Kovyr.
If you handle client tax or financial records, you're required to have a written security plan.
We write it — and we run the IT work that makes it true. One local technician, from Richfield to Spanish Fork.
Not regulated? The IT half stands on its own, and monitoring starts at $99/mo.
Not sure where you stand? Start here.
Enter your website and get a free security grade in seconds — the same things an attacker or your cyber-insurance auditor can see.
Free, instant, and passive — we only read public information, the same as an attacker or insurance auditor would.
More than monitoring
Your whole IT department, one local company.
From Spanish Fork to Richfield, we keep small-business computers, networks, and email running — and secure — so you can get back to work.
Ongoing
Managed IT
Monitoring, updates, backups, helpdesk, and security for a flat monthly price — plans sized for offices of 3 to 25 people, from $299/mo.
Plans & pricing →
When something breaks
IT Support & Repair
Hourly help for offices, clinics, firms, and job sites — remote support $95/hr, on-site $125/hr. Most problems fixed the same day, remotely. Businesses only.
Rates & what we fix →
Not ready to commit to anything monthly? Start with a one-time Internal Assessment — from $999. Half a day on site, and a written list of what we’d fix, what it costs, and what can wait. Yours to keep either way.
See what’s includedSomething down right now? Call 435-201-2646
What's behind your grade
The grade isn't the point. What it protects is.
The scan looks at the same things an attacker, a cyber-insurer, or an auditor would check first. Here's what's behind the letter — in plain English.
Can someone impersonate your email?
Whether a scammer can send email that looks exactly like it came from your business — how fake-invoice and wire-fraud scams start. It burns your customers' trust, not just yours.
Is your data protected as it travels?
Whether the connection to your website and customer portals is properly secured and up to date. If it's not, information can be intercepted — and it's the first red flag an insurer or a sharp customer notices.
Is your website's front door configured right?
Whether the security headers browsers rely on are actually set — the settings that stop your page being framed, a session being hijacked, or a file being read as something it isn't. Missing ones are the first thing an insurer's questionnaire asks about.
A grade is a snapshot. We turn it into an ongoing set of eyes.
You get monitoring that never sleeps and a local expert you can actually call — without hiring one.
The day-to-day
What actually changes, once we're on.
Security is the part you don't see. This is the part you do.
The morning something breaks
You call one number and a person picks up who already knows your network. No queue, no explaining your setup from scratch.
Someone starts Monday
Email, laptop, and file access ready before their first morning — not on their third day.
Someone leaves
Their access is actually removed that day. That's the one every office forgets.
The printer, the scanner, the machine that talks to your practice software
We deal with the vendor so nobody on your staff sits on hold.
Nobody has to be the office IT person
The one who's “good with computers” gets their afternoons back.
You stop wondering whether anything is happening
A plain-English note each month: what we did, what changed, what needs a decision from you. No dashboard to log into.
One less thing to be unsure about
Answer the question honestly, then stop thinking about it.
If you prepare taxes, you attest at PTIN renewal that you keep a Written Information Security Program. If you're a dental or medical practice, HIPAA requires a documented Security Risk Analysis. Most small firms check that box and hope it never comes up. We write the document, keep it current as your office changes, and monitor what it claims — so the honest answer and the easy answer are the same one. And where there are gaps, it says so. That's the only version worth having if anyone ever asks.
Find your requirement
Dental & medical
HIPAA Security Risk Analysis
HIPAA requires a documented risk analysis — the item OCR asks for first. For the risk analysis we're your outside provider, not a Business Associate: your practice names its own Security Official, and in that engagement we don't create, receive, maintain, or transmit your ePHI. Managed IT is a different arrangement — see the packet page.
The HIPAA packet →
Tax & financial
FTC Safeguards WISP
The FTC Safeguards Rule requires a Written Information Security Program — and your PTIN renewal now asks whether you have one. We write it, and keep it current.
The WISP packet →
Insurance agencies
Written Information Security Program
Utah insurance rule R590-216 requires licensed agents to maintain a written security program. Independent agents especially are on their own — not covered by a carrier's corporate program. We write it, and keep it current.
The insurance WISP →
Not regulated? Trucking, retail, auto, agriculture — you still have real risk. Monitoring from $99/mo, or start online now.
Who you're working with
Kendall Sorenson
Founder, Kovyr Technology · IT technician · Richfield, Utah
Real, hands-on experience with network security, DNS and email infrastructure, and PCI remediation for local businesses. When you call Kovyr, you reach a competent human who knows your setup — not a faceless tool or an overseas ticket queue.
Get the documentation you're required to have.
Start with a free scan, or book your Compliance Assessment — quoted per business, from $897.