The terms governing your use of Wintive’s Microsoft 365 audit and managed services.
Who we are
Wintive is a New Mexico limited liability company (LLC) providing Microsoft 365 security audit and managed services. Our website is https://www.wintive.com.
Eligibility
The services are intended for businesses. To purchase or use them, you must be at least 18 years old (or the age of majority in your jurisdiction) and have the legal capacity and authority to enter into these Terms on behalf of the business you represent. We do not offer the services to minors or to anyone who cannot form a binding contract.
Our services
- M365 Instant Audit — a one-time, read-only Microsoft 365 security audit with a report.
- M365 Master Audit — an in-depth assessment plus remediation, hardened to recognized frameworks (SOC 2, NIST, HIPAA, CIS, ISO 27001).
- M365 Managed Plans — ongoing, recurring Microsoft 365 security management.
Microsoft 365 and third-party services
Microsoft 365 is provided by Microsoft under its own terms, and your use of Microsoft 365 is governed by your agreement with Microsoft. Wintive is an independent Microsoft partner and is not Microsoft; we are not responsible for Microsoft’s services, pricing, or availability.
Access to your environment
Our audit and assessment connect to your Microsoft 365 tenant with read-only permissions — the M365 Instant Audit never modifies your environment. Where a service includes remediation (the M365 Master Audit) or ongoing management (Managed plans), we make configuration changes to harden your environment — only with your authorization and within the agreed scope.
Your authority to consent
By granting administrative consent to our application, you represent and warrant that you are authorized to do so for the tenant in question.
Payment
Fees are charged through our payment provider (Stripe), in US dollars, as one-time or recurring charges depending on the service. You are responsible for any applicable taxes.
Refunds
The M365 Instant and Master Audits are one-time services; except where required by law, fees are non-refundable once the service has been delivered. Managed Plans are recurring and renew automatically until cancelled — you may cancel future renewals at any time, and fees already paid for the current billing period are non-refundable.
What each service delivers
The M365 Instant Audit is a self-service diagnostic: an automated, read-only assessment that pinpoints your security gaps with prioritized, actionable guidance. You implement the fixes yourself — so its outcome is in your hands, and we do not warrant the resulting state of an environment we do not modify.
The M365 Master Audit is done for you: we remediate the identified gaps and harden your tenant to the Wintive security baseline, mapped to recognized frameworks (SOC 2, NIST, HIPAA, CIS, ISO 27001) — at completion your environment meets that baseline, and we stand behind the work we deliver. M365 Managed Plans then keep it there, continuously (see below).
Two honest points on the done-for-you tiers, true across the industry: formal certification of a framework such as SOC 2 or HIPAA is issued by an accredited third party — we harden your environment to that standard but do not issue the certificate itself; and no security provider can guarantee that no incident will ever occur.
M365 Managed Plans
Under an M365 Managed Plan we keep you secured — continuously. We monitor for configuration drift and new risks and remediate on an ongoing basis so your environment stays at the Wintive security baseline over time. Hands-on, continuous — the “plug it in and we keep it” option.
We stand behind our work: we perform the monitoring and remediation in your M365 Managed Plan with professional skill and care. The one honest boundary — true of every security provider — is that no one can guarantee that no incident will ever occur: security is shared, and it depends on your cooperation (timely access, keeping controls in place, following guidance). Scope and service levels are set out in your M365 Managed Plan.
Warranty disclaimer and limitation of liability
We warrant that our services are performed with reasonable professional skill and care. Except for that commitment, and to the maximum extent permitted by law, we disclaim other implied warranties and do not warrant that your environment will be free of all risk or that no security incident will occur. Wintive’s total liability arising out of or relating to the services is limited to the fees you paid for the applicable service (for Managed plans, the fees paid in the 12 months before the claim). Wintive is not liable for indirect, incidental, or consequential damages.
Intellectual property
The reports and other deliverables we provide are for your internal business use. Wintive retains all rights in its methods, software, and materials.
Acceptable use
You agree not to misuse the services, resell them without authorization, or use them in violation of applicable law.
Term and termination
Either party may terminate as set out in the applicable order or plan. Provisions that by their nature should survive termination will survive.
Governing law
These Terms are governed by the laws of the State of New Mexico, United States, without regard to conflict-of-laws rules. The state and federal courts located in New Mexico have exclusive jurisdiction over any dispute arising out of or relating to these Terms or the services, and you consent to that jurisdiction and venue.
Changes and contact
We may update these Terms from time to time. Questions? Email support@wintive.com.