Security and data
Firstline works on your clients’ computers, under your name. This page covers what it may and may not do there, how each client’s data stays separated, what gets written into your PSA, and where we stand on certification.
Last updated 18 August 2026
How Firstline does the work
Tickets reach Firstline through your PSA and service desk, the same way they reach your technicians. Part of the work runs through connected systems: your PSA, RMM, identity provider and device management, using defined actions with defined parameters. These are deterministic and reviewable.
Most tier-1 problems only exist on the end user’s screen, so Firstline also works on the endpoint itself. It takes a remote session and operates the machine through a support-specific harness that surrounds the underlying model with permissions, approved actions, session state, interruption controls and structured logging. It is close to what your technician does over a remote-support tool today, with the agent performing the interaction and your technician holding the approval.
The controls
Technician approval before changes
Firstline states what it intends to do in plain language and waits. Your technician approves or adjusts it in one click. Read-only diagnosis runs without a prompt, and you can pre-approve specific low-risk actions per client so routine work does not queue behind a human.
A defined set of actions, not open access
The agent works through a restricted toolset agreed with you. Each tool carries what it may affect, which parameters are valid, which approval it needs and how success is verified. There is no general-purpose access to the endpoint or to your systems.
Rules enforced per client
A policy runtime holds a separate rule set for each client. Reading device logs and state is allowed, changing network or system configuration needs approval, user files and credentials are blocked. The runtime enforces those rules rather than leaving them to the agent's judgement.
Client data stays separated
Tickets, telemetry, device data and configuration are isolated per client. Nothing Firstline sees or learns on one account is reachable from another, and nothing crosses the boundary between two clients you serve.
No standing access
Access is granted for the ticket at hand and not retained afterwards. The remote session is established for that support session and removed when it ends. Firstline holds no permanent administrator rights across your client fleet, and credentials are not stored for reuse between tickets.
Bounded memory
When your technician adjusts a step, Firstline keeps that preference for that client, so the same correction is not needed twice. It stores the preference and the reasoning behind it, not the end user's files or screen contents, and it stays inside that client's boundary.
Verification before closing
A repair is not finished because a command succeeded. Firstline tests that the original symptom is gone, the VPN connects, the mail sends, the right service is running, and writes what it checked into the ticket. Unverified means unresolved.
It stops rather than improvises
Firstline escalates instead of continuing when evidence is thin, an action falls outside its permissions, the device is in an unexpected state, verification fails, or the issue touches security or data loss. Autonomy means finishing approved work within explicit limits, not trying until something works.
What Firstline does not do
- Hold permanent administrator access to your clients' devices
- Read user files or credentials. That stays blocked whatever else you allow
- Work on an endpoint outside an active support session
- Make a change your rules for that client have not approved
- Move data, context or learned preferences between two of your clients
- Touch servers, networks or infrastructure. It works on endpoints and the systems you connect
- Make its own security decisions. It operates inside your policy rather than its own reading of it
What gets recorded
Every ticket leaves a complete record in your PSA:
- What it observed on the device and what it concluded
- What it proposed, and which technician approved it
- Which tools it used and which changes it made
- How it verified the result
- Why it closed the ticket, or why it escalated
Remote sessions can be recorded where your policy and your client’s policy allow. When Firstline escalates, the diagnostic trace travels with the ticket, so your technician continues an investigation rather than starting one. The same record is what you show a client who asks what happened on their machine.
Data
Firstline processes ticket content, diagnostics from the endpoint and connected systems, and what happens on screen during a support session. In an MSP deployment your client is the controller of that data, you are their processor, and we act as your subprocessor under a data processing agreement signed with you before a pilot begins.
Scope, storage location and retention are set per deployment and written into that agreement rather than assumed by us. The subprocessors involved, including model providers and hosting, are listed there, and we will send the current list on request in a form you can pass straight to your client. Data collected through this website is a separate matter and is covered by our privacy policy.
Where we stand on certification
The straight answer: we are not ISO 27001 or SOC 2 certified. Firstline is an early-stage company running supervised pilots, and we would rather tell you that than let an ambiguous badge imply otherwise.
What we can do while that is true:
- Complete your security questionnaire, and the ones your clients send you
- Walk your team, or your client’s security team, through the architecture and the full action list
- Sign a data processing agreement and stand as a named subprocessor in yours
- Scope a first deployment down to something you are comfortable approving
We intend to certify as the company grows, and we will say so on this page when it is done, not before.
What a first deployment looks like
We do not ask anyone to hand over the service desk. A first deployment is deliberately small:
- One client, or one site, not your whole book
- A named set of managed endpoints
- Two or three ticket categories you choose
- An explicit list of actions Firstline may take on them
- Technician approval on every change
- A fixed evaluation period, reviewed together at the end
Scope grows when the record earns it.
Reporting a vulnerability
If you find a security problem in our product or this website, email noah@firstline.so. We acknowledge reports within two business days and will keep you updated until it is resolved. We will not pursue legal action over good-faith research that respects user privacy and does not degrade the service.
Reviewing Firstline for your clients?
Send your security questionnaire, or your client’s, to noah@firstline.so, or book a call and we will take your team through the architecture, the action list and the audit trail.
