You hold the keys to their clients. We treat that seriously.
StageReady sits between an MSP and its clients' Microsoft environments. Here's exactly how those credentials — and every code — are protected.
One-time, hashed codes
6-digit codes are single-use and short-lived, and only a hash is stored — never the code itself.
Credentials in Azure Key Vault
Client secrets live only in Azure Key Vault, read just-in-time. Never in our database, config, the USB, or the device.
Microsoft 365 sign-in
Technicians use their work account. Disable a leaver in your tenant and they lose access automatically, within the hour.
Nothing on the stick
A lost or stolen USB is a non-event — no passwords, no client names, no logic. Just a boot prompt asking for a code.
Isolated by technician & client
Technicians only see the clients they're assigned to, and every action is written to a permanent audit trail.
EU-hosted, GDPR-minded
Runs on Microsoft Azure in the EU (Amsterdam). Device hardware identifiers are treated as personal data.
"What if a stick is lost?" Nothing happens.
The USB contains no passwords, no client names, and no logic — only a boot environment that asks for a code. Whoever finds it gets a prompt they can't answer. Compare that with what's on most homemade staging sticks today.
- No credentials on the stick
- No client data on the stick
- Codes are single-use and expire fast
- Only a hash of each code is ever stored
Hosted in the EU, in Microsoft's Amsterdam region
The application, the database, and the credential vault all run on Microsoft Azure in the European Union. Data stays in the EU.
EU region
Azure West Europe (Amsterdam, Netherlands). Data isn't replicated outside the EU.
Managed database
Azure's managed PostgreSQL with automatic backups and point-in-time recovery.
GDPR-minded
Device hardware identifiers are treated as personal data and handled accordingly.
Bring your toughest security questions.
Book a technical demo — we'll walk your engineers through the architecture end to end.
Book a demo