
Most Waterloo companies call us on a date they can name — the week a customer's security review landed, or the week the co-op intake arrived. We are ten minutes away in downtown Kitchener, not an hour up the 401.
Ongoing managed IT or a one-off problem — tell us which and we'll respond accordingly.
We won't sell your data or send you marketing you didn't ask for.
Trusted by businesses in Waterloo Region and across North America
Most Waterloo companies do not go looking for an IT provider. They get pushed into one, and usually on a date they can point to in a calendar.
A software company signs its first enterprise customer — a bank, an insurer, a hospital network. Somewhere between the term sheet and the signature, that customer's procurement team sends over a vendor security review. It asks who holds administrative access, how accounts are removed when somebody leaves, where backups are held and in whose jurisdiction, whether multi-factor is enforced on everything or only on email, and when a restore was last actually performed. The answers exist. They live in three people's heads and one internal wiki page that has not been touched since the Series A.
That is the point at which the IT setup that got a company to thirty staff stops being enough. Not because it was bad — it was appropriate for what it was for — but because it was never built to be evidenced to somebody else.
We do that work. To be plain about what it is and is not: we cannot make you SOC 2 compliant, and you should be wary of any IT provider that says it can. An attestation comes from an auditor. What we can do is run the environment so the answers are true and can be produced on demand — conditional access actually enforced rather than configured, a joiner and leaver record with dates against it, patch compliance you can export, backups with restore evidence rather than a green tick on a dashboard. We hold a SOC 2 Type 2 attestation for our own operations, which mostly means we have sat on the answering side of the same spreadsheet.
If a customer's review is due in four weeks, say so on the first call. It changes the order we do things in, and it changes what is worth doing at all before the deadline.
Three times a year, a large number of Waterloo Region employers replace a meaningful share of their staff in the same fortnight. Co-op terms end and begin together. For a company running twelve students, that is twelve accounts to build, twelve machines to hand over and twelve sets of access to take away again — four months later, every year, for as long as the company keeps hiring that way.
Handled casually, this is where an environment quietly rots. What a first audit turns up is consistent enough to predict: licensed accounts belonging to people who left two intakes ago, a repository that a student still has access to, a personal laptop added to the network in a rush during onboarding week and never removed, and one shared credential for a tool that only one team uses — now known to a rolling cast of people, none of whom still work there.
We treat this as a scheduled operation rather than a run of unrelated tickets. Your intake dates are known in advance. Machines are imaged and accounts provisioned from a standard build before the first day, and the offboarding list runs on the last day of the term whether or not anybody remembers to raise it. Licences come back. Access ends on the date, not on the day someone notices. When a student returns for a second term in September, that is a restore rather than a rebuild.
The same discipline is what makes the security questionnaire in the section above answerable, which is not a coincidence — offboarding is the question every reviewer asks and the one most companies answer worst.
The clients below agreed to be named, so we can describe what we actually built rather than paraphrasing a compliment.
For the Ontario Soil and Crop Improvement Association we retired a failing on-premises server, moved the association onto our private cloud and swapped its VPN for zero trust network access, so that trust is decided per user, per device and per resource instead of by whether someone reached the network. The full migration is in our cloud migration case study for an agricultural association.
For Tube-Mac Industries we designed a VMware and Nimble storage platform that keeps manufacturing running when a component fails, and built JobSight, a job management application tied into Sage 300 so that job data is entered once rather than keyed into separate systems. That build is covered in our manufacturer high availability case study.
A lot of Waterloo companies have head office, engineering and sales in Waterloo, and production or the warehouse twenty minutes down the 401 in Cambridge. The office is a current Microsoft 365 environment. The plant is a machine of uncertain vintage bolted to equipment that cost six figures and is not being replaced to satisfy a patch policy.
Most providers price the office and the plant as two engagements. We put them on one, because the split is what creates the gap — the incident lands on the plant and the credentials came from the office. In practice the plant network is segmented from the office network, the controllers are inventoried with their supported operating system and their vendor's actual written position on patching, and the shift pattern is known so nobody schedules a firewall reboot at the start of an afternoon shift.
The environment that worked at fifteen people fails differently at sixty. Not dramatically — an SSO configuration that only half the applications use, a shared drive nobody can now audit, four different laptop models bought from four suppliers. It is a slow problem, which is why it is usually addressed under deadline pressure.
The co-op cycle above is the biggest driver, and it appears in nearly every environment we take over here: licences still assigned, access still live, and nobody able to say when it should have ended.
Staff living in Elmira, St. Jacobs, Wellesley, Baden and New Hamburg are on connections that are not what the office has. When a call drops or a file sync stalls, the laptop is usually not the problem, and diagnosing that correctly the first time saves a wasted afternoon.
Waterloo has a high rate of technical people who set up their employer's infrastructure competently and then went to work somewhere else. It is documented in their head. We write it down, which is dull work and the thing most worth paying for in the first ninety days.
Waterloo is about an hour from Toronto on the 401, and rather more between three and seven. That is the practical reason most GTA-based providers serve Waterloo remotely and quote a visit separately — an onsite call costs them a technician's entire afternoon in each direction.
We do not have a Waterloo office and are not going to claim one. Ours is at 22 Frederick St, Suite 700 in downtown Kitchener: about ten minutes from uptown Waterloo, about twenty from Cambridge. That is the honest version and it is also the one that matters, because what determines whether somebody can be at your building this afternoon is the distance from the office to you, not the address printed on a website.
What follows from it: onsite attendance is part of the agreement rather than an event that triggers a separate quote. A hardware swap, a cabling job or a fault that turns out to be physical does not wait for a scheduled visit from a provider driving up the 401.
Yes, and the first thing we do is read it. Most of these ask the same nine or ten things: who holds administrative access, how accounts are removed when somebody leaves, multi-factor coverage, where backups sit and in whose jurisdiction, patch compliance, when a restore was last tested, logging, and who your subprocessors are. We work through them in the order of what can be made both true and evidenceable inside four weeks, and we tell you which answers will have to be honest rather than flattering. A reviewer will accept a dated remediation plan. They will not accept a claim that falls apart on the follow-up question.
No, and be wary of any IT provider that says it can. An auditor issues the report, and SOC 2 is an attestation rather than a certification. What we do is run the environment so the controls behind that report are genuinely in place and can be produced on demand — conditional access enforced rather than merely configured, a joiner and leaver record with dates against it, patch compliance you can export, backups with restore evidence rather than a green tick. We hold a SOC 2 Type 2 attestation for our own operations, which mostly means we have sat on the answering side of the same spreadsheet.
As a scheduled operation rather than a run of unrelated tickets. You give us the intake dates in advance; machines are imaged and accounts provisioned from a standard build before the first day, and the offboarding list runs on the last day of the term whether or not anybody remembers to raise it. Licences come back. Access ends on the date, not on the day someone notices. A student returning for a second term in September is a restore rather than a rebuild.
One. Most providers price them as two, and that split is exactly what creates the gap — the incident lands on the plant and the credentials came from the office. Under one agreement the plant network is segmented from the office network, the controllers are inventoried with their supported operating system and their vendor's written position on patching, and your shift pattern is known so nobody schedules a firewall reboot at the start of an afternoon shift.
About ten minutes from 22 Frederick St, Suite 700 to uptown Waterloo, and about twenty to Cambridge. We do not have a Waterloo office and are not going to claim one. Onsite attendance is part of the agreement rather than an event that triggers a separate quote, emergencies are same day, and everything else is scheduled.
With an inventory and administrative access, in that order. We document what actually exists — tenants, domains, certificates, licences, backup jobs, and the services billed to somebody's personal card — and take ownership of the accounts that control them. It is dull work and it is the single most valuable thing in the first ninety days, because until it is written down every decision you make about the environment is a guess.
One specific problem: their connection is not the office connection, so a dropped call or a stalled file sync is usually the link rather than the laptop. We test from the user's end before touching the machine, because diagnosing that correctly the first time saves a wasted afternoon and an unnecessary drive into the office.
Tell us what's not working. We'll be honest about whether we're the right fit and what it would realistically involve.