Common questions
What do leading MSPs include that break/fix shops miss?
RMM monitoring, patch cadence, documented SLAs, backup restore tests, EDR, and a monthly retainer with ownership - not only "call when broken." TUCE sells that model after a $999 audit and cutover.
Is the $999 audit required?
Yes for the standard path. It funds inventory, BPA/security review, and a real retail BOM (not a guess quote).
Does the assessment agent change our network?
No. Assessment is read-only - inventorial only. Network changes happen later, on the new parallel environment after approval, locked backups, and purchase. Full path: /onboarding.
How do you upgrade without breaking production?
After approval we take system-wide image backups and lock them. A cloning/upgrade agent builds a conflict-free new stack beside the old one. Your staff UAT the new side; then workstation/laptop cutover scripts run in a planned window.
Do cloud projects require flights?
No. Cloud cutovers (IONOS / AWS / Azure / GCP) are remote. Travel applies only if you need onsite recycle of old gear, or an on-prem Hyper-V cutover.
What is "fully managed"?
Every stack (hosts, network family, virt, cloud, VoIP, NAS, DreamHost) includes an ops retainer. Cutover labor is not sold alone.
Do you support co-managed IT?
Yes - keep internal Tier-1; we run RMM, Tier-2/3, after-hours options, and security escalate (see co-managed SKUs).
Will maintain windows take our users offline?
Goal is never: HA duplication + parallel upgrades keep users online; otherwise after-hours with written approval. Backups before and after every change. Details: /standards.
Can engineers bypass best practice?
No - not without top-level approval or a logged emergency (with post-incident review). We design so emergencies are rare.
Where is the client portal?
Everything stays on msp.tuce.app: portal, contract e-sign, quotes, a-la-carte, payments, command center. Agents deploy only after required signatures and assessment payment. Auditor console: /mgr.
Do you collect our files or client data?
No. Agents and monitoring use log-level signals only (errors, health thresholds, heal/debug automation). No customer documents, emails, share contents, or PHI. Config and topology are stored locally encrypted on the endpoint (agent_config.enc / topology.enc). See /privacy.
Do you support Shadow Copy, Linux versioning, and SNMP?
Yes - Windows VSS/Shadow Copy, Linux LVM/Btrfs/ZFS/Borg-style versioning, onsite + offsite (3-2-1), SNMP and the full monitoring suite (ICMP, WMI/WinRM, SSH, Syslog, NetFlow). Remote control agents are contract-authorized only. Details: /protocols.
Our hospital / clinic filter blocks the site - what should IT allowlist?
Ask them to allow https://msp.tuce.app as Business / Managed IT. Share /trust (category guidance, no ad trackers, BAA contacts) and /privacy. Do not submit ePHI in registration forms.
What liability protections apply?
Fee-capped liability, no consequential damages (where allowed), customer backup duties, change-control risk allocation, force majeure, and indemnities. See /liability and /terms. Acceptance is recorded on registration and quote approval.
IONOS Cloud vs hyperscalers?
IONOS is our hosted infrastructure lane (VDC, compute, K8s, object storage). AWS/Azure/GCP remain first-class for customers that prefer them - all remote + managed.