Trust and security
How we access and protect the environments we work in.
Our engineers work inside the systems that hold your identity, data and security controls. These are the rules we follow for that access, and the records you can check for yourself.

Access to your environment
- Named accounts for each engineer, with no shared credentials
- Least privilege: access is limited to the domains in your agreement
- Just-in-time admin: elevated rights are requested for a task and expire afterwards, using Entra Privileged Identity Management where your tenant supports it
- Multi-factor authentication on every account we use, phishing-resistant where your tenant supports it
- Access through Microsoft's delegated models where they apply, such as Azure Lighthouse and granular delegated admin privileges
- You can see and remove our access at any time
What you can check
- Our sign-ins and admin actions appear in your own audit logs
- Every change is a reviewed commit in a repository you own
- The monthly engineering report lists every change and who made it
Your data
- Your data stays in your tenant. We work on it where it is, and copy it to our systems only when a task needs it and you agree
- Your data is never used to train AI models
- AI tools are used only under business terms that exclude training on customer data
- Code, runbooks and documentation belong to you and live in your repository
How we secure North Ark
Everyone who works on client environments uses MFA and a managed device.
North Ark is a member of the Microsoft AI Cloud Partner Program.
We hold professional indemnity and cyber insurance.
If something goes wrong
If we find or suspect a security incident affecting your environment, we tell your nominated contact as soon as we know. We work the incident under the severity model in your agreement and give you a written root cause.
When an engagement ends
- Handover of the repository, runbooks and open work to your team or your next provider.
- Removal of all North Ark access, with credentials rotated where we held any.
- Written confirmation that access has been removed.
Questions buyers ask
Will you complete our vendor security questionnaire?
Yes. Send it with your enquiry and we will return it as part of scoping.
Where is our data stored?
In your own tenant and your own repository. We keep client data on our systems only when a task needs it and you agree.
Do you use subcontractors?
Trusted associates work on some engagements under the same access rules as our engineers. You are told who will have access before they get it.
Do you use AI tools on our systems?
Engineers use AI-assisted tools for triage, evidence gathering and drafting, under business terms that exclude training. Your data is never used to train AI models.
How do we remove your access?
Any of your tenant administrators can remove it at any time. At the end of an engagement we remove it ourselves and confirm in writing.
Start a conversation
Check how we would work in your environment before you commit.
Bring your security questions to the first call.
Talk to an Engineer