
Municipalities and agencies operate under constraints private firms don't have: procurement rules, records retention law, freedom of information requests, and a council or board that hears about every outage.
Including if you're preparing an RFP and want to know what's realistic to specify.
We won't sell your data or send you marketing you didn't ask for.
Any competent provider can build a network. Fewer understand why you can't simply buy the obvious solution.
Procurement thresholds mean the obvious solution may need a competitive process, which takes months you may not have.
What counts as a record, how long it's kept, and who can see it are set by statute — not by what's convenient to store.
A disclosure request means someone has to find every relevant record. Architecture that makes that hard costs staff weeks.
Capital and operating budgets are approved annually and publicly. Mid-year unplanned spend is genuinely difficult.
A private company's bad Tuesday is internal. Yours may be a council question, a press enquiry, and a public report.
Tax and permitting platforms may be decades old, unsupported, and still absolutely load-bearing.
Retention, disclosure, and residency aren't policy preferences in the public sector — they're statutory, and they determine what the environment has to be able to do. The Ontario statutes below are the ones we meet most often; every province has its equivalents, from British Columbia's FIPPA to Alberta's FOIP.
Governs access to and privacy of municipal and school board records in Ontario, including the requirement to locate and produce records on request.
The provincial equivalent, covering ministries, agencies, and universities, with similar disclosure duties.
Applies where a public body handles personal health information — paramedic services, public health units, long-term care.
Most municipalities have an adopted retention schedule. The environment has to be able to actually enforce and evidence it.
We build and evidence the technical controls. Your clerk, privacy officer, or legal counsel owns the statutory interpretation — we work to their determination rather than substituting our own.
Badly specified IT RFPs produce bids that can't be compared and contracts that disappoint. We'll happily advise on what's realistic to specify — and we're comfortable with you sharing that with other bidders.
We'll talk through what's realistic to specify and what tends to produce incomparable bids — no obligation, no cost.
We answer clarification questions in writing through your process, on the record like every other bidder.
Our submissions are specific about what's included, what isn't, and what carries additional cost — so scoring means something.
If we win, migration follows a piloted rollout with staff on site — and we deal with the outgoing provider ourselves.
Public bodies present an unusually attractive target: essential services that can't stop, constrained security budgets, and enormous political pressure to restore service quickly.
The consequences are also worse than commercial equivalents. Payments halt, permits stall, emergency dispatch may be affected, and every day of the outage is reported publicly.
Ransomware RecoveryTax, permitting, and records systems often predate everyone currently in the building. Pretending they'll be modernised on a three-year plan isn't useful — protecting them is.
An unsupported system that can't be patched gets segmented so a compromise elsewhere can't reach it — and it can't reach the internet.
Aging physical servers running critical systems get virtualised, so a failed motherboard isn't a two-week service outage.
We'll tell you what genuinely needs replacing, what can run safely for another five years, and what the real cost of each is.
We can advise on what's realistic to specify, and we're comfortable with you sharing that guidance with all bidders — that's the point. If your procurement policy treats pre-RFP advice as disqualifying, tell us and we'll stay out of it. Better a well-specified RFP we lose than a vague one we win.
Yes, where required we host in Canadian regions and document it. Whether residency is legally required for your specific records is a determination for your clerk or privacy officer — we'll build to whatever they conclude, and provide the evidence for your records.
We make sure the architecture supports it: searchable retention, preserved metadata, and access logs that can establish who saw what. The request itself is yours to process — but the difference between a two-day exercise and a three-week one is largely how the systems were built.
Yes, and we won't open with a proposal to replace everything. Legacy public-sector systems are usually load-bearing and genuinely hard to replace. The first job is protecting them — segmentation, virtualisation, tested backups — then planning replacement on a realistic horizon and budget cycle.
Yes. Managed services fall into operating budget, which is more predictable than capital, and we'll flag foreseeable capital needs early enough for your budget process rather than mid-year. Surprise requests are as unwelcome to us as they are to you.
Timing matters more in public sector than most industries, and it's worth planning for explicitly. We'd want an agreed incident communications path — who's told, in what order, and what gets said publicly — before it's needed rather than during.
Whether you're preparing an RFP, reviewing a provider, or dealing with something urgent — tell us where you are and we'll be straight about whether we're the right fit.