Trust & Security

Handing a provider the keys to your systems is a serious decision. Here is how we protect that access, exactly what we can and cannot see, how to withdraw our access, and how your team can tell a genuine 1800GEEK request from an impersonation.

Access Controls

How we protect the access you give us

The same baseline applies to every client, every engineer and every tool.

Least-privilege access

Each engineer gets only the access their work needs, and access is reviewed regularly and removed when it is no longer required.

MFA on every tool

Every console, portal and remote-access tool we use to reach your systems is protected by multi-factor authentication.

Encrypted credential vault

Your administrative credentials live in an encrypted vault — never in email, chat, tickets or spreadsheets.

Recorded administration

Administrative work on your systems is recorded, so there is always a history of what changed, when, and by whom.

Named people, not a call centre

Your environment is looked after by named engineers who know it, under a named point of contact.

Your systems stay yours

Your tenant, domains, licences and data stay registered to your business. We never put them in our own name.

Visibility

Exactly what we can and cannot see

Our monitoring and remote-access agents keep your devices patched, protected and supportable. They are not surveillance tools.

What we can see

  • Device inventory, health, disk and patch status
  • Security alerts, event logs and backup results
  • Admin consoles for the services you asked us to manage
  • A user's screen — only during an active remote session

What we do not do

  • Log keystrokes or monitor staff productivity
  • Browse personal files or personal email
  • Open business mailboxes or files unless a task you requested needs it
  • Share your data with anyone not working on your account
Your Control

How to withdraw our access

No long-term lock-in, and nothing held back. If you decide to leave, this is what happens.

1

Tell us in writing

Email support@1800geek.com from an authorised contact. We confirm, and start offboarding.

2

Remove our admin roles

In Microsoft 365 / Entra ID, remove our admin accounts and any partner (GDAP) relationship. It takes a couple of clicks.

3

Agents come off

We remove our monitoring and remote-access agents from every device we can reach and give you steps for the rest.

4

Rotate and close

We hand over the vault entries and documentation, and recommend rotating any shared credentials.

Verification

What 1800GEEK will never do

Criminals impersonate IT providers to get into businesses. Share this list with your team — if a “1800GEEK” request breaks any of these rules, it is not us.

Ask your staff for passwords

We never ask a user to read out or type their password or MFA code for us. If anyone does, it is not us.

Change bank details by email

Our payment details never change by email alone. Always call us on 1-888-915-4335 to confirm before paying.

Request gift cards or crypto

We never ask anyone to buy gift cards, send cryptocurrency, or wire money to a personal account.

Push surprise MFA prompts

We never ask a user to approve an MFA prompt they did not trigger themselves.

Cold-call staff to install software

Our engineers work from requests your organisation raised. We do not phone your staff unprompted to install anything.

Claim to be Microsoft

We are an independent provider and a Microsoft Partner — never Microsoft, and never Microsoft Support.

How to confirm a request is genuine

When in doubt, end the conversation and contact us yourself using the details below — typed from this page, never from a link, pop-up, text message or the caller.

  • Phone: 1-888-915-4335 (Monday–Saturday, 9:00 AM–6:00 PM Central)
  • Email: support@1800geek.com — genuine email from us comes only from the @1800geek.com domain
  • Website: 1800geek.com only. Watch for lookalike domains with extra words, hyphens or different endings
  • Company: Geek Of States LLC · 1800GEEK®, USPTO Reg. No. 7,582,257 · Microsoft Partner ID 6545613

If you think your business has been targeted

  • Clients: call us immediately on 1-888-915-4335. Treat it as a P1 security incident.
  • Disconnect an affected device from the network, but leave it powered on, so evidence is preserved.
  • Do not pay, and do not approve any payment-detail change, until it is verified by phone.
  • Contact your bank straight away if money has been sent.
  • Report business email compromise and fraud: in the United States to the FBI at ic3.gov; in Canada to the Canadian Anti-Fraud Centre at antifraudcentre-centreantifraude.ca.

If someone has used the 1800GEEK name to contact you, please tell us at support@1800geek.com. We take impersonation seriously.

Report a security vulnerability

If you believe you have found a security issue in our website or services, email support@1800geek.com with “Security” in the subject. Our disclosure contact is also published in security.txt. Please give us reasonable time to fix the issue before disclosing it publicly.

Related documents

How we handle information is set out in our Privacy Policy. The rules for our agents are in our Remote Management Software Terms, and our access commitments are part of our Master Terms of Service.

Not sure a request really came from us?

Do not take the chance. Call the number on this page and we will confirm, or tell you it was not us.

CallBook Now