Built for compliant workplaces
msp.tuce.app is a legitimate managed-IT business site. We publish privacy terms, limit third-party calls, ship security headers, and offer Business Associate Agreements for HIPAA covered entities - so security teams and web filters can classify us as trusted business infrastructure, not uncategorized risk.
Privacy Policy Request BAA Security contact
Active mailboxes (IONOS): privacy@tuce.app · security@tuce.app · compliance@tuce.app - monitored for privacy, security reports, and BAA requests.
For firewall / proxy administrators
If this hostname is blocked at a healthcare or enterprise site, allowlist:
https://msp.tuce.app(HTTPS only · Let's Encrypt TLS)- Category guidance: Business / Managed IT / Professional Services - not proxy, VPN anonymizer, or hacking
- Downloads under
/download/are ops-log assessment utilities (health/errors for heal/debug) - not remote-control malware and not client-content scrapers - Security contact: security@tuce.app · /.well-known/security.txt
GRC standards
We design security, privacy, and control practices to GRC-level standards — continuous monitoring, evidence readiness, and audit-aligned process discipline. SOC 2–aligned practices are process goals toward audit readiness — not invented certification seals. Details: /grc.
Compliance & trust controls
HIPAA readiness
BAA available before intentional PHI processing. Public site designed for IT ops data - do not submit ePHI in web forms. Not a standalone "HIPAA certified" claim.
Privacy & terms
Published Privacy, Terms, Liability. Acceptance logged on registration and quote approve.
Transport security
HTTPS enforced, HSTS, modern TLS via Let's Encrypt. Security headers: CSP, nosniff, frame controls, referrer policy.
Minimal third parties
No ad/analytics trackers on this property. Fonts served locally. Payment via Stripe Checkout when configured.
Ops-logs only
No client content. Telemetry is log-level health for error, heal, and debug automation - not files, emails, or documents.
Assessment hygiene
Read-only utility; no network config changes. Engineer remote assist is MFA-gated and audited under contract.
Change control
Roadmap gates, pre/post backups, no best-practice bypass without top approval or logged emergency (/standards).
What we do not claim
We do not sell SOC 2 / HITRUST / HIPAA "badges" as products. Compliance readiness packs and BAAs are real contractual work - transparency over marketing seals. See /security.
Organization
Service: TUCE MSP
Website: https://msp.tuce.app
Mail MX: IONOS (mx00.ionos.com / mx01.ionos.com)
Privacy: privacy@tuce.app live
Compliance / BAA: compliance@tuce.app live
Security: security@tuce.app live