Technology partners
The platforms we operate
We work with solutions from Microsoft, Google, Cisco, Fortinet, Check Point and IBM. The corresponding partner relationships are held by our parent organisation in Bulgaria. We are not exclusively tied to any one vendor and we advise first on the basis of your existing environment and requirements.
The platforms we implement and operate
What a partnership changes
What a partnership gives you
A partner relationship provides four specific things, in the order they tend to matter.
Certified engineers
For the platforms concerned we can assign engineers who have completed the relevant vendor training and exams. We state in advance who works on your environment and which relevant knowledge or certifications are held.
An additional escalation route
Where a problem sits in the product itself, we can escalate it through the vendor's partner channels. We remain responsible for the coordination, so you do not have to mediate between suppliers yourself.
Technical information and support
Partner channels can give access to technical documentation, security information, updates and support. Which information is available, and when, differs per vendor and partner programme.
Licence supply
We can supply licences through the partner relationship and review usage periodically, so the numbers and types stay closer to the actual environment.
We do not publish current partner tiers on this page. On request we provide the official status and the legal entity that holds it, which is a better answer than a badge.
Whose partnerships these are
Whose name the partnerships are in
The vendor relationships, the certified engineers and the certified management systems are held by Think Smart EOOD in Bulgaria. That organisation has been registered since December 2019.
Think Smart Europe B.V. is the Dutch contracting party. The technical delivery is done by the teams in Sofia, Varna and Stara Zagora, and what you buy is delivered under the certified management systems of the parent organisation.
We do not claim partner status or certification in the name of Think Smart Europe B.V. where it formally belongs to the Bulgarian organisation. For tenders and supplier assessments we supply the current documents and name the correct legal entity.
Sofia, Varna and Stara Zagora are inside the European Union. The same data-protection regime applies, the same management systems, and the same certification bodies your procurement team already recognises. That is a claim you can verify in a register instead of taking it from us.
Independence
How we choose a platform
We are not exclusively tied to any of the vendors named here. These are our working rules.
- Every recommendation names the alternative. Where we recommend a platform, we also state which alternatives were examined, what they would have cost and why they fit less well.
- The partnership is declared in the document. An existing commercial relationship with the recommended vendor is stated in the recommendation itself rather than coming up in the meeting afterwards.
- We will run a platform we did not choose. We can operate a platform that another party selected or implemented. Replacement is not a condition of our service.
- We will say when replacing it is the cheaper answer. Replacement is sometimes cheaper or easier to manage than keeping an existing solution in place. Where that is the case we support it with the expected implementation and operating costs.
Our SOC is integrated more extensively with some platforms than with others. A platform we already run in other estates onboards faster. A less familiar solution can take more time to onboard and to build good detection rules and reporting for.
We discuss that difference before you make a choice, and not in an invoice three months later. We will still run the platform you want. It simply takes longer to reach the same quality of reporting.
Platform by platform
Our role per platform
Which work is relevant depends on the platforms you use. Where a platform is not part of your estate the row does not apply to you, and a shorter list is usually a cheaper one to run.
| Vendor | What we do with it | What a client gets |
|---|---|---|
| Microsoft | Identity, endpoint and cloud. Entra ID and conditional access, Intune device management, Defender for Endpoint, and Microsoft 365 mail security. | One identity and device estate with policies that are written down, and a Defender signal that reaches our SOC rather than a console nobody opens. |
| Workspace and Google Cloud. Tenant administration, a hardened security baseline, ChromeOS and Chrome Enterprise management. | A Workspace tenant configured to a documented baseline rather than left at its defaults, with the admin audit log actually monitored. | |
| Cisco | Network and secure access. Switching, routing, wireless, remote access and network segmentation. | A network with one owner, a change process, and logs that arrive somewhere they are read. |
| Fortinet | Perimeter and connectivity. FortiGate firewalls, segmentation between sites, and SD-WAN across locations. | A firewall rulebase that is reviewed on a schedule rather than accumulated, and traffic logging that reaches the SIEM. |
| Check Point | Threat prevention at the perimeter and on email, with centralised policy management across sites. | One policy set across locations, changes recorded as they are made, and mail threats stopped before an inbox sees them. |
| IBM | Enterprise security software and infrastructure, including SIEM platforms in estates that already run them. | Continuity for a platform that is already embedded, without a migration you did not ask for. |
Where solutions overlap, we set out in advance which choice we think fits best and why, in writing, before anything is bought.
What implementation partner means here
Implementation and management in one hand
After implementation, a platform has to be updated, tuned and checked. Temporary exceptions, licensing changes and new users or systems need continuing attention.
An implementation project usually ends at go-live. The platform is installed, the policies are set to a sensible default, the documentation is handed over and the team leaves. Six months on, the rulebase has grown, the exceptions are undocumented and nobody has looked at the alerts.
We can therefore provide both the design and the implementation and the operation that follows it. That operation can consist of policy changes, updates, tuning, escalations to the vendor and periodic reporting.
You can also take the implementation alone. In that case we hand the configuration, the documentation and the open operational points over to your own team or supplier.
Supply-chain security
For your supplier assessment
Article 21(2)(d) makes an organisation in scope responsible for the security of its direct suppliers. When you take our services, we become part of your supplier chain. We therefore keep information available on our own security and service delivery.
The following documents and details can be requested, among others.
- The management systems. ISO certificates with the scope statement, the certification body and the certified legal entity, so your procurement team can verify them in the register rather than believe a line on a website.
- The processing. The data processing agreement, the relevant sub-processors and the processing locations. All of them are inside the European Union.
- The access. The processes for requesting, granting, reviewing and withdrawing administrative access.
- The incidents. Our incident response plan, the contacts, the escalation route and the arrangements on reporting.
- The continuity. The arrangements on backup, recovery, availability and termination.
- The end of the service. Handover, export, retention periods and confirmation of deletion.
For questions that concern your own environment specifically, we state which evidence your organisation or another supplier has to provide. Assessing us should take an afternoon, and it should be an afternoon spent reading rather than chasing.
Discuss your technical environment
We map which platforms you use, who operates them and which parts are insufficiently maintained or monitored. We then say what you can keep, what can be consolidated and where additional management is needed.
