Current policies

Customer policies — September 12, 2026 original

Archived published wording before the domains, integration review and AI tutorial operational update. Signed agreements take precedence.

Products, licensing and payment

Managed IT Support and Company Workspace are separate products. Managed IT Support is delivered by TLS staff under an agreed service scope. Company Workspace is customer-administered software; customer administrators manage their own users and permitted settings while TLS retains platform and infrastructure administration.

Both product lines offer Standard, Professional and Enterprise plans per named user, with ten users minimum. Company Workspace list prices are $19, $39 and $69 per user/month. Managed IT Support list prices are $79, $129 and $199 per supported user/month. Monthly subscriptions bill in advance. One-, two- and three-year prepaid terms receive 8%, 12% and 15% discounts respectively. A longer commitment requires an accepted order; changing a plan does not silently replace an existing agreement. Taxes, vendor subscriptions, projects and out-of-scope services are additional as disclosed.

Additional seats are activated after confirmed payment. Self-service increases show an invoice estimate and require payment authorization; a failed or incomplete payment does not grant extra licenses. Current paid users and history are not deleted by a payment failure. Paid invoices and receipts are available through the company billing page and Stripe’s hosted billing portal when connected.

Renewal and nonrenewal

Renewal terms and charges are shown in the accepted order and checkout. For fixed terms, submit a nonrenewal notice at least 30 calendar days before the end date, unless the signed agreement or applicable law requires another rule. Renewal reminders are scheduled for 90, 30, 14 and 7 days before expiry. If a schedule begins late, the next applicable reminder is used instead of sending a backlog.

A notice is recorded in the company account. Requesting nonrenewal is not confirmation that a Stripe subscription has been cancelled; obtain cancellation confirmation through the hosted billing portal or TLS. Monthly plans may be cancelled for the next billing period under their accepted order. No company data is erased by submitting a notice. Export, retention and any eventual deletion follow the signed agreement and a separate authorized process.

Development and QA

Dev starts clean. Professional includes up to five test users; Enterprise includes up to ten. Standard has no included Dev. Test accounts use isolated data and provider credentials. QA is a paid replica of the approved production configuration at a recorded checkpoint, including its version, settings and permitted test fixtures. Credentials, passwords, MFA secrets, active sessions, payment data and unapproved personal information are not copied.

Choose clean Dev or a sanitized QA replica during provisioning. Large replication requests may take up to two hours or require a capacity review; the portal reports the actual provisioning state. A request is not available until isolation, identity, routing and validation finish. Start changes in Dev, promote the same tested artifact to QA, and then promote that artifact to production. Production health checks remain necessary because its domains, secrets and live services differ.

Dev and QA use Production as the identity authority. Production validates the account, role, environment grant and LastStop Verify state, then issues an encrypted, request-bound grant that can be redeemed once within 60 seconds. The environment synchronizes the approved profile and creates a separate session for no more than eight hours. Passwords, Verify private keys and Production cookies are never copied. Sign in again after central role or environment-access changes.

Access and security

Use individual accounts and multi-factor authentication, especially for owners, administrators and billing roles. Domain ownership does not grant TLS owner access. Company data, secrets, license records and permissions stay scoped to the company. A custom-domain change requires ownership verification, a valid certificate and approved routing; it does not change the company identity or its access rights.

Company owners and administrators govern only their company. Role hierarchy, manual groups and time-limited delegated permissions cannot create TLS staff or platform-owner access. Dynamic identity-provider group mappings do not provision access until that company’s verified synchronization adapter confirms membership.

Security is maintained through layered controls, testing, monitoring and incident response. No service can guarantee freedom from every breach or interruption. Healthcare or other regulated use requires a separate assessment and applicable signed agreements, including a business associate agreement where required. A renewal-notice policy alone does not establish HIPAA compliance.

Read-only vendor license intelligence

Authorized company roles may connect a dedicated Microsoft 365 or Google Workspace application to display product types, reported capacity, assigned users and role indicators returned by the provider. LastStop Connect does not expose an action to add, remove or modify an external vendor license. Provider credentials are encrypted, company-scoped and never shown again after saving.

Moving a license source to Trash pauses its use and preserves a recoverable local copy. An authorized administrator may restore it or permanently delete its encrypted connection and cached inventory immediately. Permanent deletion cannot be undone in LastStop Connect, but it does not cancel or alter any Microsoft, Google or other vendor subscription.

Knowledge and co-branding

Technology Last Stop global knowledge is maintained only by TLS platform owners. Company users may read published global guidance but cannot modify, archive, restore or replace it. Authorized company Knowledge managers and administrators may create and maintain only their own company-private articles; private content never becomes global merely by exporting or importing it.

Professional and Enterprise workspaces may add an authorized square company logo. Tenant branding is additive: the official TLS mark, Technology Last Stop platform identity, owner authority and backend controls remain visible and cannot be replaced from company settings. Uploaded logos are type, signature, dimension, size and company-scope checked. Standard workspaces continue with the TLS platform presentation.

Maintenance and incidents

Planned customer-impacting changes are normally announced at least 60 days ahead, with further reminders at 30 days, 7 days, 1 day and 1 hour. The change plan records the customer’s time zone, an overnight maintenance window, an estimated duration range, tested artifact, backup reference and rollback procedure. Urgent security fixes and unplanned outages may require faster action.

Incident trackers show operational, degraded or outage states with written updates. During an active incident, TLS acknowledges the problem and provides progress without promising an unverified restoration time. Support messages should include the incident reference, the affected service and safe next steps.

Copies and questions

Your company account records the policy version, acceptance time and acting user for new orders. Keep the signed order and receipts with your own records. Download the setup PDF below or use your browser’s Print → Save as PDF for this policy.

Download setup and policy guide · Privacy Policy · Portal terms · Contact Technology Last Stop