TUCE MSPTUCE MSP
FAQ

Common questions

What do leading MSPs include that break/fix shops miss?

RMM monitoring, patch cadence, documented SLAs, backup restore tests, EDR, and a monthly retainer with ownership - not only "call when broken." TUCE sells that model after a $999 audit and cutover.

Is the $999 audit required?

Yes for the standard path. It funds inventory, BPA/security review, and a real retail BOM (not a guess quote).

Does the assessment agent change our network?

No. Assessment is read-only - inventorial only. Network changes happen later, on the new parallel environment after approval, locked backups, and purchase. Full path: /onboarding.

How do you upgrade without breaking production?

After approval we take system-wide image backups and lock them. A cloning/upgrade agent builds a conflict-free new stack beside the old one. Your staff UAT the new side; then workstation/laptop cutover scripts run in a planned window.

Do cloud projects require flights?

No. Cloud cutovers (IONOS / AWS / Azure / GCP) are remote. Travel applies only if you need onsite recycle of old gear, or an on-prem Hyper-V cutover.

What is "fully managed"?

Every stack (hosts, network family, virt, cloud, VoIP, NAS, DreamHost) includes an ops retainer. Cutover labor is not sold alone.

Do you support co-managed IT?

Yes - keep internal Tier-1; we run RMM, Tier-2/3, after-hours options, and security escalate (see co-managed SKUs).

Will maintain windows take our users offline?

Goal is never: HA duplication + parallel upgrades keep users online; otherwise after-hours with written approval. Backups before and after every change. Details: /standards.

Can engineers bypass best practice?

No - not without top-level approval or a logged emergency (with post-incident review). We design so emergencies are rare.

Where is the client portal?

Everything stays on msp.tuce.app: portal, contract e-sign, quotes, a-la-carte, payments, command center. Agents deploy only after required signatures and assessment payment. Auditor console: /mgr.

Do you collect our files or client data?

No. Agents and monitoring use log-level signals only (errors, health thresholds, heal/debug automation). No customer documents, emails, share contents, or PHI. Config and topology are stored locally encrypted on the endpoint (agent_config.enc / topology.enc). See /privacy.

Do you support Shadow Copy, Linux versioning, and SNMP?

Yes - Windows VSS/Shadow Copy, Linux LVM/Btrfs/ZFS/Borg-style versioning, onsite + offsite (3-2-1), SNMP and the full monitoring suite (ICMP, WMI/WinRM, SSH, Syslog, NetFlow). Remote control agents are contract-authorized only. Details: /protocols.

Our hospital / clinic filter blocks the site - what should IT allowlist?

Ask them to allow https://msp.tuce.app as Business / Managed IT. Share /trust (category guidance, no ad trackers, BAA contacts) and /privacy. Do not submit ePHI in registration forms.

What liability protections apply?

Fee-capped liability, no consequential damages (where allowed), customer backup duties, change-control risk allocation, force majeure, and indemnities. See /liability and /terms. Acceptance is recorded on registration and quote approval.

IONOS Cloud vs hyperscalers?

IONOS is our hosted infrastructure lane (VDC, compute, K8s, object storage). AWS/Azure/GCP remain first-class for customers that prefer them - all remote + managed.

Register SLAs