Overview
This Acceptable Use Policy ("AUP") governs the use of Lexcom Systems Group's managed IT services, network infrastructure, software platforms, and related technology resources provided to clients. It supplements your Master Services Agreement or Statement of Work and is incorporated into those agreements by reference.
The purpose of this policy is to protect the security, reliability, and integrity of Lexcom's services and the organizations that rely on them.
Scope
This policy applies to:
- All client employees, contractors, and third-party agents who access or use Lexcom-managed services or infrastructure
- All systems, networks, applications, and data managed by Lexcom on a client's behalf
- All communication channels provided or monitored by Lexcom
Clients are responsible for ensuring that all authorized users within their organization are aware of and comply with this policy.
Permitted Use
Lexcom-managed services and infrastructure may be used for:
- Legitimate business operations and activities consistent with your organization's purpose
- Authorized communication, collaboration, and productivity tools
- Accessing cloud services and applications within approved vendor agreements
- Remote work and access to organizational resources by authorized personnel
- Business continuity activities and authorized disaster recovery testing
Prohibited Activities
The following activities are strictly prohibited on Lexcom-managed systems and networks:
Security violations
- Unauthorized access to systems, accounts, or data — including those of other organizations
- Circumventing security controls, authentication mechanisms, or access policies
- Introducing malware, ransomware, or any malicious code
- Conducting port scans, vulnerability assessments, or penetration tests without prior written authorization from Lexcom
- Intercepting network traffic or attempting to capture credentials
Harmful or illegal content
- Storing, transmitting, or distributing illegal content of any kind
- Harassment, hate speech, or content that threatens or intimidates individuals
- Copyright infringement, including unauthorized distribution of software or media
- Fraudulent communications including phishing simulations without written Lexcom authorization
Network and resource abuse
- Activities that degrade network performance for other clients or systems
- Operating cryptocurrency mining software on managed infrastructure
- Running unauthorized servers, proxies, or relay services
- Mass email distribution or spam operations
- Using Lexcom resources for commercial activities not related to your contracted business
Data misuse
- Exfiltrating or copying data to unauthorized external locations without approval
- Sharing confidential client or organizational data with unauthorized parties
- Violating applicable data protection laws, including PIPEDA, PIPA, HIPAA, or GDPR where applicable
Security Obligations
All users of Lexcom-managed services are required to:
- Use strong, unique passwords and enable multi-factor authentication where required by policy
- Report suspected security incidents, phishing attempts, or policy violations to Lexcom immediately
- Lock workstations when unattended and secure mobile devices with a PIN or biometric
- Use only Lexcom-approved methods for remote access — do not use unauthorized VPNs or remote desktop tools
- Store organizational data only in Lexcom-approved and managed locations
- Complete required security awareness training as scheduled
Monitoring
As part of providing managed IT services, Lexcom monitors network traffic, system events, and security alerts on client-managed infrastructure. This monitoring is performed to:
- Detect and respond to security incidents and anomalous activity
- Maintain service availability and performance
- Ensure compliance with this AUP and applicable security policies
- Fulfill obligations under client compliance frameworks (HIPAA, PCI DSS, etc.)
Monitoring is conducted in accordance with applicable law and client agreements. Users of Lexcom-managed systems should have no expectation of privacy in connection with activities conducted on those systems.
Reporting Violations
If you observe or suspect a violation of this policy, report it immediately through your organization's designated IT contact or directly to Lexcom:
- Security incidents: Contact your Lexcom account manager or call 877‑539‑2663 (24×7 for managed IT clients)
- Policy questions or non-urgent reports: security@lexcom.com
Reports made in good faith will be treated confidentially. Lexcom does not tolerate retaliation against individuals who report suspected violations.
Enforcement
Violations of this policy may result in:
- Immediate suspension of access to Lexcom-managed services
- Notification to the client organization's management or legal team
- Remediation costs charged to the client organization
- Termination of the service agreement in cases of material breach
- Reporting to law enforcement where activities are illegal
The appropriate response will depend on the nature and severity of the violation. Lexcom reserves the right to take any action necessary to protect the security and integrity of its services and other clients.
Policy Updates
Lexcom may update this Acceptable Use Policy at any time to reflect changes in services, legal requirements, or security best practices. Updated versions will be published at lexcom.com and lexcom.ca. Continued use of Lexcom services after a policy update constitutes acceptance of the revised terms.
Contact
Questions about this policy should be directed to your Lexcom account manager or: