endpoints, leveraging AI and real-time analysis.
- Behavior-Based Threat Detection:
Blocks suspicious endpoint behaviors before execution.
- Sandbox Analysis: Isolates
potentially harmful applications for secure analysis.
- Comprehensive Malware Defense:
Protects against file-based and fileless threats, with whitelisting for
legitimate scripts.
Dark Web
Monitoring: Scans dark web sources for exposed organizational
credentials, notifying administrators of any detected compromises.
- Credential Exposure Alerts: Alerts
administrators if credentials related to the organization are found on
the dark web.
- End-User Notifications: Prompts
affected users to reset credentials, reducing risks of unauthorized
access.
Unified Threat
Detection & Response (MDR/XDR): Provides 24/7 monitoring,
detection, and incident response across email, endpoint, network, and
identity layers. MDR/XDR combines Managed Detection and Response (MDR) and
Extended Detection and Response (XDR) for a unified, holistic security
approach.
- MDR (Managed Detection &
Response): 24/7 monitoring, threat hunting, and incident
response, with real-time response from security professionals.
- XDR (Extended Detection &
Response): Correlates data from multiple layers (email,
endpoint, network, identity) for in-depth detection and response.
- On-Demand Endpoint Isolation:
Isolates compromised endpoints to prevent spread.
- Root Cause Analysis and Forensics:
Identifies threat origins, with comprehensive forensic data for
continuous improvement.
Scope
Note: MDR/XDR applies only to supported, integrated
systems managed by Onward. Effectiveness may vary depending on
integration completeness across the managed environment.
End User Security Awareness
Training: Provides training to improve end-user awareness of
cybersecurity risks, designed to reduce susceptibility to phishing and
other attacks.
- Online, On-Demand Training:
Provides self-paced, multilingual training videos covering essential
cybersecurity practices.
- Quizzes & Retention
Verification: Includes interactive quizzes to assess employee
understanding of key concepts.
- Baseline Testing & Phishing
Simulations: Assesses user susceptibility to phishing attacks
through simulated campaigns and tracks improvement over time.
NOTE: Regular user
participation in security awareness training is strongly
recommended. Failure to engage in or complete training may elevate
organizational risk.
Penetration Testing: Conducts
simulated cyberattacks to identify vulnerabilities, aligned with
Zero-Trust security principles.
- External Testing: Evaluates
internet-facing systems, firewalls, and applications for exposure to
unauthorized access.
- Internal Testing: Simulates
insider threats to test internal defenses.
- PCI Penetration Testing: Assesses
vulnerabilities per PCI standards.
- Web Application Testing: Conducts
tests on web applications following industry-standard frameworks (e.g.,
OWASP).
NOTE: Penetration Testing
includes vulnerability scanning supplemented by targeted attack
simulations for a comprehensive assessment. Additional terms for
Penetration Testing apply.
Incident Response & Alerting:
Provides immediate alerting, incident analysis, and reporting, with
escalation based on threat severity.
- 24/7 Alerting and Escalation:
Real-time alerts for suspicious activity, with escalation aligned with
risk severity.
- Incident Reporting and Analysis:
Delivers detailed incident reports, including root cause analysis,
impact assessment, and recommendations for improved resilience.
- Data Ingestion and Reporting:
Integrates security data into the IT Service Management Platform,
enabling centralized access to metrics, alerts, and compliance
information.
NOTE: Please refer to
Anti-Virus, Anti-Malware, and Breach/Cyber Security Incident
Recovery sections for specific remediation details.
|
|
Cloud Infrastructure Management
|
Implementation and facilitation of a
comprehensive cloud infrastructure management solution, focusing on the
deployment, management, and support of virtual resources within designated
cloud platforms. This service provides end-to-end oversight of cloud-based
servers, storage, and applications, ensuring scalability, security, and
operational efficiency across managed cloud resources. Designed to enable
organizations to leverage cloud-native benefits, this solution maintains
control over resource utilization, cost optimization, and security
standards.
- Cloud Resource Deployment: Deploys
cloud-based resources, including virtual machines, storage accounts,
databases, and other cloud-native applications, tailored to support
secure and resilient operations based on customer requirements.
- Provisioning and Configuration
Management: Manages configurations, access controls, and
permissions for cloud resources, enforcing role-based access control
(RBAC) to comply with industry and company standards.
- Cost Management and Optimization:
Monitors cloud usage and optimizes spending across resources. Provides
cost allocation and reporting to identify savings opportunities,
ensuring cost-effective resource management.
- Scalability and Performance
Optimization: Adjusts scaling and performance settings to
maintain optimal service levels, monitoring resource utilization and
provisioning adjustments to meet fluctuating demand.
- Backup and Disaster Recovery:
Configures cloud-native backup and disaster recovery for critical
resources, ensuring encrypted backups that meet specific recovery point
(RPO) and recovery time objectives (RTO).
- Security and Compliance
Management: Applies security configurations, including
encryption, access controls, and compliance with regulatory frameworks
(e.g., SOC 2, HIPAA) to ensure secure resource management.
- Monitoring and Alerts: Provides
continuous monitoring for performance, availability, and security, with
automated alerts routed to the ITSM platform for efficient incident
response.
- Cloud-Based Identity and Access
Management (IAM): Configures IAM with multi-factor
authentication (MFA) and role-based policies, enhancing security and
controlling access to cloud resources.
- Automation and Infrastructure as Code
(IaC): Utilizes IaC to automate deployments and ensure
consistent configurations across cloud resources, minimizing manual
configuration efforts.
- Virtual Network Management:
Manages secure, cloud-based virtual networks, configuring connectivity
across cloud resources, including VPNs and virtual firewalls, for
secure, isolated communication within the cloud environment.
NOTE: Cloud Infrastructure
Management applies exclusively to resources within supported cloud
environments. This service does not include management of physical
on-premise infrastructure or hybrid solutions unless explicitly
stated in the Quote. Additional charges may apply for complex
configurations, specialized integrations, or non-standard resources
requiring specific management.
For co-managed customers who procure
cloud infrastructure subscriptions through Onward, self-provisioned
resources are outside our standard support scope and will incur
extra charges for any necessary management, as they may not adhere
to Onward’s deployment standards.
|
|
Network Infrastructure Management
|
Implementation and facilitation of a secure,
scalable, cloud-managed network infrastructure solution that provides
full-stack visibility and centralized management using our designated Third
Party Provider. This infrastructure standard ensures efficient, reliable
configurations across all network components, including firewalls, switches,
access points, VPNs, and cloud-based virtual networks, delivering robust
security and performance monitoring.
Note: Onward will only deploy
and implement network solutions that meet these requirements to
optimize operational reliability and security. Any networking
devices, such as firewalls, switches, wireless access points or
routers, that are supplied by Customer cannot be older than five (5)
years from the applicable device’s original date of manufacture, and
in all cases must be supported by the manufacturer of the device(s).
Cloud-Managed
Network Infrastructure: Establishes a centralized, cloud-based
environment for managing all network components, enabling control,
scalability, and full-stack visibility across on-premise and cloud
infrastructures (e.g., virtual networks, SD-WAN).
- Full-Stack Visibility: Provides
continuous visibility into network performance, device health, and
security status, enabling proactive management and rapid issue
resolution across firewalls, switches, access points, VPNs, and virtual
networks.
- Scalability: Allows seamless
network expansion and adjustment to accommodate organizational growth
and changing network needs, supporting both on-premise and cloud
environments.
- Centralized Management Console:
Provides a single, cloud-managed interface for efficient remote
management of all network devices and configurations, simplifying
network operations and oversight across on-premise, SD-WAN, and cloud
environments.
SD-WAN and
Cloud Network Integration: Leverages SD-WAN to enable secure,
optimized connectivity across multiple locations and between on-premise and
cloud resources.
- Secure, Reliable Connectivity:
Configures SD-WAN capabilities to provide secure, high-performance
connections between distributed sites and cloud-based resources.
- Traffic Prioritization: SD-WAN
routes network traffic based on priority, ensuring optimal bandwidth
allocation and improved application performance across remote locations.
- Seamless Cloud Integration:
Extends network policies and controls to cloud-based networks,
supporting secure, consistent connectivity between on-premise
infrastructure and virtual networks.
Network
Security Management: Provides centralized security configurations
and monitoring across network devices, enforcing policies to protect all
network layers and resources.
- Traffic Monitoring and Filtering:
Monitors inbound and outbound traffic to detect unauthorized or
malicious activity, enforcing security policies for network integrity.
- Intrusion Prevention System (IPS):
Continuously analyzes network traffic to detect and block known attack
signatures and suspicious behavior, helping prevent exploitation of
vulnerabilities.
- DNS Security: Implements DNS-level
threat protection to block malicious domains and prevent access to
harmful sites, reducing the risk of phishing, malware, and other
threats. This provides an additional layer of security by proactively
filtering requests before they reach the internal network.
- Access Control Configuration:
Configures role-based access across the network, ensuring access to
sensitive resources is limited to authorized personnel only.
- Encrypted Remote Access (VPN):
Configures secure, encrypted VPNs to protect data in transit,
maintaining confidentiality for remote and distributed users.
- Content Filtering and Web
Security: Enforces web filtering policies across the network,
blocking access to malicious or non-business sites, enhancing
productivity and network security.
Unified Threat
Detection & Response Across Network Devices: Provides
continuous monitoring, real-time detection, and response capabilities across
all network devices, including SD-WAN components, to address security
threats.
- 24/7 Network Monitoring:
Continuous monitoring of all network devices (firewalls, switches,
access points, VPNs, etc.) for real-time threat detection and response.
- Threat Detection and Incident
Response: Delivers real-time alerts and incident escalation
based on the severity of detected threats, ensuring prompt attention to
critical issues.
- Automated Firmware and Software
Updates: Regularly updates network devices with security
patches and firmware to mitigate vulnerabilities and ensure alignment
with security standards.
Cloud Network
Security: Extends network security policies to cloud-based
virtual networks, ensuring consistent security across on-premise and cloud
environments, including secure connections between physical and virtual
resources.
- Cloud Virtual Network Integration:
Configures and secures virtual network resources in cloud environments,
applying access controls, encryption, and segmentation to maintain
security.
- Cross-Environment Access Control:
Manages access policies consistently across on-premise and cloud
networks, supporting seamless, secure connectivity for distributed
environments.
- Unified Monitoring: Centralizes
monitoring of on-premise, SD-WAN, and cloud network segments, enabling
integrated threat detection and comprehensive reporting across all
network layers.
Wi-Fi Network
Management: Ensures secure, reliable wireless connectivity with
thorough setup, management, and security monitoring across all customer
premises.
- Wireless Site Survey: Conducts
detailed surveys to assess coverage, interference, and performance,
optimizing access point placement for consistent connectivity.
- Wireless Access Point
Configuration: Configures secure access points to deliver
optimized coverage and seamless user connectivity throughout managed
locations.
- Performance Monitoring:
Continuously monitors Wi-Fi performance to proactively detect
connectivity or security issues.
- Standards Compliance: Ensures all
Wi-Fi equipment complies with industry standards, supporting
compatibility and reliability across device types.
- Remote Support: Provides remote
troubleshooting and support during business hours to address Wi-Fi
connectivity and security issues as needed.
Network
Security & Compliance: Implements strong data protection and
aligns network security configurations with industry standards to meet
compliance and regulatory needs.
- Data Encryption: Encrypts all
network transmissions to prevent interception and ensure data
confidentiality.
- Role-Based Access Control:
Configures access policies based on user roles, ensuring critical
network resources are only accessible to authorized users.
- Alignment with Security Standards:
Configures network security in accordance with industry frameworks
(e.g., NIST, CIS Controls) to meet compliance standards relevant to
Customer’s industry.
Incident
Response & Alerting: Provides continuous monitoring,
real-time alerting, and detailed incident reporting for any unusual network
activity or security events.
- 24/7 Monitoring and Alerting:
Continuous monitoring of network security across all devices, with
real-time alerts for suspicious activity or potential security
incidents.
- Incident Reporting: Provides
detailed reports on detected threats, actions taken, and recommendations
for future improvements.
NOTE: This Service requires
Customer cooperation to ensure that all relevant configurations and
access requirements are provided accurately. Onward is not
responsible for security incidents arising from third-party
integrations or external configurations outside our control.
Remediation of network incidents beyond standard monitoring and
alerting is provided on a time and materials basis. Please see
additional terms for remediation services below.
|
|
Remote Monitoring & Management
|
Implementation and facilitation of a
comprehensive Remote Monitoring & Management (RMM) solution from our
designated Third Party Provider. This service provides configuration,
compliance enforcement, continuous monitoring, and proactive maintenance for
endpoints (e.g., workstations, laptops, IoT devices) and servers. The RMM
service also includes workforce productivity tracking and reporting to help
optimize operational efficiency and support employee productivity.
Note: RMM services apply to
all managed endpoints and servers within Onward’s scope. This
service excludes peripheral devices such as printers, scanners, and
other non-core equipment. Additional configurations may be necessary
for specialized or non-standard devices to ensure compatibility with
Onward’s RMM framework.
Policy
Management & Compliance for Endpoints and Servers:
Establishes and enforces policies across all managed devices to ensure
security and operational compliance.
- Policy Configuration for Devices:
Configures security and operational policies for endpoints and servers,
including access controls, security settings, and usage permissions
aligned with corporate policies.
- Compliance Monitoring &
Enforcement: Monitors device compliance with company
policies, generating alerts and corrective actions for non-compliance as
needed.
- Device Enrollment & Access
Control: Manages device enrollment and access controls,
ensuring that only authorized users can access critical systems through
centralized policy settings.
Endpoint
Coverage: Provides tailored management for different device types
to meet specific security and operational requirements.
- Workstations & Laptops:
Manages user-facing devices to ensure policy alignment, security
updates, and performance optimization.
- IoT & Specialized Devices:
Configures and monitors specialized endpoints critical to operations,
including IoT devices, digital signage, kiosks, and conference units, to
maintain consistent performance and security.
- Servers: Manages production and
infrastructure servers to ensure optimal configuration, security
compliance, and performance, supporting front-end and backend
operations.
- Device Provisioning Automation:
Automates the initial setup and configuration of new devices, ensuring
they are equipped with required software, policies, and access
permissions in alignment with Customer’s operational needs. This service
also covers provisioning for on-site, remote, and hybrid environments.
- White Glove Finalization & User
Training: Completes device provisioning with a “white-glove”
service, including personalized setup and detailed user orientation.
This includes training on device functionality, access controls, and
software usage, ensuring smooth transitions and minimizing support needs
during onboarding.
Continuous
Monitoring & Performance Management: Offers real-time
monitoring and performance optimization for all managed devices to
proactively detect and address issues.
- 24/7 Performance & Health
Monitoring: Monitors devices continuously for key indicators
(e.g., CPU, memory, disk usage), enabling rapid response to any issues
that may arise.
- Critical Alerts & Escalation:
Generates alerts for critical issues, such as hardware failures or low
disk space, enabling Onward’s support team to act quickly to prevent
disruptions.
- Capacity Monitoring: Monitors
system capacity to proactively address storage constraints or
performance degradation before they impact operations.
Patch
Management for Endpoints and Servers: Ensures that all managed
devices are updated with the latest security patches and firmware updates.
- Automated Patch Deployment:
Schedules and deploys patches across all endpoints, servers, and IoT
devices, reducing the risk of security vulnerabilities.
- Compliance Verification for Patch
Management: Verifies patch compliance for all devices,
ensuring that updates are correctly applied and align with security
standards.
- Firmware Updates for Devices and
Servers: Deploys firmware updates on applicable devices to
maintain compatibility, security, and performance.
Note: We will keep all managed
hardware and managed software current with critical patches and
updates (“Patches”) as those Patches are released generally by the
applicable manufacturers. Patches are developed by third party
vendors and, on rare occasions, may make the Environment, or
portions of the Environment, unstable or cause the managed equipment
or software to fail to function properly even when the Patches are
installed correctly. We will not be responsible for any downtime or
losses arising from or related to the installation or use of any
Patch. We reserve the right, but not the obligation, to refrain from
installing a Patch if we are aware of technical problems caused by a
Patch, or we believe that a Patch may render the Environment, or any
portion of the Environment, unstable.
Automated
Health Optimization for Devices and Servers: Enhances performance
and health across devices using automation.
- Self-Healing Scripts: Uses
automation to address common issues on endpoints and servers without
requiring manual intervention.
- Performance Optimization:
Schedules automated performance enhancements for both endpoints and
servers, optimizing CPU, memory, and storage efficiency.
- Disk Cleanup & Optimization:
Regularly cleans temporary files and unnecessary data to free up storage
and ensure optimal device performance.
Workforce
Productivity Tracking: Provides insights into productivity trends
and resource utilization to support workforce efficiency and alignment with
organizational goals.
- Usage Analytics: Monitors device
usage to track active hours, application usage, and productivity trends
to help inform operational decisions.
- Activity Reporting: Provides
activity summaries to management, helping identify productivity patterns
and opportunities for operational improvement.
- Compliance Tracking for Remote
Work: Monitors remote work compliance to ensure employees
adhere to approved productivity guidelines and policies.
Remote Access
& Support: Enables secure remote access and troubleshooting
for all managed devices to provide uninterrupted support.
- Secure Remote Access: Facilitates
secure, remote access for troubleshooting across all devices, ensuring
data confidentiality and quick issue resolution.
- Audited Remote Sessions: Logs and
audits all remote access sessions to support compliance requirements.
- End-User Support &
Troubleshooting: Provides support for end users during
business hours, assisting with device connectivity, configurations, and
other technical issues.
Incident
Response & Alerting: Delivers immediate alerting and incident
response to address unusual device activity or security threats.
- 24/7 Monitoring and Alerting:
Continuous monitoring across all devices for real-time alerts related to
suspicious activity or potential security incidents.
- Incident Reporting: Provides
detailed incident reports, including detected threats, corrective
actions, and recommendations for improved security.
NOTE: This RMM service applies
to devices and servers within Onward’s managed scope. Peripheral
devices (e.g., printers, scanners) and non-core equipment are
excluded from this service. Specialized or non-standard devices may
require additional configurations to ensure full compatibility with
Onward’s RMM management framework.
|
|
Remote Helpdesk & Onsite
Support
|
Implementation and facilitation of a
comprehensive remote helpdesk and onsite support solution. This service
provides tiered support for troubleshooting, incident resolution, and
escalation across all managed assets. Remote Helpdesk offers responsive,
efficient support during standard business hours, while Onsite Support
addresses incidents that require physical intervention at the customer’s
premises.
Note: Remote Helpdesk and
Onsite Support are limited to managed assets within Onward’s service
scope. Requests involving non-managed or third-party equipment may
incur additional charges or require referral to the original
equipment provider.
Remote Helpdesk
Support: Offers remote technical support to assist with
troubleshooting and issue resolution for managed devices, software, and
infrastructure.
- Scope of Support: Remote Helpdesk
is available to address technical issues on managed devices and software
within the agreed scope, including troubleshooting hardware and software
failures, network connectivity issues, and operational disruptions.
- Service Hours: Standard Remote
Helpdesk support is available Monday through Friday, from 8:00 AM to
5:00 PM Eastern Time, excluding holidays. Support requests outside these
hours may be subject to increased rates and require prior scheduling.
- Support Request Channels:
Customers may submit support requests via:
- Escalation Process: Incidents
unresolved within the standard response time will be escalated to senior
technicians or specialized teams. Customers will be informed of
escalation actions and receive updates on expected resolution timelines.
NOTE: Remote Helpdesk support
may involve remote screen-sharing or device access, requiring
customer approval for each session. Some issues may require
specialized support at an additional charge.
Onsite Support Services:
Dispatches certified technicians to the customer’s location for
incidents that cannot be resolved remotely.
- Scope of Onsite Support: Onsite
Support is available for managed assets under Onward’s service scope
when remote troubleshooting is unsuccessful or physical intervention is
required. Common services include hardware repairs, network diagnostics,
and server maintenance.
- Scheduling and Availability:
Onsite Support is subject to technician availability and is scheduled
based on incident urgency. Standard hours are Monday through Friday,
8:00 AM to 5:00 PM Eastern Time. After-hours and emergency support may
incur additional charges.
- Travel and Onsite Charges: Travel
expenses and onsite service charges apply as specified in the agreement.
Charges include travel fees, time onsite, and any required materials.
- Onsite Response Time: Onsite
response times and prioritization follow the terms outlined in the
Service Level Agreement (SLA).
- Escalation and Reporting: If the
issue persists after the initial visit, technicians coordinate with
senior engineers and relevant teams for prompt resolution. A report
detailing the onsite service and any recommended follow-up actions will
be provided.
NOTE: Onsite Support is
limited to managed assets and does not cover third-party or
customer-provided equipment. Non-covered equipment may incur
additional service charges or require referral to the original
equipment provider.
Proactive Support & Issue
Prevention: Provides proactive monitoring and periodic checks
to minimize recurring issues and system downtime.
- Health Checks & Preventive
Maintenance: Conducts periodic health checks on managed
systems to identify and address potential issues before they affect
operations.
- Scheduled Maintenance Windows:
Maintenance activities, such as system updates and backups, are
scheduled outside regular business hours to minimize operational impact.
- Customer Notifications: Customers
receive advance notification of preventive maintenance, scheduled
downtime, or updates to the Helpdesk service scope.
NOTE: Proactive support
activities are scheduled based on business needs and may vary
depending on system usage patterns, customer requirements, and
service agreements.
End-User Support & Training
Assistance: Provides basic troubleshooting and user
assistance, including training support on common software and systems.
- Basic Troubleshooting Assistance:
Assists end-users in resolving common issues with managed software,
device configurations, and connectivity.
- Guided Walkthroughs: Offers
step-by-step guidance for routine tasks, such as accessing shared
resources, configuring email, and connecting to VPN.
- User Training Sessions: Arranges
user training sessions on key systems or applications upon request,
subject to technician availability.
NOTE: End-user support is
limited to managed systems and does not include specialized
application training unless expressly included in the service
agreement.
Incident Reporting and
Documentation: Provides detailed documentation and reporting
for incidents, ensuring full visibility into issue resolution and
support activity.
- Incident Documentation: All
support requests are documented in the ticketing system, including issue
descriptions, resolution steps, and any follow-up actions.
- Service Reports: Monthly reports
summarizing support activity, response times, and common incidents are
available upon request, providing insight into system health and support
efficiency.
- Customer Feedback & Quality
Assurance: Customers are encouraged to provide feedback on
support interactions. Feedback is reviewed to improve service quality.
NOTE: Documentation and
reporting cover managed services and do not include third-party or
unsupported systems unless otherwise specified in the agreement.
|
|
Co-Managed Services
|
Onward’s Co-Managed IT Services provide an
adaptable IT management framework, enhancing the capabilities of the
Customer’s IT team through shared responsibilities, specialized expertise,
and access to essential tools and support functions. This service includes
dedicated resources for IT strategy, infrastructure management, and support
assistance, allowing the Customer to maintain operational control while
benefiting from Onward’s technical and governance expertise.
- Collaborative Support Framework:
Onward assists the Customer’s IT team with support responsibilities,
providing guidance and escalation resources for day-to-day technical
issues. While the Customer’s team retains primary control over user
support, Onward offers structured assistance, including remote
troubleshooting, escalation management, and periodic support for complex
technical issues that exceed the standard scope.
- IT Infrastructure Management:
Onward manages and supports key IT infrastructure components, including
provisioning, configuration, and maintenance of servers, cloud
environments, and network devices. Infrastructure services are tailored
to align with Customer goals, ensuring efficient deployment and
management of critical IT resources.
- Change and Incident Coordination:
Onward oversees change management processes, handling requests,
approvals, and communications for major updates or new technologies
introduced within the managed environment. For incidents that impact IT
services, Onward collaborates with the Customer’s team to expedite
resolution, providing a systematic approach to incident handling and
response.
- Strategic IT Guidance: Onward
provides regular consultation sessions to review IT strategy, offering
insights and recommendations to align IT services with Customer business
objectives. This includes semi-annual or annual strategic reviews to
assess long-term goals and the current IT environment.
- ITSM Platform Access and
Reporting: Customers receive access to Onward’s IT Service
Management (ITSM) platform, which includes tools for asset tracking,
ticket management, and compliance reporting. This platform integrates
analytics and dashboards for visibility into IT operations, empowering
the Customer’s team with actionable insights and efficient tracking of
service performance.
- Asset and Lifecycle Management:
Onward provides asset lifecycle services, including provisioning,
tracking, and maintenance. This structured approach ensures that IT
assets remain secure, up-to-date, and compliant with organizational
standards, supporting smooth operation throughout each asset’s
lifecycle.
Note: The Co-Managed IT
Services are intended to provide supplementary support and
expertise. Customer retains primary responsibility for in-house user
support and daily IT operations, with Onward acting as a technology
advisor and resource to ensure effective, compliant IT management.
Refer to the Co-Managed Services
Policy section for details on roles, responsibilities,
and escalation protocols specific to co-managed environments.
|
|
IT Service Management (ITSM) Platform
|
Implementation and facilitation of a
comprehensive IT Service Management (ITSM) platform by Onward, designed to
enhance service delivery, operational transparency, and support efficiency
for Customer’s IT environment. This service includes a centralized portal,
asset management, ticketing, reporting, and automated workflows, providing
end-users and management with easy access to IT support and insights into
service metrics.
Note: Onward administers the
ITSM platform, offering training and guidance on its effective use.
Customer’s IT personnel are responsible for adhering to internal
procedures and protocols for ITSM utilization.
Customer Portal
Access: Provides a secure, accessible portal for Customer to
submit, track, and monitor IT service requests, with tools for automation
and reporting dashboards.
- Ticket Submission and Tracking:
Permits end-users to log IT support requests and monitor resolution
status.
- Service Request Monitoring:
Enables Customer to view updates and timelines for ongoing service
requests.
- Automation Access: Allows
authorized end-users to initiate pre-approved automated tasks, such as
password resets or account unlocks, as enabled by Onward.
- Managerial Dashboards: Provides
Customer’s managers and executives with real-time access to IT service
metrics, SLA compliance data, and performance analytics.
Ticketing and
Incident Management: Centralized logging, prioritization, and
AI-assisted management of IT support requests for consistent service
delivery.
- AI-Driven Ticket Classification:
Automatically categorizes support requests by issue type and urgency to
prioritize effectively.
- Automated Ticket Routing: Assigns
tickets to appropriate teams based on classification, priority level,
and service-level targets.
- Response Time Protocols: Aligns
ticket handling with designated priority levels to meet SLA
requirements.
- Escalation Procedures: Escalates
incidents that exceed standard resolution times to senior technicians,
with Customer notified of escalation steps.
Asset
Management and Integration: Maintains records of IT assets,
including hardware, software, and licenses, with real-time data updates.
- Live Asset Data: Integrates with
vendor platforms for accurate, real-time asset tracking.
- User-to-Asset Mapping: Tracks
asset assignments to end-users for accountability and visibility.
- Lifecycle and Location Status:
Manages asset lifecycle stages, including status updates for production,
reprovisioning, and decommissioning.
Project
Tracking and Business Review Reports: Tracks IT project
milestones and provides regular reviews to assess IT support effectiveness.
- Project Status Tracking: Monitors
ongoing IT projects, including milestones, resource allocations, and
deadlines.
- Monthly Reports: Summarizes IT
activity, SLA adherence, and resolution metrics.
- IT Service Recommendations: Offers
recommendations based on periodic reviews, aimed at improving IT support
quality and efficiency.
Dashboards and
Reporting: Offers detailed reporting tools to support oversight
and performance evaluation.
- Managerial Dashboards: Access for
leadership to monitor metrics such as resolution times, resource usage,
and performance data.
- Custom Reports: Customer may
generate reports tailored to specific IT metrics, SLA achievements, or
compliance needs.
NOTE: SLA management terms
apply as outlined in this Guide. Requests for modifications to SLA
targets or escalation paths may require adjustments to the service
scope.
|
|
Orchestration and Automation Platform
|
Implementation and facilitation of an
Orchestration and Automation Platform by Onward, aimed at automating
business and system processes within Customer’s managed IT environment. This
platform evaluates and integrates compatible cloud services and systems to
streamline operations, reduce manual effort, and enhance operational
consistency. The platform functions under Onward’s management scope,
aligning with DevOps principles and practices when applicable, as outlined
in the DevOps Addendum.
Note: Automation solutions
apply to systems and services within Onward’s managed scope.
Identification, evaluation, and execution of automation
opportunities require collaboration with Onward’s DevOps team to
ensure compatibility and alignment with Customer’s operational
needs.
Process
Evaluation & Automation Identification: Identifies automation
opportunities within Customer’s business and IT processes, focusing on
compatibility with the Customer’s managed environment.
- Automation Feasibility Assessment:
Evaluates business and system processes to determine their potential for
automation within the Customer’s IT infrastructure.
- Integration with Managed Services:
Ensures that proposed automations align with Onward’s supported
infrastructure, cloud services, and policy standards.
- Collaboration with DevOps for Complex
Workflows: Complex automations requiring advanced workflows
or multi-system integrations are executed in collaboration with Onward’s
DevOps service.
Workflow
Automation Implementation: Deploys rule-based workflows to
automate recurring tasks, minimizing manual involvement and supporting
operational efficiency.
- Automated Task Execution:
Configures automated workflows for routine tasks (e.g., exception
handling, data synchronization) across approved environments.
- Onboarding/Offboarding Automation:
Automates key steps in employee onboarding and offboarding, streamlining
account setup, permissions configuration, and device allocation for new
hires. For offboarding, this includes secure access revocation, device
reset, and data backup. This automation reduces manual work, enhances
security, and ensures compliance with HR and IT policies.
- Self-Service Automation: Publishes
specific automations to the Customer’s ITSM portal, enabling authorized
end-users to initiate actions independently.
- Event-Triggered and Scheduled
Automations: Enables event-triggered and scheduled
automations for consistent workflow execution aligned with business
timelines.
System and
Cross-Platform Integration: Integrates supported applications and
IT systems to synchronize data and execute orchestrated workflows.
- Data Synchronization Across
Systems: Automates data updates and ensures data consistency
across systems under Onward’s management.
- Application Compatibility and
Integration: Facilitates seamless operations by integrating
compatible business applications within the managed IT environment.
- API-Based Data Ingestion:
Leverages API connections to pull real-time data from approved
platforms, enhancing accuracy and reliability.
Comprehensive
Monitoring & Analytics: Provides visibility into active
automations, offering insights for performance assessment and optimization.
- Real-Time Workflow Tracking:
Monitors workflow status, completion times, and task outcomes for
operational oversight.
- Performance Analytics: Tracks
efficiency metrics, completion rates, and task durations to identify
bottlenecks and optimization opportunities.
- Customizable Reporting: Generates
tailored reports on workflow performance, automation impact, and
resource utilization to support decision-making.
End-User Access
and Permissions: Manages access permissions, ensuring authorized
users interact with published automations.
- Role-Based Access Control:
Configures permissions to restrict access to specific users based on
their roles and responsibilities.
- Audit Trail and Accountability:
Logs user interactions with automation workflows, providing a record of
task initiations and completions.
- Training and Support for Authorized
Users: Provides training and resources to ensure end-users
engage with automations effectively and securely.
NOTE: This service requires
Customer’s active cooperation by providing access to necessary
systems and process details. Automations are restricted to Onward’s
managed environment. Expansion of scope may incur additional fees or
require updates to the existing service agreement.
|
|
Virtual Chief Information Officer (vCIO) / Virtual
Chief Technology Officer (vCTO)
|
Implementation and facilitation of strategic IT
leadership through a Virtual Chief Information Officer (vCIO) or Virtual
Chief Technology Officer (vCTO). This service empowers Customer to align IT
objectives with business goals, optimize technology investments, and
leverage data-driven planning for growth and operational efficiency.IT Strategy Development: Collaborates
with Customer’s executive team to develop an IT strategy aligned with
business goals and industry standards.
- IT Strategy Development:
Collaborates with Customer’s executive team to craft an IT strategy
aligned with business objectives and industry standards.
- Technology Roadmap Planning:
Develops a roadmap outlining critical projects, upgrades, and
improvements aligned with evolving business needs.
- Quarterly Business Reviews (QBRs) and
Risk Assessments: Conducts QBRs and risk assessments to
evaluate IT performance, identify vulnerabilities, and recommend
necessary actions.
- Budgeting and Forecasting:
Provides strategic budgeting and financial forecasting to align
technology investments with organizational goals.
- Contract Management: Oversees
technology-related contracts, including review, negotiation, and renewal
planning, ensuring effective resource allocation.
- Recommendation Planning: Delivers
customized recommendations on technology improvements, vendor
partnerships, and operational efficiencies based on performance and
strategic goals.
- IT Strategic Planning Platform
Access: Provides access to Onward’s IT Strategic
Planning Platform for real-time data on QBRs, budgeting forecasts,
contract status, and risk assessments.
NOTE:
Access to the IT Strategic Planning Platform requires an
additional fee. This access enables Customer to utilize the platform
for strategic insights, real-time updates, and proactive management
of IT assets and contracts.
- Vendor Management: Manages
third-party vendor relationships to ensure compliance, performance, and
alignment with Customer’s strategic goals.
- Flexible Cadence Calls: Regular
cadence calls are available on a weekly, biweekly, or monthly basis,
based on Customer’s needs, to discuss operational adjustments, strategic
progress, and immediate concerns.
- Annual Strategic Review (Upon
Request): Available upon Customer’s request, this review
assesses the strategic alignment of IT services with business goals and
discusses necessary large-scale initiatives or adjustments.
NOTE:
Customer’s active participation in scheduled reviews and use
of the IT Strategic Planning Platform is encouraged to enhance
strategic alignment. Non-participation may result in missed
improvement opportunities and impact IT strategy alignment.
|
|
Wireless Network Gateway (HaaS) Subscription
|
Implementation and facilitation of a managed
wireless network gateway solution utilizing high-speed satellite-based
units. This subscription provides options for Standard or High Performance
models based on specific site connectivity needs and includes comprehensive
storm servicing, mounting hardware, installation, and optional cloud-managed
firewall/router or uplink aggregator for multi-unit setups. Ideal for remote
sites without cable access and/or as a failover connection to a primary
business-class circuit, this solution ensures seamless connectivity and
redundancy.
- Satellite-Based Unit Deployment:
Supplies either Standard or High Performance satellite units tailored to
site requirements, providing high-speed internet access in areas lacking
traditional cable infrastructure.
- Mounting Hardware and
Installation: Professional installation includes mounting
hardware to ensure optimal unit placement and secure, reliable
connectivity at each site.
- Storm Servicing: Proactive
maintenance during adverse weather conditions, including hardware
inspections and remote monitoring to minimize weather-related
connectivity disruptions.
- Cloud-Managed Firewall/Router
(Optional): Offers a cloud-managed firewall or router for
enhanced security, allowing centralized traffic control, access
management, and policy enforcement.
- Uplink Aggregation (Optional):
Configures an uplink aggregator for sites requiring multiple units,
delivering redundancy and increased bandwidth as needed.
- Failover Connectivity for Business-Class
Circuits: Configures the unit as a failover connection to
existing business-class circuits, providing reliable backup connectivity
in the event of primary circuit downtime.
- Secure Remote Management and
Monitoring: Centralized management of network configurations
and unit performance, with real-time status alerts and proactive
troubleshooting.
- Real-Time Network Health
Monitoring: Continuous monitoring of network performance,
including connectivity status and immediate alerts for any issues.
- Comprehensive Site Assessment:
Conducts an assessment to determine the optimal configuration, equipment
placement, and installation strategy to align with specific site
requirements.
NOTE:
Onward will handle deployment, mounting, and ongoing
maintenance of the wireless network gateway solution, including
satellite units and related equipment to ensure reliable
connectivity. Additional site assessments, optional configurations,
or specific customer requirements may incur additional charges based
on the service scope.
Optional Add-Ons
- Guest Network Configuration:
Establishes a secure guest network to manage visitor access while
maintaining the integrity of the primary network.
- Hardware and Software Updates:
Regular firmware updates for the satellite unit, firewall, router, and
associated devices, ensuring compliance with the latest security and
performance standards.
- Network Expansion Services:
Enables expansion with additional units or components as Customer’s
needs evolve, configured according to established security and
performance protocols.
NOTE:
This Wireless Network Gateway Subscription covers only
devices and services within Onward’s management scope. Connectivity
or security issues related to third-party devices or configurations
outside of this scope are not covered by Onward’s responsibilities
within this subscription.
|
|
Fleet Management
|
Implementation and facilitation of a
comprehensive Fleet Management solution that enables real-time GPS tracking
for a diverse set of assets, including vehicles, boats, trailers, and mobile
devices. This service includes OBD-II tracking devices for vehicles,
compatible fleet telematic units for specialized assets, and secure mobile
applications for iOS and Android devices managed under Onward’s Mobile
Device Management (MDM) platform. Fleet Management delivers location
tracking, route optimization, and operational insights to support efficient
fleet utilization, compliance, and security.
Features
- Real-Time GPS Tracking: Provides
continuous location tracking for vehicles, boats, trailers, and managed
iOS/Android devices, delivering an integrated view of all fleet and
mobile assets in motion.
- Diverse Asset Compatibility:
Includes OBD-II devices for standard vehicle diagnostics and fleet
telematic tracking units for specialized assets (e.g., boats, trailers),
ensuring comprehensive tracking across the fleet.
- Mobile Application for Managed
Devices: Extends tracking capabilities to iOS and Android
devices, allowing managers to monitor team locations and usage of mobile
devices within the fleet framework.
- Route Optimization: Recommends
efficient routes based on real-time data, reducing fuel consumption,
travel time, and enhancing overall fleet productivity.
- Geo-Fencing Capabilities: Enables
customizable geo-fenced zones with alerts for entry and exit, improving
security and supporting compliance for assets in sensitive or restricted
locations.
- Activity Monitoring: Records data
on asset usage, including location, speed, idle time, and duration of
stops, supporting operational insights and safety tracking.
- Historical Data & Reporting:
Stores detailed trip history and utilization data for reporting on asset
efficiency, compliance, and driver/operator patterns.
- Maintenance Alerts: Provides
automated reminders based on mileage, hours of use, or specific
conditions, helping prevent costly repairs and extend asset lifespan.
- Driver and Operator Behavior
Analytics: Monitors behaviors such as speeding, hard braking,
and rapid acceleration to support safety policies and reduce risk.
- Integrated Mobile Device Tracking:
Allows iOS and Android devices to be tracked as part of the fleet under
Onward’s MDM, with secure data access and device permissions to ensure
compliance with organizational security policies.
NOTE: Fleet Management encompasses
GPS tracking for vehicles, boats, trailers, and compatible mobile
devices managed by Onward. Additional or custom assets may require
special integration agreements or incur extra fees.
- Enhanced Analytics &
Dashboards: Offers advanced dashboards with detailed insights
into fleet metrics, usage patterns, and cost analysis.
- Third-Party System Integration:
Supports integration with logistics or asset management systems,
consolidating fleet data across platforms for unified management.
- Custom Alerts and Notifications:
Configurable alerts for specific events, including unauthorized usage,
off-hours operation, or prolonged idle times.
NOTE: Fleet Management services
are limited to Onward-managed assets. Requests to add non-standard
assets or integrate additional third-party systems may require
additional fees or agreements.
|
|
VOIP Management
|
Implementation and facilitation of a robust
cloud-based VOIP management solution, designed to enhance communication,
streamline administration, and provide data-driven insights for quality
improvement. This service encompasses full deployment, user management, and
proactive monitoring of VOIP systems across desktop, mobile, and web
platforms, creating a scalable communication framework tailored to diverse
operational needs. An optional Quality Management and Analytics platform is
also available to offer advanced insights and detailed performance tracking.
- Cloud-Based VOIP System
Deployment: Deploys a cloud-based VOIP solution that supports
voice, video, and messaging capabilities across multiple access points,
including desktop, mobile, and web applications, for seamless, flexible
communication.
- User Configuration and Management:
Manages all aspects of VOIP user setup and access, including number
assignments, extension configurations, and permission settings, tailored
to the specific communication requirements of the organization.
- Device Flexibility: Offers support
for multiple device types, including softphones, desktop handsets, and
mobile applications, ensuring flexible communication options that adapt
to users’ preferences and organizational needs.
- Automated Call Routing and IVR
Setup: Configures sophisticated call routing rules and
auto-attendant functionalities, including IVR systems, call forwarding,
and priority call routing to optimize call flow and minimize
disruptions.
- Integration with Collaboration
Platforms: Seamlessly integrates with productivity tools and
collaboration platforms, enhancing workflows and unifying communications
within the existing IT infrastructure.
- Scalability and Adaptability:
Designed to support remote, hybrid, and in-office environments, with
capabilities to adjust user counts and service features as the
organization grows or changes.
- Standard Analytics and Reporting:
Provides valuable metrics and insights on call patterns, call duration,
and usage to aid performance monitoring, resource planning, and
operational oversight.
- Security and Compliance:
Implements secure data encryption protocols, both in transit and at
rest, ensuring compliance with relevant voice and communication data
standards across industries.
- Quality of Service (QoS)
Monitoring: Continuously monitors call quality parameters
such as bandwidth usage and latency to maintain high audio and video
standards, ensuring a consistent user experience.
NOTE:
VOIP Management & Analytics services apply exclusively to
cloud-based VOIP systems and do not cover legacy PBX or analog
systems. Certain features may necessitate additional training for
administrators or subscription adjustments, depending on the
customer’s specific requirements. There are additional terms related
to the VoIP service, including your use of E911 features, toward the
end of this Services Guide. Please read them carefully. You may be
required to sign an additional consent form indicating your
understanding and acceptance of the limitations of 911 dialing using
the VoIP services.
Optional Add-On: Quality Management and
Analytics Platform
- Enhanced Quality Management:
Deploys a comprehensive Quality Management platform that tracks
communication-related key performance indicators (KPIs) to monitor
quality, call handling, and user satisfaction levels.
- Advanced Analytics and Reporting:
Provides detailed call analytics, with access to custom dashboards and
department-specific reporting, allowing for granular performance
assessments and actionable insights.
- Customizable Performance Metrics:
Enables the configuration of specific quality metrics to monitor call
performance, service levels, and productivity benchmarks, empowering
organizations to set and track targeted quality standards.
NOTE:
The Quality Management and Analytics Platform is available as
an optional add-on and may require additional licensing or
subscriptions. Please contact Onward for further details on pricing
and customization options.
|
|
Web Development and Hosting
|
Implementation and facilitation of a reliable, scalable website hosting and
development solution from our designated Third Party Provider. This service
includes managed hosting, ongoing maintenance, and technical support to
ensure your website (“Website”) remains operational, updated,
and compliant with security standards. The Website will be available on a
24×7 basis, excluding scheduled downtime or force majeure events. Each
Website is hosted on a shared server environment, with a unique address
assigned to each customer.
-
Web Development and Technical
Maintenance: Provides ongoing maintenance of the Website,
including plugin updates, configuration adjustments, and support for
technical integrations (e.g., APIs, third-party software). This service
ensures that the Website operates efficiently and remains compatible
with necessary integrations. Creative design work, such as custom
graphics or website layout redesign, is outside the scope of this
service and will be provided through a designated third-party.
-
Migration of Servers: As part of
regular operations, Onward or our designated Third Party Provider may
migrate the servers hosting the Website to maintain optimal performance
and security. This migration process will not impact the continuity of
the hosting services; however, due to the potential for migration, a
permanent or dedicated IP address is not guaranteed.
-
Administration: Access is
provided to a secure dashboard where customers may make configuration
adjustments to the hosted environment. We strongly advise customers to
refrain from making changes without Onward’s guidance, as Onward
cannot assume responsibility for issues arising from customer-directed
adjustments. Onward will remediate issues caused by customer changes
only if made under our guidance or written direction.
-
Resource and Load Balancing:
Bandwidth is shared across all hosted websites and is monitored to
ensure fair distribution among all Onward customers. Onward reserves the
right to load-balance bandwidth or restrict access if a customer’s
website activity disproportionately impacts the network, creating
potential limitations for other users.
-
Backup Services: Daily backups
are conducted as part of the Standard Backup Service, covering basic
data protection for the Website. This backup is intended as a standard
security measure and does not replace a comprehensive backup and
disaster recovery solution. Customers are encouraged to maintain a
separate backup and recovery solution for more extensive protection.
-
Storage and Security: Onward,
alongside our third-party providers, applies industry-standard security
measures to safeguard the Website and hosted environment against
unauthorized access. While Onward takes reasonable precautions, no
system can guarantee absolute security, and we cannot warrant that the
hosted environment will remain entirely free from unauthorized access or
malware.
NOTE:
Customer, as well as any visitors to the Website, must comply
with our Acceptable Use Policy, located at the end of this Services
Guide. This policy outlines acceptable usage guidelines and
restrictions to maintain service quality and security across
Onward’s managed hosting environment.
|
|
Print Management
|
Implementation and facilitation of a Print
Management solution in collaboration with a designated Third Party Provider.
This service covers the logical configuration, network integration, and
deployment of Print Management Platforms by Onward. The Third Party Provider
is responsible for the hardware provisioning, physical servicing, and
management of consumables, ensuring seamless and efficient print operations.
- Centralized Print Management:
Implements centralized control over print activities, including
monitoring, user access, and secure print release, through supported
Print Management Platforms.
- Network Integration and Cloud Printing:
Configures print servers and integrates cloud solutions like
Microsoft Universal Print to support secure, flexible printing across
on-premise and cloud environments.
- Remote Monitoring and Usage Analytics:
Provides real-time tracking of device status, usage, and
performance metrics, allowing proactive management and consumable
planning.
- End-User and IT Support: Assists
users with accessing print services, resolving permissions, and
addressing connectivity issues as part of Onward’s support scope.
- Onward’s Responsibilities
- Logical and Network Configuration:
Configures the network settings, print servers, and access controls for
secure, efficient print operations across all managed workstations and
cloud environments.
- Specialty Printer Configuration:
Directly provisions and configures specialty printers, such as label and
unique format printers, to meet Customer’s operational needs.
- Print Management Platform
Implementation: Deploys and configures print management
solutions, such as PaperCut and PrinterLogic, to enable centralized
control over permissions, print release, and user access.
- Cloud Printing Solutions:
Implements Microsoft Universal Print for eligible environments,
providing cloud-based printing capabilities that eliminate the need for
on-premise print servers.
- Integration with Cost Recovery
Systems: Sets up cost recovery features within print
management platforms to track and allocate print expenses by user or
department, supporting budgeting and resource management.
- Third Party Provider’s
Responsibilities
- Hardware Provisioning and
Physical Maintenance: Supplies and services the
multi-function printers, 3D printers, and imaging devices,
performing routine maintenance, repairs, and any physical device
servicing.
- Consumable Management:
Monitors usage levels for consumables (e.g., ink, toner, and
paper) and manages refills to ensure uninterrupted print
service.
- Hardware and Device
Support: Provides support for physical device issues
beyond logical or network-related configurations.
|
|
DevOps BI & Data Integration
|
Implementation and facilitation of a DevOps
solution from Onward, designed to automate, integrate, and streamline
software development, deployment, and data management processes. Onward’s
DevOps service incorporates industry-standard tools to enable continuous
delivery, version control, and collaboration, while also providing
comprehensive Data Integration & Business Intelligence (BI) capabilities
to enhance data-driven decision-making. Our services cover the entire
lifecycle of DevOps, from planning and development to maintenance, ensuring
secure and scalable solutions.
- Data Integration & Business
Intelligence (BI)
- Data Ingestion and ETL
Processes: Onward configures and manages secure data
pipelines for data ingestion, transformation, and integration
from multiple sources, ensuring data accuracy and consistency.
- Business Intelligence Dashboards
and Reporting: Onward implements BI dashboards and
reporting solutions to provide real-time insights, customized
metrics, and on-demand visualizations that support strategic
decision-making.
- ERP System Integration:
Onward facilitates ERP integration with other business systems,
providing performance monitoring and routine maintenance to
ensure consistent data flow.
- Data Security and
Governance: Onward applies security measures and
governance protocols to ensure data integrity, compliance, and
controlled access across platforms.
- Azure DevOps Management
- CI/CD Pipelines
Configuration: Onward configures and manages
Continuous Integration/Continuous Delivery (CI/CD) pipelines
within Azure DevOps to automate the build, testing, and
deployment cycles. This enhances speed, reliability, and
stability in releasing software updates.
- Project and Sprint
Management: Onward assists in organizing and managing
project backlogs, sprint planning, and task assignments, using
Azure DevOps Boards to streamline development workflows and
enhance team productivity.
- Automated Testing and Quality
Assurance: Onward implements and monitors automated
testing procedures within Azure DevOps to ensure code quality
and application performance standards are met throughout the
development lifecycle.
- Release Management and
Versioning: Onward establishes and maintains a
versioned release process using Azure DevOps, providing clear
visibility into release stages and deployment histories for
improved change control.
- Git-Based Version Control
- Repository Management:
Onward configures and manages Git repositories, implementing
branch strategies and access controls to maintain secure,
efficient version control and collaboration.
- Code Review and
Collaboration: Onward enables structured code review
workflows within Git, including pull requests and approval
protocols, to enhance collaboration and maintain code quality.
- Branching Strategies and Workflow
Customization: Onward implements branching strategies
tailored to the project’s needs (e.g., feature branching,
Gitflow), facilitating structured and efficient development
workflows.
- Integration with CI/CD
Pipelines: Onward integrates Git repositories with
CI/CD pipelines to ensure code changes are automatically tested
and deployed, aligning with DevOps best practices.
- Core DevOps Services
- Infrastructure as Code
(IaC): Onward configures infrastructure through code,
enabling repeatable environment setups and version control to
support scalability and consistency.
- Monitoring and Feedback
Loops: Onward provides continuous monitoring and
feedback, supporting rapid detection and resolution of issues to
maintain performance. Dashboards and analytics are made
accessible to authorized stakeholders.
- Collaboration and
Governance: Onward facilitates collaboration between
development and IT operations teams, establishing protocols,
governance standards, and KPIs for performance tracking.
NOTE:
Not all listed services may be included in the standard
DevOps engagement. Services are implemented selectively and tailored
to align with the Customer’s environment and business requirements.
For further details on specific responsibilities and expectations,
refer to the DevOps
Addendum. Additional requests outside the defined scope
may require adjustments to service costs.
|
Policies and Procedures Applicable to Services
Software
Licensing: All software provided to you by or through Onward is licensed, not sold,
to you (“Software”). In addition to any Software-related requirements described in Onward’s Master
Services Agreement, Software may also be subject to end user license agreements (EULAs), acceptable use
policies (AUPs), and other restrictions all of which must be strictly followed by you and any of your
authorized users.
When installing/implementing software licenses
in the managed environment or as part of the Services, we may accept (and you agree that we may accept)
any required EULAs or AUPs on your behalf. You should assume that all Software has an applicable EULA
and/or AUP to which your authorized users and you must adhere. If you have any questions or require a
copy of the EULA or AUP, please contact us.
Hardware
as a Service (HaaS): The following applies to all hardware, devices, and accessories
that are provided to you on a “hardware as a service” basis (“HaaS Equipment”).
• Deployment.
We will deploy HaaS Equipment within the timeframe stated in the Quote, provided that you promptly
provide all information that we reasonably request from you to complete deployment. This deployment
guaranty does not apply to any software, other managed services, or hardware devices other than the HaaS
Equipment. In addition, this deployment time frame may be extended as necessary to accommodate delays
that are outside of our reasonable control, such as embargoes, labor or supply chain shortages, or other
force majeure events. If you wish to delay the deployment of the HaaS Equipment, then you may do so if
you give us written notice of your election to delay no later than five (5) days following the date you
sign the Quote. Deployment shall not extend beyond two (2) months following the date on which you sign
the Quote. You will be charged at the rate of fifty percent (50%) of the monthly recurring fees for the
HaaS-related services during the period of delay. Following deployment, we will charge you the full
monthly recurring fee (plus other usage fees as applicable) for the full term indicated in the Quote.
- Repair/replacement
of HaaS Equipment. Onward will endeavor to repair or replace HaaS Equipment
within five (5) business days following the business day on which the applicable problem is
identified by, or reported to, Onward and has been determined by Onward to be incapable of being
remediated remotely. This warranty does not include the time required to rebuild your system, such
as the time required to configure a replacement device, rebuild a RAID array, reload the operating
system, reload and configure applications, and/or restore from backup (if necessary).
• Technical Support
for HaaS Equipment. We will provide technical support for HaaS Equipment in
accordance with the Service Levels listed in this Services Guide.
• Usage.
You will use all HaaS Equipment for your internal business purposes only. You shall not sublease,
sublicense, rent or otherwise make the HaaS Equipment available to any third party without our prior
written consent. You agree to refrain from using the HaaS Equipment in a manner that unreasonably or
materially interferes with our other hosted equipment or hardware, or in a manner that disrupts or that
is likely to disrupt the services that we provide to our other Customers. We reserve the right to
throttle or suspend your access and/or use of the HaaS Equipment if we believe, in our sole but
reasonable judgment, that your use of the HaaS Equipment violates the terms of the Quote, this Services
Guide, or the Agreement.
• Return of HaaS
Equipment. Unless we expressly direct you to do so, you shall not remove or disable,
or attempt to remove or disable, any software agents installed in the HaaS Equipment. Doing so could
result in network vulnerabilities and/or the continuation of license fees for the software agents for
which you will be responsible, and/or the requirement that we remediate the situation at our
then-current hourly rates, for which you will also be responsible. Within ten (10) days after the
termination of HaaS-related Services, Customer will provide Onward access to the premises at which the
HaaS Equipment is located so that all such equipment may be retrieved and removed by us. If you fail to
provide us with timely access to the HaaS Equipment or if the equipment is returned damaged (normal wear
and tear excepted), then we will have the right to charge you, and you hereby agree to pay, the
replacement value of all such unreturned or damaged equipment.
DevOps. If DevOps (or “DevOps as a Service”) is
listed in the Quote, then we will provide such services in the scope, manner, and timing described in
the DevOps Addendum, below.
Covered
Environment. Services will be applied to the number of devices indicated in the Quote
(“Covered Hardware”). The list of Covered Hardware may be modified by mutual consent (email is
sufficient for this purpose); however, we reserve the right to modify the list of Covered Hardware at
any time if we discover devices that were not previously included in the list of Covered Hardware and
which are receiving Services, or as necessary to accommodate changes to the quantity of Covered
Hardware.
Unless otherwise stated in the Quote, Covered
Devices will only include technology assets (such as computers, servers, and networking equipment) owned
by Customer’s organization. As an accommodation, Onward may provide guidance in connecting a personal
device to Customer’s organization’s technology, but support of personal devices is generally not
included in the Scope of Services.
If the Quote indicates that the Services are
billed on a “per user” basis, then the Services will be provided for up to two (2) Business Devices used
by the number of users indicated in the Quote. A “Business Device” is a device that (i) is owned or
leased by Customer and used primarily for business, (ii) is regularly connected to Customer’s managed
network, and (iii) has installed on it a software agent through which we (or our designated Third Party
Providers) can monitor the device.
We will provide support for any software
applications that are licensed through us. Such software (“Supported Software”) will be supported on a
“best effort” basis only and any support required beyond Level 2-type support will be facilitated with
the applicable software vendor/producer. Coverage for non-Supported Software is outside of the scope of
the Quote and will be provided to you on a “best-effort” basis and a time and materials basis with no
guarantee of remediation. Should our technicians provide you with advice concerning non-Supported
Software, the provision of that advice should be viewed as an accommodation and not an obligation to
you.
If we are unable to remediate an issue with
non-Supported Software, then you will be required to contact the manufacturer/distributor of the
software for further support. Please
note: Manufacturers/distributors of such software may charge fees, some of which may
be significant, for technical support; therefore, we strongly recommend that you maintain service or
support contracts for all non-Supported Software (“Service Contract”). If you request that we facilitate
technical support for non-Supported Software and if you have a Service Contract in place, our
facilitation services will be provided to you at our then-current hourly rates.
In this Services Guide, Covered Hardware and
Supported Software will be referred to as the “Environment” or “Covered Equipment.”
Physical
Locations Covered by Services. Services will be provided remotely unless, in our
discretion, we determine that an onsite visit is required. Onward visits will be scheduled in accordance
with the priority assigned to the issue (below) and are subject to technician availability. Unless we
agree otherwise, all onsite Services will be provided at Customer’s primary business location.
Additional fees may apply for onsite visits: Please review the Service Level section below for more
details.
Minimum
Requirements / Exclusions. The scheduling, fees and provision of the Services are
based upon the following assumptions and minimum requirements, all of which must be provided/maintained
by Customer at all times:
• Server hardware must be
under current warranty coverage
• All equipment with
Microsoft Windows® operating systems must be running then-currently supported versions of such software
and have all the latest Microsoft service packs and critical updates installed.
• All software must be
genuine, licensed, and vendor- or OEM-supported.
• Server file systems and
email systems (if applicable) must be protected by licensed and up-to-date virus protection software.
• The managed environment
must have a currently licensed, vendor-supported server-based backup solution that can be monitored.
• All wireless data traffic
in the managed environment must be securely encrypted.
• All servers must be
connected to working UPS devices.
• Recovery coverage assumes
data integrity of the backups or the data stored on the backup devices. We do not guarantee the
integrity of the backups or the data stored on the backup devices. Server restoration will be to the
point of the last successful backup.
• Customer must provide all
software installation media and key codes in the event of a failure.
• Any costs required to
bring the Environment up to these minimum standards are not included in this Services Guide.
- Customer must provide us with
exclusive administrative privileges to the Environment.
- Customer must not affix or install
any accessory, addition, upgrade, equipment, or device on to the firewall, server, or NAS appliances
(other than electronic data) unless expressly approved in writing by us.
Exclusions.
Services that are not expressly described in the Quote will be out of
scope and will not be provided to Customer unless otherwise agreed, in writing, by Onward.
Without limiting the foregoing, the following services are expressly excluded, and if required to be
performed, must be agreed upon by Onward in writing:
- Support for applications,
platforms, and/or operating systems that are not present in the Environment at the commencement of
the Services.
- Support for applications,
platforms, and/or operating systems that are not supported by their respective manufacturers.
- Customization of third party
applications, or programming of any kind.
- Support for operating systems,
applications, or hardware no longer supported by the manufacturer.
- Data/voice wiring or cabling
services of any kind.
- Battery backup replacement.
- Equipment relocation.
- The cost to bring the managed
environment
- The cost of repairs to hardware or
any supported equipment or software, or the costs to acquire parts or equipment, or shipping charges
of any kind.
Service
Levels. Automated monitoring is provided on
an ongoing (i.e., 24x7x365) basis. Response, repair, and/or
remediation services (as applicable) will be provided only during our business hours (currently M-F, 8
AM – 5 PM Eastern Time, excluding legal holidays and Onward-observed holidays as listed below), unless
otherwise specifically stated in the Quote or as otherwise described below.
We will respond to problems, errors, or
interruptions in the provision of the Services in the timeframe(s) described below. Severity levels will
be determined by Onward in our discretion after consulting with Customer. All remediation services will
initially be attempted remotely; Onward will provide onsite service only if remote remediation is
ineffective and, under all circumstances, only if covered under the Service plan selected by Customer.
|
|
|
Critical /
Service Not Available
(e.g.,
all users and functions unavailable)
|
Response within two (2) business hours after
notification.
|
Significant
Degradation
(e.g.,
large number of users or business critical functions affected)
|
Response within four (4) business hours after
notification.
|
Limited
Degradation
(e.g.,
limited number of users or functions affected, business process can
continue).
|
Response within eight (8) business hours after
notification.
|
Small Service
Degradation
(e.g., business process can continue, one user
affected).
|
Response within two (2) business days after
notification.
|
Long Term
Project, Preventative Maintenance
|
Response within four (4) business days after
notification.
|
* All time frames are calculated as of the time that we are notified of the applicable issue /
problem by Customer through our designated support portal, help desk, or by telephone at the
telephone number listed in the Quote. Notifications received in any manner other than described
herein may result in a delay in the provision of remediation efforts.
Support During
Off-Hours/Non-Business Hours: Technical support provided outside of our normal
business hours is offered on a case-by-case basis and is subject to technician availability. Response
times are not guaranteed for off-hours/non-business hours services. If Onward agrees to provide
off-hours/non-business hours support (“Non-Business Hour Support”), and unless you and Onward agree
otherwise, such support will be provided on a time and materials basis (which is not covered under any
Service plan), and will be billed to Customer at a flat rate of $395/incident, regardless of duration.
Onward-Observed
Holidays: Onward observes the following holidays:
- Memorial Day
- Independence Day
- Labor Day
- Thanksgiving Day
- The day following Thanksgiving Day
- Christmas Eve
- Christmas Day
- New Year’s Eve
- New Year’s Day
Service
Credits: Our service level target is 90% as measured over a calendar month (“Target
Service Level”). If we fail to adhere to the Target Service Level and Customer timely brings that
failure to our attention in writing (as per the requirements of our Master Services Agreement), then
Customer will be entitled to receive a pro-rated service credit equal to 1/30 of that calendar month’s
recurring service fees (excluding hard costs, licenses, etc.) for each day on which the Target Service
Level is missed. Under no circumstances shall credits exceed 30% of the total monthly recurring service
fees under an applicable Quote.
Fees.
The fees for the Services will be as indicated in the Quote.
Reconciliation.
Fees for certain Third Party Services that we facilitate or resell to you may begin to accrue prior to
the “go-live” date of other applicable Services. (For example, Microsoft Azure or AWS-related fees begin
to accrue on the first date on which we start creating and/or configuring certain hosted portions of the
Environment; however, the Services that rely on Microsoft Azure or AWS may not be available to you until
a future date). You understand and agree that you will be responsible for the payment of all fees for
Third Party Services that are required to begin prior to the “go-live” date of Services, and we reserve
the right to reconcile amounts owed for those fees by including those fees on your monthly invoices.
Changes to
Environment. Initially, you will be charged the monthly fees indicated in the Quote.
Thereafter, if the managed environment changes, or if the number of authorized users accessing the
managed environment changes, then you agree that the fees will be automatically and immediately modified
to accommodate those changes.
Travel
Time. If onsite services are provided, we will travel up to 45 minutes from our
office to your location at no charge. Time spent traveling beyond 45 minutes (e.g., locations that are beyond 45 minutes from our office,
occasions on which traffic conditions extend our drive time beyond 45 minutes one-way, etc.) will be
billed to you at our then current hourly rates. In addition, you will be billed for all tolls, parking
fees, and related expenses that we incur if we provide onsite services to you.
Appointment
Cancellations. You may cancel or reschedule any appointment with us at no charge by
providing us with notice of cancellation at least one business day in advance. If we do not receive
timely a notice of cancellation/re-scheduling, or if you are not present at the scheduled time or if we
are otherwise denied access to your premises at a pre-scheduled appointment time, then you agree to pay
us a cancellation fee equal to two (2) hours of our normal consulting time (or non-business hours
consulting time, whichever is appropriate), calculated at our then-current hourly rates.
Access
Licensing. One or more of the Services may require us to purchase certain “per seat”
or “per device” licenses (often called “Access Licenses”) from one or more Third Party Providers.
(Microsoft “New Commerce Experience” licenses as well as Cisco Meraki “per device” licenses are examples
of Access Licenses.) Access Licenses cannot be canceled once they are purchased and often cannot be
transferred to any other customer. For that reason, you understand and agree that regardless of the
reason for termination of the Services, fees for Access Licenses are non-mitigatable and you are
required to pay for all applicable Access Licenses in full for the entire term of those licenses.
Provided that you have paid for the Access Licenses in full, you will be permitted to use those licenses
until they expire.
Term;
Termination. The Services will commence, and billing will begin, on the date
indicated in the Quote (“Commencement Date”) and will continue through the initial term listed in the
Quote (“Initial Term”). We reserve the right to delay the Commencement Date until all
onboarding/transition services (if any) are completed, and all deficiencies / revisions identified in
the onboarding process (if any) are addressed or remediated to Onward’s satisfaction.
The Services will continue through the Initial
Term until terminated as provided in the Agreement, the Quote, or as indicated in this Service Guide
(the “Service Term”).
Per
Seat/Per Device Licensing: Regardless of the reason
for the termination of the Services, you will be required to pay for all per seat or per device
licenses that we acquire on your behalf. Please see “Access Licensing” in the Fees section above for
more details.
Removal of Software
Agents; Return of Firewall & Backup Appliances: Unless we expressly direct you to
do so, you will not remove or disable, or attempt to remove or disable, any software agents that we
installed in the managed environment or any of the devices on which we installed software agents. Doing
so without our guidance may make it difficult or impracticable to remove the software agents, which
could result in network vulnerabilities and/or the continuation of license fees for the software agents
for which you will be responsible, and/or the requirement that we remediate the situation at our
then-current hourly rates, for which you will also be responsible. Depending on the particular software
agent and the costs of removal, we may elect to keep the software agent in the managed environment but
in a dormant and/or unused state.
Within ten (10) days after
being directed to do so, you must remove, package and ship, at your expense and in a commercially
reasonable manner, all hardware, equipment, and accessories leased, loaned, rented, or otherwise
provided to you by Onward “as a service.” If you fail to timely return all such equipment to us, or if
the equipment is returned to us damaged (normal wear and tear excepted), then we will have the right to
charge you, and you hereby agree to pay, the replacement value of all such unreturned or damaged
equipment.
Offboarding.
Subject to the requirements in the MSA, Onward will off-board Customer from Onward’s services by
performing one or more of the following:
• Removal / disabling of
monitoring agents in the Environment.
• Removal / disabling of
endpoint software from the Environment.
• Removal / disabling of
Microsoft 365 from the Environment (unless the licenses for Microsoft 365 are being transferred to your
incoming provider; please speak to your technician for details.)
• Termination of SQL or
Remote Desktop licenses provided by Onward.
• Removal of credentials
from the Environment.
• Removal of backup software
from the Environment.
Additional Policies
The following additional policies (“Policies”)
apply to Services that we provide or facilitate under a Quote. By accepting a Service for which one or
more of the Policies apply, you agree to the applicable Policy.
Authenticity
Everything in the managed environment must be
genuine and licensed, including all hardware, software, etc. If we ask for proof of authenticity and/or
licensing, you must provide us with such proof. All minimum hardware or software requirements as
indicated in a Quote or this Services Guide (“Minimum Requirements”) must be implemented and maintained
as an ongoing requirement of us providing the Services to you.
Monitoring Services; Alert Services
Unless otherwise indicated in the Quote, all
monitoring and alert-type services are limited to detection and notification functionalities only.
Monitoring levels will be set by Onward, and Customer shall not modify these levels without our prior
written consent.
Configuration of Third Party Services
Certain third party services provided to you
under a Quote may provide you with administrative access through which you could modify the
configurations, features, and/or functions (“Configurations”) of those services. However, any
modifications of Configurations made by you without authorization could disrupt the Services and/or
cause a significant increase in the fees charged for those third party services. For that reason, we
strongly advise you to refrain from changing the Configurations unless we authorize those changes. You
will be responsible for paying any increased fees or costs arising from or related to changes to the
Configurations.
Modification of Environment
Changes made to the Environment without our
prior authorization or knowledge may have a substantial, negative impact on the provision and
effectiveness of the Services and may impact the fees charged under the Quote. You agree to refrain from
moving, modifying, or otherwise altering any portion of the Environment without our prior knowledge or
consent. For example, you agree to refrain from adding or removing hardware from the Environment,
installing applications on the Environment, or modifying the configuration or log files of the
Environment without our prior knowledge or consent. Unauthorized changes, configurations made contrary
to Onward’s recommendations, or changes implemented at Customer’s explicit request despite
Onward’s advisement against them may result in affected systems being excluded from Onward’s support
scope. In these cases, Onward will not be liable for the results or outcomes of such modifications. Any
work required to restore or remediate issues arising from these changes will incur additional costs.
Compliance with Onward’s security and management protocols is essential for maintaining the integrity
and reliability of services. Failure to adhere to these protocols may delay service resolution and
increase costs associated with the Services.
Anti-Virus; Anti-Malware
Our anti-virus / anti-malware solution will
generally protect the Environment from becoming infected with new viruses and malware (“Malware”);
however, Malware that exists in the Environment at the time that the security solution is implemented
may not be capable of being removed without additional services, for which a charge may be incurred. We
do not warrant or guarantee that all Malware will be detected, avoided, or removed, or that any data
erased, corrupted, or encrypted by Malware will be recoverable. The effectiveness of Onward’s security
measures, including anti-virus and anti-malware solutions, depends on Customer’s active compliance with
Onward’s recommendations, guidelines, and security protocols. Failure to adhere to these recommendations
may reduce service effectiveness and incur additional costs if recovery services are necessary. To
improve security awareness, you agree that Onward or its designated third party affiliate may transfer
information about the results of processed files, information used for URL reputation determination,
security risk tracking, and statistics for protection against spam and malware. Any information obtained
in this manner does not and will not contain any personal or confidential information.
Breach/Cyber Security Incident Recovery
Unless otherwise expressly stated in the Quote,
the scope of the Services does not include the remediation and/or recovery from a Security Incident
(defined below). In the event of a Security Incident, Customer’s adherence to Onward’s recommended
security protocols and configurations will play a crucial role in minimizing incident response times and
associated costs. Additional fees will apply for recovery efforts necessitated by non-compliance with
Onward’s security protocols, and Onward’s ability to remediate such incidents may be impacted. Such
services, if requested by you, will be provided on a time and materials basis under our then-current
hourly labor rates. Given the varied number of possible Security Incidents, we cannot and do not warrant
or guarantee (i) the amount of time required to remediate the effects of a Security Incident (or that
recovery will be possible under all circumstances), or (ii) that all data or systems impacted by the
incident will be recoverable or remediated. For the purposes of this paragraph, a Security Incident
means any unauthorized or impermissible access to or use of the Environment, or any unauthorized or
impermissible disclosure of Customer’s confidential information (such as user names, passwords, etc.),
that (i) compromises the security or privacy of the information or applications in, or the structure or
integrity of, the managed environment, or (ii) prevents normal access to the managed environment, or
impedes or disrupts the normal functions of the managed environment.
Environmental Factors
Exposure to environmental factors, such as
water, heat, cold, or varying lighting conditions, may cause installed equipment to malfunction. Unless
expressly stated in the Quote, we do not warrant or guarantee that installed equipment will operate
error-free or in an uninterrupted manner, or that any video or audio equipment will clearly capture
and/or record the details of events occurring at or near such equipment under all circumstances.
Fair Usage Policy
Our Fair Usage Policy (“FUP”) applies to all
services that are described or designated as “unlimited” or which are not expressly capped in the number
of available usage hours per month. An “unlimited” service designation means that, subject to the terms
of this FUP, you may use the applicable service as reasonably necessary for you to enjoy the use and
benefit of the service without incurring additional time-based or usage-based costs. However, unless
expressly stated otherwise in the Quote, all unlimited services are provided during our normal business
hours only and are subject to our technicians’ availabilities, which cannot always be guaranteed. In
addition, we reserve the right to assign our technicians as we deem necessary to handle issues that are
more urgent, critical, or pressing than the request(s) or issue(s) reported by you. Consistent with this
FUP, you agree to refrain from (i) creating urgent support tickets for non-urgent or non-critical
issues, (ii) requesting excessive support services that are inconsistent with normal usage patterns in
the industry (e.g., requesting support in lieu of training),
(iii) requesting support or services that are intended to interfere, or may likely interfere, with our
ability to provide our services to our other customers.
Hosted Email
You are solely responsible for the proper use
of any hosted email service provided to you (“Hosted Email”). Hosted Email solutions are subject to
acceptable use policies (“AUPs”), and your use of Hosted Email must comply with those AUPs. In all
cases, you agree to refrain from uploading, posting, transmitting or distributing (or permitting any of
your authorized users of the Hosted Email to upload, post, transmit or distribute) any prohibited
content, which is generally content that (i) is obscene, illegal, or intended to advocate or induce the
violation of any law, rule or regulation, or (ii) violates the intellectual property rights or privacy
rights of any third party, or (iii) mischaracterizes you, and/or is intended to create a false identity
or to otherwise attempt to mislead any person as to the identity or origin of any communication, or (iv)
interferes or disrupts the services provided by Onward or the services of any third party, or (v)
contains Viruses, trojan horses or any other malicious code or programs. In addition, you must not use
the Hosted Email for the purpose of sending unsolicited commercial electronic messages (“SPAM”) in
violation of any federal or state law. Onward reserves the right, but not the obligation, to suspend
Customer’s access to the Hosted Email and/or all transactions occurring under Customer’s Hosted Email
account(s) if Onward believes, in its discretion, that Customer’s email account(s) is/are being used in
an improper or illegal manner.
Backup (BDR) Services
All data transmitted over the Internet may be
subject to malware and computer contaminants such as viruses, worms and trojan horses, as well as
attempts by unauthorized users, such as hackers, to access or damage Customer’s data. Neither Onward nor
its designated affiliates will be responsible for the outcome or results of such activities.
BDR services require a reliable,
always-connected internet solution. Data backup and recovery time will depend on the speed and
reliability of your internet connection. Internet and telecommunications outages will prevent the BDR
services from operating correctly. In addition, all computer hardware is prone to failure due to
equipment malfunction, telecommunication-related issues, etc., for which we will be held harmless. Due
to technology limitations, all computer hardware, including communications equipment, network servers
and related equipment, has an error transaction rate that can be minimized, but not eliminated. Onward
cannot and does not warrant that data corruption or loss will be avoided, and Customer agrees that
Onward shall be held harmless if such data corruption or loss occurs. Customer is strongly advised to keep a local backup of all of stored data
to mitigate against the unintentional loss of data.
Procurement
Equipment and software procured by Onward on
Customer’s behalf (“Procured Equipment”) may be covered by one or more manufacturer warranties, which
will be passed through to Customer to the greatest extent possible. By procuring equipment or software
for Customer, Onward does not make any warranties or representations regarding the quality, integrity,
or usefulness of the Procured Equipment. Certain equipment or software, once purchased, may not be
returnable or, in certain cases, may be subject to third party return policies and/or re-stocking fees,
all of which shall be Customer’s responsibility in the event that a return of the Procured Equipment is
requested. Onward is not a warranty service or repair center. Onward will facilitate the return or
warranty repair of Procured Equipment; however, Customer understands and agrees that (i) the return or
warranty repair of Procured Equipment is governed by the terms of the warranties (if any) governing the
applicable Procured Equipment, for which Onward will be held harmless, and (ii) Onward is not
responsible for the quantity, condition, or timely delivery of the Procured Equipment once the equipment
has been tendered to the designated shipping or delivery courier.
Business Review / IT Strategic Planning Meetings
We strongly suggest that you participate in
business review/strategic planning meetings as may be requested by us from time to time. These meetings
are intended to educate you about recommended (and potentially crucial) modifications to your IT
environment, as well as to discuss your company’s present and future IT-related needs. These reviews can
provide you with important insights and strategies to make your managed IT environment more efficient
and secure. You understand that by suggesting a particular service or solution, we are not endorsing any
specific manufacturer or service provider.
VCTO or VCIO Services
The advice and suggestions provided by us in
our capacity as a virtual chief technology or information officer (if applicable) will be for your
informational and/or educational purposes only.
Onward will not hold an actual director or officer position in Customer’s company, and we will neither
hold nor maintain any fiduciary relationship with Customer. Under no circumstances shall Customer list
or place Onward on Customer’s corporate records or accounts.
Sample Policies, Procedures.
From time to time, we may provide you with
sample (i.e., template) policies and procedures for use in
connection with Customer’s business (“Sample Policies”). The Sample Policies are for your informational
use only, and do not constitute or comprise legal or professional advice, and the policies are not
intended to be a substitute for the advice of competent counsel. You should seek the advice of competent
legal counsel prior to using or distributing the Sample Policies, in part or in whole, in any
transaction. We do not warrant or guarantee that the Sample Policies are complete, accurate, or suitable
for your (or your customers’) specific needs, or that you will reduce or avoid liability by utilizing
the Sample Policies in your (or your customers’) business operations.
Penetration Testing; Vulnerability Scanning
You understand and agree that security devices,
alarms, or other security measures, both physical and virtual, may be tripped or activated during the
penetration testing and/or vulnerability scanning processes, despite our efforts to avoid such
occurrences. You will be solely responsible for notifying any monitoring company and all law enforcement
authorities of the potential for “false alarms” due to the provision of the penetration testing or
vulnerability scanning services, and you agree to take all steps necessary to ensure that false alarms
are not reported or treated as “real alarms” or credible threats against any person, place, or property.
Some alarms and advanced security measures, when activated, may cause the partial or complete shutdown
of the Environment, causing substantial downtime and/or delay to your business activities. We will not
be responsible for any claims, costs, fees, or expenses arising or resulting from (i) any response to
the penetration testing or vulnerability scanning services by any monitoring company or law enforcement
authorities, or (ii) the partial or complete shutdown of the Environment by any alarm or security
monitoring device.
No Third Party Scanning
Unless we authorize such activity in writing,
you will not conduct any test, nor request or allow any third party to conduct any test (diagnostic or
otherwise), of the security system, protocols, processes, or solutions that we implement in the managed
environment (“Testing Activity”). Any services required to diagnose or remediate errors, issues, or
problems arising from unauthorized Testing Activity are not covered under the Quote, and if you request
us (and we elect) to perform those services, those services will be billed to you at our then-current
hourly rates.
Obsolescence
If at any time any portion of the managed
environment becomes outdated, obsolete, reaches the end of its useful life, or acquires “end of support”
status from the applicable device’s or software’s manufacturer (“Obsolete Element”), then we may
designate the device or software as “unsupported” or “non-standard” and require you to update the
Obsolete Element within a reasonable time period. If you do not replace the Obsolete Element reasonably
promptly, then in our discretion we may (i) continue to provide the Services to the Obsolete Element
using our “best efforts” only with no warranty or requirement of remediation whatsoever regarding the
operability or functionality of the Obsolete Element, or (ii) eliminate the Obsolete Element from the
scope of the Services by providing written notice to you (email is sufficient for this purpose). In any
event, we make no representation or warranty whatsoever regarding any Obsolete Element or the
deployment, service level guarantees, or remediation activities for any Obsolete Element.
Licenses
If we are required to re-install or replicate
any software provided by you as part of the Services, then it is your responsibility to verify that all
such software is properly licensed. We reserve the right, but not the obligation, to require proof of
licensing before installing, re-installing, or replicating software into the managed environment. The
cost of acquiring licenses is not included in the scope of the Quote unless otherwise expressly stated
therein.
VOIP – Dialing 911 (Emergency) Services
The following
terms and conditions apply to your use of any VoIP service that we facilitate for you or that is
provided to you by a third party provider of such service. Please note, by using VoIP services you
agree to the provisions of the waiver at the end of this section. If you do not understand or do not
agree with any of the terms below, you must not subscribe to, use, or rely upon any VoIP service
and, instead, you must contact us immediately.
There is an important difference in how 9-1-1
(i.e., emergency) services can be dialed using a VoIP service
as compared to a traditional telephone line. Calling emergency services using a VoIP service is referred
to as “E911.”
Registration:
You are responsible for activating the E911 dialing feature by registering the address where you will
use the VoIP service. This will not be done for you, and you must take
this step on your own initiative. To do this, you must log into your VoIP control panel and
provide a valid physical address. If you do not take this step, then
E911 services may not work correctly, or at all, using the VoIP service. Emergency service
dispatchers will only send emergency personnel to a properly registered E911 service address.
Location:
The address you provide in the control panel is the location to which emergency services (such as the
fire department, the police department, etc.) will respond. For this reason, it is important that you
correctly enter the location at which you are using the VoIP services. PO boxes are not proper addresses
for registration and must not be used as your registered address. Please note, even if your account is
properly registered with a correct physical address, (i) there may be a problem automatically
transmitting a caller’s physical location to the emergency responders, even if the caller can
reach the 911 call center, and (ii) a VoIP 911 call may go to an unstaffed call center administrative
line or be routed to a call center in the wrong location. These issues are inherent to all VoIP systems
and services. We will not be responsible for, and you agree to hold us
harmless from, any issues, problems, incidents, damages (both bodily- and property-related), costs,
expenses, and fees arising from or related to your failure to register timely and correctly your
physical location information into the control panel.
Address
Change(s): If you change the address used for E911 calling, the E911 services may not
be available and/or may operate differently than expected. Moreover, if you do not properly and promptly
register a change of address, then emergency services may be directed to the location where your
services are registered and not
where the emergency may be occurring. For that reason, you must register a change of address with us through the VoIP control panel no
less than three (3) business days prior to your anticipated move/address change. Address changes that are
provided to us with less than three (3) business days notice may cause incorrect/outdated information to
be conveyed to emergency service personnel. If you are unable to provide us with at least three (3)
business days notice of an address change, then you should not rely on the E911 service to provide
correct physical location information to emergency service personnel. Under those circumstances, you
must
provide your correct physical location to emergency service dispatchers if you call them using the VoIP
services.
If you do not register the VoIP service at your
location and you dial 9-1-1, that call will be categorized as a “rogue 911 call.” If you are responsible for dialing a rogue 911 call, you will be charged
a non-refundable and non-disputable fee of $250/call.
Power
Loss: If you lose power or there is a disruption to power at the location where the
VoIP services are used, then the E911 calling service will not function until power is restored. You
should also be aware that after a power failure or disruption, you may need to reset or reconfigure the
device prior to utilizing the service, including E911 dialing.
Internet
Disruption: If your internet connection or broadband service is lost, suspended,
terminated or disrupted, E911 calling will not function until the internet connection and/or broadband
service is restored.
Account
Suspension: If your account is suspended or terminated, then all E911 dialing
services will not function.
Network
Congestion: There may be a greater possibility of network congestion and/or reduced
speed in the routing of E911 calls as compared to 911 dialing over traditional public telephone
networks.
Messaging:
All messages sent through the VoIP service must conform to the following requirements and restrictions:
- Recipients must give their consent
to receive text messages from you. This can be direct consent or, depending on the circumstances,
implied consent (such as a pre-existing business relationship, contact initiated by the recipient,
etc.).
- Recipients must be provided with
an opt-out mechanism to avoid receiving future text messages from you.
- You shall not mis-identify
yourself or cause the message to appear as if it was sent from a telephone number other than the
number assigned to you by the VoIP service.
- All messaging-related activities
must strictly comport with the requirements and restrictions of the Telephone Consumer Protection
Act (47 USC §227) (“TCPA”). You agree to indemnify and hold us harmless from any costs, fees,
expenses, and/or penalties that we incur because of your failure to abide strictly by the TCPA. If,
in our reasonable judgment, we believe that your activities violate the TCPA, we reserve the right
to suspend the messaging service until we receive reasonable assurances that the activity has
stopped and will not be repeated. Repeated violation of the TCP is a material breach of your
agreement with us.
WAIVER:
You hereby agree to release, indemnify, defend, and hold us and our officers, directors,
representatives, agents, and any third party service provider that furnishes VoIP-related services to
you, harmless from any and all claims, damages, losses, suits or actions, fines, penalties, costs and
expenses (including, but not limited to, attorneys’ fees), whether suffered, made, instituted or
asserted by you or by any other party or person (collectively, “Claims”) arising from or related to the
VoIP services, including but not limited to any failure or outage of the VoIP services, incorrect
routing or use of, or any inability to use, E911 dialing features. The foregoing waiver and release
shall not apply to Claims arising from our gross negligence, recklessness, or willful misconduct.
Co-Managed Services Policy
Onward’s Role: In co-managed situations (i.e., situations in which Onward is providing services alongside
another IT vendor, IT manager/department, or a third party solution provider that is providing
different, complementary, or overlapping services), Onward serves as the technology subject matter
expert, responsible for the overall management, provisioning, and governance of the IT Services covered
by the Quote. While Onward establishes and enforces the standards and key performance indicators (KPIs)
necessary to ensure service quality and compliance, Onward does not assume responsibility for any
services or systems Customer independently decides to develop or implement outside the scope of the
Quote. Such initiatives must be standardized and formally incorporated into the scope for Onward to
manage or support them.
Service Provisioning: Onward is responsible for deploying,
configuring, and maintaining the IT infrastructure necessary for the IT Services under the Quote. This
responsibility extends to ensuring that the infrastructure aligns with Customer’s business needs and
adheres to the Service Level Agreements (SLAs) outlined in in this Guide. If Customer provisions
services on Onward’s cloud-hosted infrastructure, Onward provides best-effort support but does not
assume responsibility for their management or performance unless specifically agreed upon, which may
require an adjustment to fees.
Change Management: Onward will oversee the change management
process, including handling change requests, approvals, and communication related to significant updates
or the introduction of new technologies within the managed IT environment. This ensures that all changes
are managed systematically to minimize disruption and align with business objectives.
Incident and Problem Management: Onward shall manage critical
incidents and problem management processes within the co-managed environment. This includes coordinating
with Customer’s IT team to help ensure timely resolution of issues.
Customer’s Role and Collaboration: Customer is responsible
for managing internal processes, communicating with end-users, and assisting with day-to-day IT support
under Onward’s guidance. Customer must ensure that its IT personnel adhere to the ITSM processes,
standards, and KPIs defined by Onward. This includes maintaining adequate IT staffing levels to ensure
they can effectively collaborate within the co-managed environment. Onward is not responsible for any
gaps in support or service that arise from inadequate staffing on Customer’s part. Such gaps,
should they occur, may cause the Services to be delayed, adjusted by Onward, and/or may require Customer
to pay additional fees and costs to accommodate the gaps in Customer’s personnel or staffing.
Expertise and Support: Onward provides the technical expertise
necessary for specialized IT deployments, governance, and strategy development. This includes ensuring
compliance with industry standards, implementing best practices, and supporting Customer in complex
technical initiatives.
Support and Guidance: Onward will offer guidance and support to
both Customer’s IT team and end-users for the services covered under the Quote. This includes
helping the IT team effectively utilize the ITSM platform and adhere to established protocols. Onward
will also provide end-user support for IT services and systems managed by Onward, though comprehensive
training on all Customer applications is outside the scope.
Tools, Business Intelligence, and Resources: Onward will provide
tools, resources, and business intelligence related to ITSM to facilitate IT management for
Customer’s IT team. These tools include automated workflows, templates, and documentation to
streamline processes and improve efficiency.
Strategic Consultation: Onward will engage in regular reviews and
strategic consultations with Customer to align IT services with Customer’s business goals. This
includes recommending improvements and adjustments to the IT environment as needed.
Shared Responsibility: The co-managed IT model relies on effective
collaboration between Onward and Customer. While Onward provides the framework, tools, and expert
guidance, Customer’s IT personnel are expected to actively participate in the ongoing management
and support of their IT systems, following Onward’s standards and KPIs.
Exclusion from Co-Management: If Customer’s IT personnel do
not meet the required proficiency levels or fail to adhere to the established ITSM protocols, Onward may
limit their involvement in co-management activities. In such cases, Onward will retain greater control
over the management process to ensure service quality. If Customer’s IT personnel later meet the
necessary standards, their involvement in co-management may be reinstated upon mutual agreement.
Acceptable Use Policy
The following policy applies to all hosted
services provided to you, including but not limited to (and as applicable) hosted applications, hosted
websites, hosted email services, and hosted infrastructure services (“Hosted Services”).
Onward does not routinely monitor the activity
of hosted accounts except to measure service utilization and/or service uptime, security-related
purposes and billing-related purposes, and as necessary for us to provide or facilitate our managed
services to you; however, we reserve the right to monitor Hosted Services at any time to ensure your
compliance with the terms of this Acceptable Use Policy (this “AUP”) and our master services agreement,
and to help monitor and ensure the safety, integrity, reliability, or security of the Hosted Services.
Similarly, we do not exercise editorial control
over the content of any information or data created on or accessible over or through the Hosted
Services. Instead, we prefer to advise our customers of inappropriate behavior and any necessary
corrective action. If, however, Hosted Services are used in violation of this AUP, then we reserve the
right to suspend your access to part or all of the Hosted Services without prior notice.
Violations of
this AUP: The following constitute violations of this AUP:
· Harmful or illegal uses: Use of a Hosted Service for illegal
purposes or in support of illegal activities, to cause harm to minors or attempt to contact minors for
illicit purposes, to transmit any material that threatens or encourages bodily harm or destruction of
property or to transmit any material that harasses another is prohibited.
· Fraudulent activity: Use of a Hosted Service to conduct any
fraudulent activity or to engage in any unfair or deceptive practices, including but not limited to
fraudulent offers to sell or buy products, items, or services, or to advance any type of financial scam
such as “pyramid schemes,” “Ponzi schemes,” and “chain letters” is prohibited.
· Forgery or impersonation: Adding, removing, or modifying
identifying network header information to deceive or mislead is prohibited. Attempting to impersonate
any person by using forged headers or other identifying information is prohibited. The use of anonymous
remailers or nicknames does not constitute impersonation.
· SPAM: Onward has a zero tolerance policy for the sending of
unsolicited commercial email (“SPAM”). Use of a Hosted Service to transmit any unsolicited commercial or
unsolicited bulk e-mail is prohibited. You are not permitted to host, or permit the hosting of, sites or
information that is advertised by SPAM from other networks. To prevent unnecessary blacklisting due to
SPAM, we reserve the right to drop the section of IP space identified by SPAM or denial-of-service
complaints if it is clear that the offending activity is causing harm to parties on the Internet, if
open relays are on the hosted network, or if denial of service attacks are originated from the hosted
network.
· Internet Relay Chat (IRC): The use of IRC on a hosted server is
prohibited.
· Open or “anonymous” proxy: Use of open or anonymous proxy servers
is prohibited.
· Cryptomining: Using any portion of the Hosted Services for mining
cryptocurrency or using any bandwidth or processing power made available by or through a Hosted Services
for mining cryptocurrency, is prohibited.
· Hosting spammers: The hosting of websites or services using a
hosted server that supports spammers, or which causes (or is likely to cause) our IP space or any IP
space allocated to us or our customers to be listed in any of the various SPAM databases, is prohibited.
Customers violating this policy will have their server immediately removed from our network and the
server will not be reconnected until such time that Customer agrees to remove all traces of the
offending material immediately upon reconnection and agree to allow Onward to access the server to
confirm that all material has been completely removed. Any subscriber guilty of a second violation may
be immediately and permanently removed from the hosted network for cause and without prior notice.
· Email/message forging: Forging any email message header, in part
or whole, is prohibited.
· Unauthorized access: Use of the Hosted Services to access, or to
attempt to access, the accounts of others or to penetrate, or attempt to penetrate, Onward’s security
measures or the security measures of another entity’s network or electronic communications system,
whether or not the intrusion results in the corruption or loss of data, is prohibited. This includes but
is not limited to accessing data not intended for you, logging into or making use of a server or account
you are not expressly authorized to access, or probing the security of other networks, as well as the
use or distribution of tools designed for compromising security such as password guessing programs,
cracking tools, or network probing tools.
· IP infringement: Use of a Hosted Service to transmit any materials
that infringe any copyright, trademark, patent, trade secret or other proprietary rights of any third
party, is prohibited.
· Collection of personal data: Use of a Hosted Service to collect,
or attempt to collect, personal information about third parties without their knowledge or consent is
prohibited.
· Disruptive Activity: Use of the Hosted Services for any activity
which affects the ability of other people or systems to use the Hosted Services or the internet is
prohibited. This includes “denial of service” (DOS) attacks against another network host or individual,
“flooding” of networks, deliberate attempts to overload a service, and attempts to “crash” a host.
· Distribution of malware: Intentional distribution of software or
code that attempts to and/or causes damage, harassment, or annoyance to persons, data, and/or computer
systems is prohibited.
· Excessive use or abuse of shared resources: The Hosted Services
depend on shared resources. Excessive use or abuse of these shared network resources by one customer may
have a negative impact on all other customers. Misuse of network resources in a manner which impairs
network performance is prohibited. You are prohibited from excessive consumption of resources, including
CPU time, memory, and session time. You may not use resource-intensive programs which negatively impact
other customers or the performances of our systems or networks.
· Allowing the misuse of your account: You are responsible for any
misuse of your account, even if the inappropriate activity was committed by an employee or independent
contractor. You shall not permit your hosted network, through action or inaction, to be configured in
such a way that gives a third party the capability to use your hosted network in an illegal or
inappropriate manner. You must take adequate security measures to prevent or minimize unauthorized use
of your account. It is your responsibility to keep your account credentials secure.
To maintain the security and integrity of the
hosted environment, we reserve the right, but not the obligation, to filter content, Onward requests, or
website access for any web requests made from within the hosted environment.
Revisions to
this AUP: We reserve the right to revise or modify this AUP at any time. Changes to this AUP
shall not be grounds for early contract termination or non-payment.
DevOps Addendum
Our development operations services (or
“DevOps”) help automate and integrate the processes between software development and information
technology (IT) operations teams. Generally, DevOps entails five principles:
- Collaboration:
DevOps assists the development and operations team to communicate and collaborate, fostering shared
responsibility and collaboration.
- Automation:
DevOps uses automated solutions to streamline the software development cycle, from building and
testing to deployment and monitoring.
- Continuous
Integration & Continuous Delivery (“CI/CD”): CI/CD pipelines automate the
process of building, testing, and deploying code changes, enable frequent, stable, and reliable code
releases.
- Infrastructure
as Code (“IaC”): This involves managing and provisioning infrastructure through
code, making both processes repeatable and version-controlled.
- Monitoring
& Feedback: Continuous monitoring and feedback loops help identify and
address issues quickly, helping to ensure overall stability and performance.
To ensure the principles of DevOps are fully
implemented, DevOps requires Customer’s cooperation and Customer’s participation in certain shared
responsibilities. To that end, Customer must:
- Employ
a Senior IT Leader: Customer should designate a senior IT leader (e.g., a
Director of IT, IT Manager, or Chief Information Officer) with relevant experience in IT management,
operations, or DevOps practices. This individual will serve as the primary point of contact and
Authorized Representative (as defined in the MSA) for DevOps-related matters.
- Co-Managed
DevOps: If Customer is participating in a co-managed DevOps engagement (as
described in the Co-Managed Services section of this Services Guide), Customer must also maintain a
qualified IT team to support DevOps activities. At a minimum, this team should include:
- IT
Support Personnel: Staff with experience in systems administration, network
management, or cloud services, capable of addressing technical issues related to DevOps.
- Business
Analysts: Analysts with familiarity in DevOps workflows and process automation,
responsible for aligning business needs with DevOps objectives.
- All members of Customer’s DevOps
team should be readily available to Onward during normal business hours to ensure responsive support
and alignment with DevOps goals.
- Establish
and Maintain IT Protocols: Customer must create, document, and enforce IT
protocols aligned with DevOps practices, which will be subject to Onward’s review and approval to
ensure best practices.
Customer’s failure to fulfill and maintain the
above-listed requirements may result in a delay in the provision of DevOps for which Onward will not be
responsible, or in cases where the failure substantially impacts Onward’s ability to perform, may result
in Onward (in its sole discretion) (i) terminating the DevOps for cause, (ii) amending the scope of the
DevOps to accommodate the failure, or (iii) increasing the monthly fee to cover Onward’s increased costs
and time.
Both Onward’s technicians and Customer will be
involved in the following DevOps stages:
- Planning
& Development: Onward and Customer’s
DevOps Team will work together to plan and design applications and infrastructure.
- Testing:
Onward and Customer’s DevOps Team will be involved in testing at various stages of
the DevOps process, including automated testing and performance testing. It is crucial that
Customer’s DevOps Team provide prompt and complete feedback in response to testing activities.
- Deployment: Onward and Customer’s DevOps Team will collaborate to
automate and streamline deployment of developed applications and processes.
- Monitoring
& Maintenance: During the term of the DevOps service, Onward will monitor
overall performance of developed applications and processes, and remediate issues that are reported
(and which are capable of being observed in Onward’s laboratory or similar technical setting).
Customer’s DevOps Team will monitor the performance and effectiveness of the developed applications
and processes, and promptly report any deviations, errors, or suspected deficiencies to Onward for
further evaluation.
If Customer fails to participate in any of the
steps or stages described above, DevOps may be delayed, canceled for cause, or result in increased
monthly fee to cover Onward’s increased costs and time.
Service
Hours: DevOps will be provided during our normal business hours, which are currently
8 AM through 5 PM Eastern Time, Monday through Friday, excluding the following Onward-recognized
holidays:
- New Year’s Eve
- New Years Day
- Christmas Eve through the day
after Christmas
- Thanksgiving Day and the day after
Thanksgiving
- Labor Day
- Memorial Day
- Independence Day
Services may be available during non-business
hours on a case-by-case basis, subject to technician availability and additional fees. (Emergency
incidents will be invoiced at $350 per incident regardless of the length of service. All after-hours or
emergency-related services require Customer’s prior approval before being implemented.)
Exclusions:
The following are out-of-scope of DevOps and, if provided, will require Customer’s approval and will be
subject to additional fees:
- Projects or services that are not
included in the scope of the Quote (such as New DevOps Projects / Add-Ons, described below);
- Off-hours/emergency services
(described above);
- Support for line-of-business
software that does not have a then-current support contract from the software manufacturer, it being
understood that if Onward provides such support it will be on a “best efforts” and “as is” basis
with no warranty or guaranty whatsoever; and,
- Installation, implementation,
and/or maintenance of new line-of-business platforms, module installations, migrations of data,
software, or equipment, or software upgrades.
New DevOps projects that require consultation,
design planning, or support efforts, as well as major changes to Customer’s then existing IT hardware or
software environment or active user account increases, can be accommodated but will require Customer’s
prior approval and will require the payment of additional fees and costs.
Hourly
Work: Any services performed or provided by
Onward on an hourly basis will be billed in fifteen (15) minute increments for MSA agreements, and
thirty (30) minute increments for DevOps or Contract agreements, with partial increments being rounded
up to the next highest increment. In additional to hourly services described elsewhere in this Addendum,
all travel time to and from Customer’s location outside of Lee County will be billed as hourly work, as
will any time spent setting up, configuring, or maintaining out-of-scope services or changes.
New
DevOps Projects / Add-Ons: If Customer or
Onward identifies a new business need that necessitates a change to the existing technology hardware or
software (such as a new line-of-business application, new office space opening, increased staffing
levels, business acquisition), then Onward will following the following procedure:
- Customer and Onward will
collaborate to validate all requirements for additional hardware or software needed to support the
identified business need before making any purchases.
- For software add-ons, Customer
will designate a software application owner from Customer’s DevOps Team (“Project Owner”). Onward
will work with the Project Owner to install a demo of the software (if available) and assess its
features and benefits before making any purchases. Once the software is confirmed to meet business
requirements, Project Owner will inform Customer and Customer’s DevOp’s Team of the demo results.
- Onward will determine and notify
the Customer’s business principal of any required additional hardware purchases to support the
new software before any purchases are made.
- Onward validates the installation
and ongoing support requirements for any additional hardware and/or software and presents the
increase in monthly Onward Managed DevOps Services fees to the Project Owner before making any
purchases. If approved, all time spent procuring, installing, and maintaining the additional
hardware and/or software will be covered under the Onward Managed DevOps then-current services
quote. If the increase in monthly fees is not approved, the support provided will be offered on a
best-effort basis and invoiced according to Onward’s then-current hourly rates.
- Onward reserves the right to
determine and adjust the vendors, technologies, and third-party providers that support our managed
services based on evolving industry standards, compatibility with Customer environments, and
continuous improvement in service quality. Supported vendors and technologies will be selected at
Onward’s discretion to ensure alignment with service delivery goals. Onward will notify Customers of
any major changes that may impact service outcomes or Customer responsibilities.
Last updated: October 17, 2023