Canopytech Resources
Menu

Free · 26 checks · no upload, no sign-up

What your managed IT quote doesn't say

Two proposals at the same monthly price can be completely different agreements. Work through 26 checks against the document in front of you and get a clarity score, a section-by-section breakdown, and the exact questions to put to the provider — while you still have the leverage to ask them.

There's nothing to upload. We never ask for the document, your company, your email address or the provider's name. You read the quote, you answer the checks, and the scoring runs on your own device.

0 of 26 checked

Scope & support

7 checks · 21 of 80 points

Check 1 of 26: Does it say whether help desk support is genuinely unlimited, or capped by hours, tickets or users?
4 pts
Check 2 of 26: Does it define what "24/7" means — an engineer who can fix things, or a service that takes a message?
4 pts
Check 3 of 26: Are response and resolution targets stated by priority level, with something attached if they're missed?
3 pts
Check 4 of 26: Are on-site visits included, and does it say how many and how quickly somebody turns up?
3 pts
Check 5 of 26: Is it explicit about what is being priced — every user, endpoint, server, site and network device — and what is excluded?
3 pts
Check 6 of 26: Does it say whether dealing with your other vendors — internet, phone system, line-of-business software — is included?
2 pts
Check 7 of 26: Does it say who actually performs the work — in-house staff, subcontractors, or an offshore service desk?
2 pts

Security inclusions

7 checks · 22 of 80 points

Check 8 of 26: Does it name multi-factor authentication as included — deployed and enforced, not merely available?
4 pts
Check 9 of 26: Does it name the endpoint security product, and say whether the licence sits inside the monthly fee?
4 pts
Check 10 of 26: Does it commit to patching on a stated schedule, and say whether third-party applications are included?
3 pts
Check 11 of 26: Does it include email authentication — SPF, DKIM and DMARC configured and moved to an enforcing policy?
3 pts
Check 12 of 26: Does it say who watches security alerts outside business hours, and what they're allowed to do about one?
3 pts
Check 13 of 26: Does it say whether responding to a security incident is covered, or billed separately as project work?
3 pts
Check 14 of 26: Is security awareness training or phishing simulation named as included, or is it an add-on?
2 pts

Backup, recovery & data

4 checks · 14 of 80 points

Check 15 of 26: Does it state exactly what's backed up — servers, endpoints, and the data in Microsoft 365 or Google Workspace?
4 pts
Check 16 of 26: Does it commit to test restores — how often they run, and whether you're shown the result?
4 pts
Check 17 of 26: Does it put numbers on recovery — how much data you could lose, and how long you'd be down?
3 pts
Check 18 of 26: Does it say where your data and backups are physically stored, and in which country?
3 pts

Ownership & exit

4 checks · 13 of 80 points

Check 19 of 26: Does it say who owns your Microsoft 365 or Google Workspace tenant and your domain, and who holds the top-level administrator credentials — you or the provider?
4 pts
Check 20 of 26: Does it say you receive the documentation — network diagram, asset inventory, licence records — and how administrative access is handed back, if you leave?
3 pts
Check 21 of 26: Does it say who holds your backup data, and how you get it back if the relationship ends?
3 pts
Check 22 of 26: Does it set out the term, the notice period, whether it auto-renews, and any early-termination charge?
3 pts

Commercial terms & risk

4 checks · 10 of 80 points

Check 23 of 26: Is the line drawn between covered work and project work — migrations, new sites, hardware, licences?
3 pts
Check 24 of 26: Does it state the provider's insurance and the limit of their liability if something goes wrong?
3 pts
Check 25 of 26: Does it say how and when the monthly price can change?
2 pts
Check 26 of 26: Does it state the onboarding fee, how long onboarding takes, and what it covers?
2 pts

Work through all 26 checks to score the quote

26 still to go.

How the score works

Each check carries a weight based on how much money or leverage rides on it being left vague. Answeringin writing costs nothing, mentioned but not pinned down costs half the weight rounded up, and not there costs the lot. What's left is expressed out of 80 and shown as a clarity score out of 100 — so unlike most scores on the internet, higher is better.

A loose clause still scores something on purpose. If the document says backups are tested but not how often, you at least have a sentence to point at. Silence gives you nothing to point at.

Scope & support

7 checks · 21 of 80 points

Security inclusions

7 checks · 22 of 80 points

Backup, recovery & data

4 checks · 14 of 80 points

Ownership & exit

4 checks · 13 of 80 points

Commercial terms & risk

4 checks · 10 of 80 points

The heaviest checks, and why

These 7 carry the most weight because each one on its own decides a large recurring cost, whether you can leave at all, or how bad an incident gets:

  • Does it say whether help desk support is genuinely unlimited, or capped by hours, tickets or users?
  • Does it define what "24/7" means — an engineer who can fix things, or a service that takes a message?
  • Does it name multi-factor authentication as included — deployed and enforced, not merely available?
  • Does it name the endpoint security product, and say whether the licence sits inside the monthly fee?
  • Does it state exactly what's backed up — servers, endpoints, and the data in Microsoft 365 or Google Workspace?
  • Does it commit to test restores — how often they run, and whether you're shown the result?
  • Does it say who owns your Microsoft 365 or Google Workspace tenant and your domain, and who holds the top-level administrator credentials — you or the provider?

Unusually thorough

88–100

Solid, a few gaps

68–87

Typical — real gaps

42–67

Too vague to compare

18–41

Not ready to sign

0–17

What this is

A buyer's checklist. It gives you a way to compare two proposals on what they actually commit to rather than on the monthly figure, and a set of questions that are answerable in a sentence. Run both quotes through it and compare the scores, not the prices.

What this is not

It scores a document, not a company, and it isn't legal advice. A thin proposal doesn't make a provider incapable, and a thorough one isn't proof they're good. For a significant multi-year agreement, have a lawyer read it as well.

Quote Checker FAQs

What does the quote checker actually do?

It walks you through 26 things that should be written into a managed IT proposal — help desk caps, what "24/7" really means, response targets, MFA and endpoint protection, patching, email authentication, out-of-hours monitoring, incident response, backup scope and restore testing, recovery objectives, where your data lives, who owns your cloud tenant and domain, what you get back if you leave, term and auto-renewal, project boundaries, liability, price changes and onboarding. For each one you mark whether it's in writing, vaguely mentioned, or absent. You get a clarity score out of 100, a breakdown by section, and a list of questions to send the provider.

Do I have to upload the quote?

No, and there is nothing to upload it to. The tool never asks for the document, your company name, your email address or the provider's name. You read the quote yourself, answer the checks, and the scoring runs on your own device. Your answers are never transmitted, stored or logged — not to us, not to anyone. To be precise about what we do count: like most sites we log page visits, using analytics we host ourselves, which records that this page was opened and sets a first-party cookie so you aren't counted twice. It never sees the quote, your answers or your score.

Does a low score mean the provider is bad?

No. It scores a document, not a company — plenty of capable providers write thin proposals, and a polished proposal is not proof of competence either. A low score means you can't yet compare this quote against another one, and that several things which will determine your real cost haven't been agreed in writing. That's fixable in one email.

Can I use it on a Canopytech quote?

Yes, and we'd rather you did. The checklist is deliberately written to apply to any managed IT provider, including us. If our proposal doesn't answer one of these, that's a fair question to put to us, and we'd sooner answer it before you sign than argue about it afterwards.

Why does "mentioned, but not pinned down" still score points?

Because a loose clause is still an argument you can have. If the document says backups are tested but doesn't say how often, you at least have something to point at. Silence gives you nothing to point at, so it scores nothing.

Is this a legal review?

No. It's a buyer's checklist, not legal advice, and it doesn't assess whether the terms are enforceable or fair under your contract law. For a significant multi-year agreement, have a lawyer read it as well — this tool is for working out which questions are worth their time.

Want a third proposal to compare against?

We'll put one together that answers every check on this page, whether or not you end up choosing us — at least you'll know what a complete quote looks like.

Request a Quote