Proof and assurance
What you can verify before you put us in front of a customer.
We would rather publish a short, honest assurance position than a wall of unverifiable claims. This page covers how we handle access, who is accountable for delivery, how quality is controlled across our specialist collective, and how we talk about capacity.
Access and security control
How we hold access to a customer environment
Partners are handing us privileged access to a security platform. The controls below are engagement conditions, not aspirations.
Time-bound access
No standing admin
Least privilege
Named individuals
Audit trail
Data handling
Accountability
Delivery has a named owner
Avertory operates as a directed collective of platform specialists rather than an anonymous body-shop. That model only works if accountability is explicit.
Who is accountable
- Josh Gardner, Director, is accountable for delivery quality on every engagement.
- Each engagement has a single named delivery owner who is the partner’s point of contact.
- Specialists are assigned by platform, and the partner is told who is working on their engagement.
- Escalation runs to the Director, not into a ticket queue.
How quality is controlled
- Work is delivered against a written scope with documented assumptions and exclusions.
- Configuration baselines are peer-reviewed before go-live rather than signed off by the engineer who built them.
- Validation evidence is produced for the controls implemented, so ‘done’ is demonstrable.
- Every engagement closes with a handover pack, which is the artefact the partner presents.
- Retainer work runs on change control: what we may change without approval is agreed up front.
Capacity
How we talk about capacity
We deliberately cap concurrent engagements so delivery quality does not degrade, and we would rather decline a date than miss one.
- Current available capacity is confirmed in writing when we acknowledge an opportunity brief.
- A delivery window is only issued once access, scope and dependencies are understood.
- If we cannot meet a date, we say so at the brief stage rather than after you have quoted.
- Partners with an established working arrangement are scheduled ahead of cold enquiries.
Deliverables
The artefacts a partner receives
These are the standard outputs. They are written so the partner can present them under their own name.
| Artefact | When it is issued | What it is for |
|---|---|---|
| Partner-safe scope | After the readiness sprint | Wrapping into your own statement of work |
| Effort estimate against SKUs | After the readiness sprint | Pricing your services line item |
| As-built configuration baseline | At go-live | Showing the customer what was implemented |
| Validation evidence | At go-live | Demonstrating the controls actually work |
| Handover pack | End of hypercare | Transferring operational ownership |
| QBR pack | Retainer cadence | Evidencing value ahead of renewal |
What we will not publish
Claims we hold back until they can be evidenced
We are early, and we would rather be trusted than impressive.
- We do not claim vendor programme tiers or certifications we cannot currently evidence to a partner.
- We do not publish anonymised case studies or partner quotes until the partner has approved the wording.
- We do not publish rate cards or margin positions publicly — qualified partners receive the commercial pack.
- We do not describe ourselves as a 24/7 SOC, because we are not one.
If you need reference detail for a specific customer opportunity, ask on the brief and we will tell you exactly what we can and cannot evidence.
Send the platform, customer scale and desired date. We return assumptions and a delivery window.
Brief a live opportunity


