Revision 2.0 | Effective April 2026 | Companion to MSA Rev. 2.0
SERVICE STATEMENT
Virtual IT Group, LLC | Revision 2.0 | Effective April 2026 | Companion to MSA Rev. 2.0
1. INTRODUCTION AND RELATIONSHIP TO MSA
1.1 Relationship to MSA. This Service Statement is a supplement to the Virtual IT Group, LLC Master Service Agreement (the “MSA”) and the applicable Quote. All terms of the MSA are incorporated herein by reference. Capitalized terms used but not defined in this Service Statement have the meanings set forth in the MSA. In the event of any conflict between this Service Statement and the MSA, the MSA controls except where this Service Statement provides a more specific provision for a particular Service. In the event of any conflict between this Service Statement and a Quote, the Quote controls.
1.2 Purpose. This Service Statement contains provisions that define, clarify, and govern the Services described in the Quote to which it is attached. If you do not agree with the terms of this Service Statement, you should not sign the Quote and you must contact us for more information.
1.3 Scope. This Service Statement is ViTG’s “owner’s manual” that generally describes all managed services provided by ViTG; however, only those Services specifically described in the Quote will be provided to Client. Activities or items not specifically described in the Quote are out of scope and will not be provided unless otherwise agreed in writing by ViTG.
1.4 Fee Governance. Fee adjustments are governed exclusively by Section 4.2 (Annual Price Adjustment) of the MSA. This Service Statement does not create any separate fee-adjustment right or obligation. Credit card convenience fees and ACH returned-payment fees are governed by Section 4 of the MSA. The specific fees in effect as of Quote acceptance are disclosed on the applicable invoice.
1.5 Hourly Rate Definition. ViTG’s “then-current hourly rate” for work outside recurring Services means the hourly rate in effect on the date the work is performed, provided that ViTG will not raise its hourly rate more than once per calendar year, and any such increase will not exceed the CPI-based adjustment described in MSA §4.2. Current hourly rates are available upon request.
2. ONBOARDING SERVICES
2.1 Onboarding Scope. If onboarding Services are provided under the Quote, the following activities will be performed:
• Uninstall monitoring tools or software installed by previous IT consultants.
• Compile a full inventory of all protected servers, workstations, and laptops.
• Uninstall previous antivirus and install ViTG’s managed antivirus/endpoint protection.
• Install remote support access application on each managed device.
• Configure patch management and check for missing security updates.
• Uninstall unsafe or unnecessary applications.
• Optimize device performance including disk cleanup, antivirus, and spyware scans.
• Review firewall configuration and network infrastructure devices.
• Review battery backup (UPS) protection status on all critical devices.
• Stabilize the network and ensure all devices can securely access file services.
• Review and document current server configuration and status.
• Determine existing backup strategy and status; prepare backup options for consideration.
• Review password policies and update user and device passwords.
• Make recommendations for changes to the managed Environment as applicable.
2.2 Changes to Onboarding. The foregoing list is subject to change if ViTG determines, in its discretion, that different or additional onboarding activities are required.
2.3 Scope Discrepancies. If onboarding discovery reveals that the Environment materially differs from Client’s representations during the sales process (including but not limited to undisclosed hosts, out-of-support systems, unlicensed software, prior undisclosed breach indicators, or Regulated Data holdings not previously disclosed), ViTG may: (a) adjust the Quote pricing to reflect actual scope and provide Client with thirty (30) days to accept or cancel without penalty beyond onboarding fees already incurred; (b) require remediation as a condition of ongoing Services (at Client’s cost); or (c) decline to proceed with ongoing Services and retain 100% of onboarding fees. Client’s failure to disclose material environmental conditions is a breach of MSA §3.3.
2.4 Onboarding Exclusions. Unless otherwise expressly stated in the Quote, onboarding Services do not include the remediation of any issues, errors, or deficiencies discovered during onboarding. ViTG cannot guarantee that all issues will be detected during the onboarding process.
3. ONGOING / RECURRING SERVICES
3.1 General. Ongoing/recurring Services are provided on a continuous basis and, unless otherwise indicated in a Quote, are billed monthly. Ongoing Services generally begin upon the completion of onboarding; any delays to onboarding may delay the commencement of ongoing Services.
3.2 Available Managed Services. The following Services, if listed in the Quote, will be provided to Client:
Remote Monitoring and Management (RMM): Software agents installed in Covered Equipment report status and events on a 24×7 basis; alerts are generated and responded to per the Service Levels described in Section 6.
Onsite Service: Technical assistance provided at Client’s premises, delivered solely at ViTG’s discretion per Section 6.5.
Backup and Disaster Recovery (BDR): 24/7 monitoring of backup systems, including offsite backup, offsite replication, and an onsite backup appliance. See Section 4 for complete BDR terms.
Updates and Patching: Deployment of updates, bug fixes, security patches, service packs, and firmware updates on managed hardware per Section 10.
End User Security Awareness Training: Online on-demand training videos (multilingual), quizzes, baseline phishing simulations, and simulated phishing campaigns.
Hardware as a Service (HaaS): Provision, deployment, support, repair/replacement, and periodic refresh of designated hardware. See Section 5 for complete HaaS terms.
General Support / Diagnostic Services: Level-one type support and diagnostic troubleshooting for the managed Environment. Issues requiring vendor/OEM support, additional licensing, or hardware repair are not included unless expressly stated in the Quote.
4. BACKUP AND DISASTER RECOVERY (BDR)
4.1 Scope. BDR Services apply only to the servers, workstations, and data sources specifically listed in the Quote. Data on equipment not listed in the Quote will not be backed up.
4.2 Storage. Client will be allocated storage space as listed in the Quote. Space beyond that allocation will be provided in blocks of 1 TB at the rate listed in the Quote or at ViTG’s then-current rate.
4.3 Frequency and Security. On-site backups will occur in real time; offsite backups will occur no less than every three (3) hours, Monday through Friday. All backed-up data is encrypted in transit and at rest using AES-256. All offsite facilities implement physical security controls including cameras, access logs, and redundant internet connectivity.
4.4 Retention. Unless otherwise stated in the Quote, backed-up data will be retained for up to one (1) year as a rolling window of recoverable restore points. This rolling backup window is an operational recovery feature and does not constitute a regulatory retention service. Client is solely responsible for all long-term retention obligations, including those imposed by HIPAA, FIPA, PCI-DSS, SOX, IRS recordkeeping rules, and Client’s own insurance or contractual obligations, consistent with MSA §9. If Client requires retention beyond the rolling backup window, Client must purchase a separately-priced long-term archive service. Following termination of the BDR Service, backed-up data will be deleted forty-five (45) calendar days after the close of the data-return window described in MSA §9.2, unless a BAA or equivalent agreement requires longer retention, in which case the BAA terms govern.
4.5 Restore Failures. Recovery coverage assumes data integrity of the backups and the data stored on backup devices. ViTG does not guarantee the integrity of backups. Server restoration will be to the point of the last successful backup. If a backup restoration fails, is incomplete, or produces corrupted data for any reason (including but not limited to silent hardware corruption on the source system, backup media failure, software defects, or file-level integrity issues), Client’s sole and exclusive remedy is a service credit equal to the affected month’s BDR service fee. ViTG shall have no liability for: (a) data unrecoverable due to circumstances predating ViTG’s BDR Service; (b) data corrupted at the source before backup; (c) data that cannot be restored due to encryption keys, licenses, or credentials controlled by Client; or (d) business losses, regulatory penalties, or third-party claims arising from a restore failure.
4.6 Disaster Recovery. BDR planning is included in the applicable Quote. Recovery actions in a declared disaster are a project outside the scope of recurring Services and will incur project fees. Client must contact ViTG to request data recovery; upon payment of applicable project fees, ViTG will make backed-up data available in a hosted virtual environment for a period of two (2) weeks. Extended access is available at ViTG’s then-current rates.
4.7 BDR Software License. ViTG hereby grants Client a non-exclusive, royalty-free, non-transferable license, during the term of the BDR Service, to use the proprietary software embedded in backup appliances (“BDR Software”). Client shall not reverse-engineer, decompile, or otherwise use the BDR Software except as authorized by ViTG.
4.8 BDR Limitations. All data transmitted over the Internet may be subject to malware, unauthorized access attempts, and similar threats. ViTG shall not be responsible for the outcome of such activities. BDR Services require a reliable, always-connected Internet connection; backup and recovery times depend on connection speed and reliability. Internet and telecommunications outages will prevent BDR Services from operating correctly. Due to inherent technology limitations, ViTG cannot warrant that data corruption or loss will be avoided. Client is strongly advised to maintain a separate local backup of critical data.
5. HARDWARE AS A SERVICE (HaaS)
5.1 Equipment. ViTG will provide the HaaS Equipment described in the Quote. If no hardware is expressly designated as HaaS Equipment in the Quote, a complete list will be provided under separate cover.
5.2 Deployment. ViTG will deploy HaaS Equipment within the timeframe stated in the Quote, provided Client promptly provides all reasonably requested information. This deployment guarantee applies only to HaaS Equipment and not to software or other Services. Client may delay deployment by providing written notice within five (5) days of signing the Quote; deployment shall not extend beyond two (2) months, and Client will be charged at 50% of the monthly recurring HaaS fee during the delay period.
5.3 Repair/Replacement. ViTG will repair or replace HaaS Equipment by the end of the business day following the business day on which the problem is identified and determined to be incapable of remote remediation. This warranty does not include time required for system rebuilds (configure replacement, rebuild RAID, reload OS, restore from backup, etc.).
5.4 Service Credits. Service credits for HaaS Equipment failures that materially and adversely affect Client’s hosted environment: 5% of the monthly HaaS fee per hour of downtime (after the initial one-hour problem-identification window), up to 100% of the monthly fee for the affected equipment. Service credits are Client’s sole and exclusive contractual remedy for service-level failures and do not limit or expand the liability limitations in MSA §5. Service credits are not cumulative with other damages.
5.5 Periodic Replacement. ViTG will refresh HaaS Equipment on a rolling basis, generally replacing units on or before the fifth (5th) anniversary of deployment. Equipment may be replaced earlier where ViTG determines it has reached end-of-support, is underperforming, or poses a security risk, subject to manufacturer supply-chain availability. Equipment refresh at or before five (5) years is a material component of the HaaS service and is included in the HaaS fee.
5.6 Insurance. All HaaS Equipment must be insured by Client for the full replacement value. ViTG must be listed as an additional insured and loss payee on any such policy. The policy must require the insurer to provide at least thirty (30) days’ prior written notice to ViTG before cancellation, non-renewal, or material modification. Client shall not voluntarily cancel or materially reduce coverage during the HaaS term, and shall promptly replace any coverage involuntarily cancelled. Upon request, Client shall provide proof of insurance including proof of premium payment.
5.7 Return of Equipment. Client shall not remove or disable, or attempt to remove or disable, any software agents installed by ViTG in HaaS Equipment unless expressly directed by ViTG. Unauthorized removal may result in network vulnerabilities, continuation of license fees (at Client’s expense), and remediation charges at ViTG’s then-current hourly rates. Within ten (10) business days after termination of HaaS Services, Client will provide ViTG access to the premises at which HaaS Equipment is located so that all equipment may be retrieved. If Client fails to provide timely access, or if equipment is returned damaged (normal wear and tear excepted), ViTG may invoice Client for full replacement value.
5.8 Use Restrictions. Client will use all ViTG-hosted or ViTG-supplied equipment and hardware (collectively, “Infrastructure”) for internal business purposes only. Client shall not sublease, sublicense, rent, or otherwise make the Infrastructure available to any third party without ViTG’s prior written consent. ViTG reserves the right to throttle or suspend access if Client’s use violates the Quote, this Service Statement, or the MSA.
6. SERVICE LEVELS
6.1 General. Automated monitoring is provided 24x7x365. Response, repair, and remediation services are provided during business hours unless the Quote specifies extended-hours coverage. Severity levels are determined by ViTG in its discretion after consulting with Client. All remediation is initially attempted remotely; ViTG will provide onsite service only if remote remediation is ineffective, and only at ViTG’s sole discretion.
6.2 Response Time Calculation. Response times are calculated from the time ViTG is notified through its designated support channels (support portal, help desk, or telephone at the number listed in the Quote). Notifications received in any other manner may result in delayed response. Help desk support outside normal business hours will be billed at 1.5× the listed hourly rate (2-hour minimum applies).
6.3 Severity Matrix. The following response targets apply, subject to the service tier indicated in the Quote:
Severity
Standard Response
Extended-Hours Response
P1 — Critical: Service unavailable (all users/functions affected)
2 hours
1 hour (if purchased)
P2 — Significant: Large number of users or business-critical functions affected
4 hours
2 hours (if purchased)
P3 — Limited: Limited users/functions affected; workaround available
8 business hours
4 business hours (if purchased)
P4 — Small: One user affected; business can continue
2 business days
1 business day (if purchased)
6.4 Service Availability. ViTG targets 99.5% monthly availability for managed Services (excluding Scheduled Downtime, Client-Side Downtime, Vendor-Side Downtime, force majeure events, and Third Party Service outages). If monthly availability falls below 99.0% for reasons within ViTG’s control and not excluded above, Client is entitled to a service credit equal to 5% of the affected monthly fee per half-percentage-point of availability below 99.0%, up to 50% of the affected monthly fee. Service credits must be claimed in writing within thirty (30) days of the end of the month in which the shortfall occurred, and Client must have reported the outage through designated support channels within twenty-four (24) hours of becoming aware of it. Service credits are Client’s sole and exclusive remedy for availability failures.
6.4a Restoration Time Disclaimer. The availability target in Section 6.4 measures whether ViTG’s managed monitoring, alerting, and remote-support Services are accessible and responding — it does not measure, and ViTG does not warrant, the time required to fully restore the Environment, applications, or data following a hardware failure, Security Incident, or other disruptive event. Full restoration time depends on factors outside ViTG’s control, including but not limited to: (a) manufacturer warranty response times for replacement hardware (which may range from 4 hours to 10+ business days depending on the warranty level purchased by Client); (b) RAID array rebuild times (which are hardware-dependent and may take 4–48+ hours); (c) operating system, application, and configuration restoration (which depends on the complexity of the Environment); (d) data restoration from backup (which depends on data volume and backup infrastructure performance); (e) availability of vendor-specific licenses, activation keys, and software media; and (f) third-party dependencies including ISP, cloud provider, and SaaS vendor restoration timelines. Client is strongly advised to purchase hardware with the highest available manufacturer warranty tier (e.g., 4-hour onsite, next-business-day) and to maintain an adequate inventory of critical spare equipment. ViTG’s responsibility during a restoration event is to commence remediation efforts within the response times specified in Section 6.3 and to work diligently toward restoration; ViTG does not guarantee any specific restoration completion time. THE AVAILABILITY TARGET AND SERVICE CREDITS IN SECTION 6.4 ARE CLIENT’S SOLE AND EXCLUSIVE REMEDY FOR SERVICE INTERRUPTIONS AND DO NOT CREATE ANY WARRANTY, GUARANTEE, OR OBLIGATION REGARDING RESTORATION TIME, HARDWARE REPLACEMENT TIME, OR DATA RECOVERY TIME.
6.5 Onsite Services. All Services are delivered remotely by default. ViTG-initiated onsite visits are included at no additional charge when ViTG determines, in its sole professional judgment, that remote remediation is insufficient or infeasible for the issue at hand. Client may request onsite support; however, Client-requested onsite visits (where ViTG has not independently determined that onsite is necessary) are available as a separately-billed service at ViTG’s then-current hourly rate plus travel per Section 6.6. ViTG reserves sole discretion to approve or decline any Client-initiated onsite request based on technical necessity, technician availability, and geographic feasibility. Scheduled recurring onsite visits (monthly, quarterly, or otherwise) are not included in any service tier unless a specific Onsite Visit Package is purchased as a separately-priced add-on in the Quote. For Clients located outside ViTG’s primary service area (25-mile radius of Brandon, FL), ViTG-initiated onsite services may be delivered by a qualified third-party field service provider dispatched by ViTG, with dispatch costs included as a cost of service delivery. Client-requested onsite visits for remote locations are billable at actual cost plus a 15% coordination fee. Remote Clients may purchase an Onsite Visit Package as a Quote add-on; onsite delivery method (ViTG staff travel, third-party field dispatch, or local partner) and response commitments for remote onsite are defined in the applicable Quote and may differ from ViTG’s primary service area commitments.
6.6 Travel. Onsite Services provided within a twenty-five (25) mile radius of ViTG’s Brandon, Florida office are included at no additional travel charge when approved by ViTG. Travel beyond this radius will be billed at ViTG’s then-current hourly rate, door to door, plus actual tolls, parking, and per-mile reimbursement at the current IRS business mileage rate.
6.7 Cancellations. Client may cancel or reschedule any appointment at no charge by providing at least one (1) business day’s advance notice. Without timely notice, or if Client is not present or ViTG is denied access at the scheduled time, Client agrees to pay a cancellation fee equal to two (2) hours at ViTG’s then-current hourly rate.
7. COVERED EQUIPMENT
7.1 Scope. Managed Services will be applied to the equipment listed in the Quote (“Covered Hardware”) and the software listed in the Quote (“Supported Software”), provided that all Supported Software must at all times be properly licensed and, where applicable, under a manufacturer maintenance/support agreement. Covered Hardware and Supported Software are collectively referred to as the “Covered Equipment.”
7.2 Physical Locations. Unless otherwise agreed in writing, all onsite Services will be provided at Client’s primary office location listed in the Quote. Unless the Quote expressly provides for a specific number of onsite visits, Services are delivered remotely per Section 6.5.
8. TERM AND FEES
8.1 Commencement. Services will commence and billing will begin on the date indicated in the Quote (“Commencement Date”) and will continue through the Initial Term listed in the Quote. ViTG reserves the right to delay the Commencement Date until all onboarding/transition activities are completed and all deficiencies are addressed to ViTG’s satisfaction.
8.2 Auto-Renewal. After the Initial Term, the Service Term will automatically renew for contiguous terms equal to the Initial Term unless either party provides written notice of non-renewal at least sixty (60) days before the end of the then-current term. ViTG will provide written notice of any upcoming auto-renewal not less than sixty (60) days prior to the renewal date, identifying the renewal term and any price change, consistent with MSA §10.1.
8.3 Fees and MMF. Fees are as indicated in the Quote. If the managed Environment changes or the number of authorized users changes, fees will be automatically adjusted to accommodate those changes. The initial fees in the Quote are the minimum monthly fees (“MMF”); amounts paid will not drop below the MMF regardless of changes, unless ViTG agrees in writing.
8.4 Automated Payment. Invoices must be paid by automated recurring means (ACH or credit card) unless waived by ViTG in writing. If both are on file, ACH is attempted first; if ACH fails, the designated credit card will be charged. A $35.00 service charge applies to any ACH debit returned unpaid. If a payment method fails, ViTG will retry once within three (3) business days. If the retry fails, ViTG may (a) suspend Services until successful payment, (b) require an alternate payment method within ten (10) days, or (c) upon fourteen (14) days of unpaid balance, terminate For Cause under MSA §10.3. Client remains responsible for all fees accrued during suspension.
9. ASSUMPTIONS, MINIMUM REQUIREMENTS, AND EXCLUSIONS
9.1 Minimum Requirements. The scheduling, fees, and provision of Services are based upon the following assumptions and minimum requirements:
• Server hardware must be under current warranty coverage.
• All equipment with Microsoft Windows operating systems must be running then-currently supported versions with all latest service packs and critical updates installed.
• All software must be genuine, licensed, and under vendor-supported maintenance or technical support.
• Server file systems and email systems (if applicable) must be protected by licensed, current antivirus software.
• The Environment must have a currently licensed, vendor-supported, server-based backup solution that can be monitored.
• All wireless data traffic in the Environment must be securely encrypted.
• A static IP address must be assigned to a network device allowing VPN/RDP access.
• All servers must be connected to working UPS devices.
• Client must provide all software installation media and key codes in the event of a failure.
• Client must provide ViTG with exclusive administrative privileges to the managed Environment.
• Client must not install accessories, additions, upgrades, equipment, or devices on the firewall, server, or NAS appliances without ViTG’s express written approval.
• Costs to bring the Environment up to these minimum standards are not included unless expressly stated in the Quote.
9.2 Exclusions. The following services are expressly excluded from all Quotes unless separately agreed in writing by ViTG:
• Moves, adds, or changes to the managed Environment.
• Customization of third-party applications, or programming of any kind.
• Support for operating systems, applications, or hardware no longer supported by the manufacturer.
• Data/voice wiring or cabling services.
• Battery backup replacement.
• Equipment relocation.
• Costs to bring the Environment up to Minimum Requirements (unless noted in the Quote).
• Costs to repair or replace hardware, or to acquire parts, equipment, or pay shipping charges.
• Remediation and/or recovery from a Security Incident, ransomware, or data-loss event (see Section 11).
10. PATCH MANAGEMENT
10.1 Patching SLA. ViTG applies security-critical patches in accordance with the Common Vulnerability Scoring System (CVSS) severity ratings and the following internal patch-management SLA: CVSS 9.0–10.0 (Critical) within seven (7) days of vendor release; CVSS 7.0–8.9 (High) within thirty (30) days; CVSS below 7.0 within sixty (60) days, subject to compatibility testing. ViTG may delay or decline a patch only where ViTG determines, in its reasonable discretion, that the patch is unstable, incompatible with the Environment, or outweighed by operational risk, and will document such decisions. Client is responsible for patching any systems not expressly within ViTG’s patch-management scope.
10.2 Patch Disclaimer. Patches are developed by third-party vendors and may, on rare occasions, render the Environment or portions of it unstable. ViTG will not be responsible for downtime or losses arising from or related to the installation or use of any patch, even when installed correctly.
11. SECURITY INCIDENT RESPONSE AND CYBERSECURITY
11.1 Security Incident Recovery — Out of Scope. Unless otherwise expressly stated in the Quote, the scope of the Services do not include the remediation and/or recovery from a Security Incident. Such services, if requested, will be provided on a time-and-materials basis at ViTG’s then-current hourly rate. Given the varied nature of Security Incidents, ViTG cannot warrant (i) the amount of time required to remediate a Security Incident (or that recovery will be possible under all circumstances), or (ii) that all Impacted Data will be recoverable.
11.2 Incident Response Retainer. Incident Response (“IR”) is a discrete service offered separately from ongoing managed Services. If Client purchases an IR Retainer under the Quote, ViTG will provide dedicated IR resources within the retainer hours and at the retainer response SLA. Without an IR Retainer, ViTG’s response to a Security Incident will be on a best-efforts, as-available basis and will be billed at 1.5× ViTG’s then-current hourly rate with a 10-hour minimum. Client is strongly advised to purchase an IR Retainer before a Security Incident occurs; emergency engagement rates (after an incident has begun) are 2.5× ViTG’s then-current hourly rate with a 40-hour minimum.
11.3 Antivirus / Anti-Malware. ViTG’s antivirus/anti-malware solution will generally protect the Environment from becoming infected with new malware; however, malware existing in the Environment prior to implementation may not be removable without additional services. ViTG does not warrant that all malware will be detected, avoided, or removed, or that any Impacted Data will be recoverable. Unless otherwise stated in the Quote, remediation of virus or ransomware incidents is not included in the Services. Information about processed files, URL reputation data, and security statistics may be shared with ViTG’s designated security affiliates for threat-intelligence purposes; such information does not contain personal or confidential information.
11.4 Dark Web Monitoring. Dark web monitoring uses third-party data sources that may be incomplete, delayed, or inaccurate. ViTG does not warrant: (a) that all exposed credentials or data will be detected; (b) that detection will occur before credentials are exploited; (c) that notifications will be received in any particular timeframe; or (d) that remediation following detection will prevent harm. Dark web monitoring is advisory only and does not replace Client’s obligation to implement MFA, rotate credentials, and maintain security hygiene as required by MSA §3.
12. MONITORING, REMEDIATION, AND ENVIRONMENT CHANGES
12.1 Monitoring. Unless otherwise indicated in the Quote, all monitoring and alert-type services are limited to detection and notification functionalities only. Monitoring levels are set by ViTG; Client shall not modify these levels without ViTG’s prior written consent.
12.2 Remediation. Unless otherwise provided in the Quote, remediation services are provided in accordance with managed services industry recommended practices. Remediation is not a warranty or guarantee of the functionality of the Environment, or a service plan for repair of any particular hardware or software.
12.3 Unauthorized Modifications. Changes made to the Environment without ViTG’s prior authorization may have a substantial negative impact on the Services and may affect fees. Client agrees to refrain from moving, modifying, or altering any portion of the Environment without ViTG’s prior consent (including adding/removing hardware, installing applications, or modifying configuration or log files).
12.4 Co-Managed Environments. In a co-managed Environment, ViTG will coordinate with Client’s internal IT personnel as necessary. ViTG is not responsible for remediation of issues caused by activities of Client’s internal IT personnel that are beyond the scope of the Quote and not pre-authorized by ViTG, consistent with MSA §2.6.
12.5 Third-Party Service Configurations. Certain third-party services may provide Client with administrative access to modify configurations. Unauthorized modifications by Client could disrupt the Services or increase fees. Client is solely responsible for increased fees or costs arising from unauthorized configuration changes.
13. VoIP / PHONE SYSTEM
13.1 911 Limitations. The VoIP Service (“VoIP Service”) may not support traditional 911 or E911 access to emergency services in all locations. The 911 feature is not automatic; Client must take affirmative steps to register the address where the VoIP Service will be used. Client must inform all users of the VoIP Service of the limitations of 911 dialing. When a VoIP calling device is registered at a location, it must not be moved without re-registering; Client shall not move any VoIP device without ViTG’s written consent. Client holds ViTG harmless for claims arising from inability to use 911/E911 services.
13.2 Kari’s Law / RAY BAUM’s Act Compliance. Client acknowledges its obligations under Kari’s Law (47 U.S.C. § 623) and the RAY BAUM’s Act (47 U.S.C. § 615 Note) for multi-line telephone systems, including direct 911 dialing without prefixes and provision of dispatchable location information. ViTG will configure the VoIP System to support these requirements based on Client’s registered site information; Client is responsible for maintaining accurate location data, internal notification contacts, and user training on 911 procedures.
13.3 VoIP Operational Limitations. Client understands that 911 dialing does not function during power failures, ISP/broadband outages, or service suspensions. 911 dialing will not function if Client changes telephone numbers or adds/ports new numbers until the location of use is re-registered for each number. Client authorizes ViTG to disclose Client’s name and address to call routers, call centers, and PSAPs for the purpose of dispatching emergency services. Client agrees not to use the VoIP System for autodialing, telemarketing, fax broadcasting, or usage inconsistent with standard commercial calling patterns.
14. THIRD PARTY SERVICE DATA RETENTION
14.1 Third Party Retention. Many Services depend on Third Party Providers and Third Party Services (e.g., Huntress for EDR, Avanan for email security, Microsoft 365, cloud backup vendors, SIEM platforms). The retention periods, availability, accessibility, and data-export formats of such Third Party Services are governed entirely by the applicable Third Party Provider’s terms and are outside ViTG’s control. By way of example only (without creating any obligation or warranty): EDR alert data may be retained by the underlying vendor for approximately 365 days; email security quarantine and log data for approximately 180 days; and Microsoft 365 audit log retention varies by license tier (90 days to multiple years with add-on licenses).
14.2 Client Responsibility. Client acknowledges: (a) ViTG has no obligation to retain, archive, or preserve Third Party Service data beyond what the underlying vendor provides; (b) if Client’s regulatory or legal obligations require longer retention, Client is responsible for purchasing additional retention services (directly from the vendor or as a separately-priced add-on through ViTG); and (c) ViTG shall have no liability for loss of access to, unavailability of, or deletion of data by any Third Party Provider.
15. ADDITIONAL SERVICES AND TERMS
15.1 Domain Names and IP Addresses. If Client registers, renews, or transfers a domain name through ViTG, ViTG will submit the request to the applicable registrar on Client’s behalf. ViTG’s sole responsibility is to submit the request, and ViTG is not responsible for any errors, omissions, or failures of the registrar. Any IP addresses provided by ViTG during the Service Term are managed by ViTG and will be retained by ViTG after termination.
15.2 Hosted Email. Client is solely responsible for the proper use of any hosted email service (“Hosted Email”). Client must comply with all applicable AUPs and agrees to refrain from uploading, posting, transmitting, or distributing (or permitting users to do so) any content that is obscene, illegal, infringes intellectual property or privacy rights, creates a false identity, disrupts services, or contains malware. Client shall not use Hosted Email for unsolicited commercial messages (SPAM) in violation of any federal or state law. ViTG may suspend Hosted Email access if ViTG believes the account is being used improperly.
15.3 Hosting Services / AUP. Client is responsible for the actions of its users. Neither Client nor any employee or representative will use the Services in violation of any law. Client will not: transmit unsolicited bulk email; engage in denial-of-service attacks; infringe third-party IP rights; collect personally identifiable information without proper consent and privacy policies; or undertake any action harmful to ViTG or its infrastructure. Client is solely responsible for the security and strength of login credentials. ViTG shall have no liability for unauthorized use of Client’s credentials. Client must notify ViTG immediately if credentials are lost, stolen, or used by unauthorized parties.
15.4 Environmental Factors. Exposure to environmental factors (water, heat, cold, varying lighting conditions) may cause installed equipment to malfunction. Unless expressly stated in the Quote, ViTG does not warrant that equipment will operate error-free or that any video or audio equipment will capture events under all circumstances.
15.5 Fair Usage Policy. ViTG’s Fair Usage Policy (“FUP”) applies to all Services designated as “unlimited.” Unlimited means Client may use the service as reasonably necessary without incurring additional time-based or usage-based costs, subject to: normal business hours (unless otherwise stated); technician availability (not guaranteed); and ViTG’s right to prioritize more urgent issues. Client agrees to refrain from: creating urgent tickets for non-urgent issues; requesting excessive support inconsistent with industry norms; or requesting services that may interfere with ViTG’s ability to serve other clients.
15.6 vCTO / vCIO Services. Advice and suggestions provided by ViTG in a virtual CTO/CIO capacity are for informational and educational purposes only. ViTG will not hold an actual director or officer position in Client’s company, and ViTG will not hold or maintain any fiduciary relationship with Client. Under no circumstances shall Client list ViTG on Client’s corporate records or accounts.
15.7 Sample Policies. Any Sample Policies (template policies and procedures) provided by ViTG are for informational use only and do not constitute legal or professional advice. Client should seek competent legal counsel before using or distributing Sample Policies. ViTG does not warrant that Sample Policies are complete, accurate, or suitable for Client’s needs. Client agrees to: (a) have all Sample Policies reviewed by Client’s own legal counsel before adoption; (b) not represent that the policies were drafted or endorsed by ViTG’s attorneys; and (c) hold ViTG harmless from any claim arising from Client’s use of the Sample Policies.
15.8 Unsupported Configurations. If ViTG designates a configuration element or service as Unsupported (by any of the following terms in a Quote or service description: “Unsupported,” “Non-Standard,” “Best Efforts,” “EOL,” or “End of Support”), ViTG makes no representation or warranty with respect to such element, and no SLA, availability guarantee, or deployment commitment shall apply.
15.9 Licenses. If ViTG is required to re-install or replicate any software provided by Client, it is Client’s responsibility to verify proper licensing. ViTG reserves the right to require proof of licensing before installation. License acquisition costs are not included in the Quote unless expressly stated.
15.10 Procurement. Equipment and software procured by ViTG on Client’s behalf may be covered by manufacturer warranties, which will be passed through to Client to the greatest extent possible. ViTG makes no warranties regarding the quality, integrity, or usefulness of procured items. Return policies, re-stocking fees, and warranty terms are governed by the third-party provider.
15.11 QBR and Strategic Planning. Quarterly Business Reviews (QBRs) and IT strategic planning suggestions are provided in accordance with relevant industry practices based on Client’s specific needs. By rendering advice or suggesting a solution, ViTG does not endorse any particular manufacturer or service provider.
16. PENETRATION TESTING AND VULNERABILITY ASSESSMENT
16.1 Pre-Engagement Authorization. Penetration testing engagements require a written Pre-Engagement Authorization signed by Client and ViTG no less than five (5) business days prior to testing. The Pre-Engagement Authorization must include: (a) list of systems in scope and out of scope; (b) testing window (start and stop times); (c) Client’s confirmation that monitoring companies, alarm providers, ISPs, and law enforcement liaisons (as applicable) have been notified; (d) Client’s emergency contact list; and (e) Client’s written attestation of legal authority to authorize testing against the target systems. Testing will not commence until the Pre-Engagement Authorization is executed.
16.2 False Alarms. Security devices, alarms, or other security measures may be tripped during penetration testing despite ViTG’s efforts to avoid such occurrences. Client is solely responsible for notifying monitoring companies and law enforcement of the potential for false alarms. Client agrees to hold ViTG harmless from all claims, costs, or expenses arising from any response to testing by monitoring companies or law enforcement, or from any shutdown of the Environment by security devices.
16.3 Unauthorized Testing. Unless authorized by ViTG in writing, Client will not conduct any test (diagnostic or otherwise) of ViTG’s security systems, protocols, or solutions. Services required to diagnose or remediate issues arising from unauthorized testing are not covered and will be billed at ViTG’s then-current hourly rates.
Virtual IT Group, LLC • Service Statement Revision 2.0 • Effective April 2026 • Companion to MSA Rev. 2.0