Home / Directory /
Cloud and managed IT
Cloud and managed IT: a buyer's guide
What we list in this category, how the field splits between long-established
products and newer ones, and the questions worth pressing on before you commit.
Every entry below was recorded from a page we opened, and each carries the source we
read. Where we could not establish something it is left blank rather than guessed. Read
how this site works if you want the detail.
Long-established products
Recorded as established: in production for many years, usually with a deep reference base and broad coverage. Those are real advantages, and so is the fact that a fifteen-year horizon is easier to argue for a supplier that has already lasted one.
- AbacusFlex — A tiered multi-cloud managed IT and cybersecurity subscription for regulated financial firms, sold to hedge funds, private credit, venture capital and asset managers. source
- Align IT Suite — A Microsoft public cloud based managed services suite for alternative investment firms and RIAs, with a companion Align Guardian cybersecurity and archiving offering; the vendor states over 35 years in business. source
- Coretelligent Managed IT and Cloud Services — Managed IT, private cloud and compliance services (branded Core360, CoreCloud, CoreArmor and CoreComply) for hedge funds, private equity, family offices and wealth managers, grown through eight MSP acquisitions since 2019. source
- ECI Managed Cloud Services — Managed cloud, network and cybersecurity operations for hedge funds, private equity and asset managers; the firm was previously branded Eze Castle Integration and states 30 years in business and 15 global offices. source
- LPAssure — A small specialist MSP whose flagship program pairs managed IT with a named virtual CISO, allocator due diligence questionnaire library and SEC and Form PF compliance artefacts for emerging SEC-registered managers. source
- Linedata Technology Services — Public cloud migration, 24/7 managed services and the Linedata Protect security offering, sold by an asset management software vendor that describes itself as a buy-side MSP for over 25 years. source
- Netrio Managed IT and Cybersecurity Services — Managed IT, security operations and cloud services for financial services and private equity; Netrio acquired the New York financial services MSP Agio in 2025 and agio.com now redirects to netrio.com. source
- Pico Market Services — Managed trading infrastructure, colocation, connectivity and market data across 55+ data centres, with Corvil Analytics for packet-level monitoring, used by hedge funds and asset managers. source
Newer products
Recorded as modern or emerging. Newer suppliers often offer capability and pricing the incumbents do not, and they carry risks the incumbents do not: fewer references at your size, less operating history, and concentration if they are small. Both belong in the same comparison, on the same fields.
- Atlas Technica Outsourced IT — Outsourced IT, cloud and cybersecurity built for hedge funds, private equity, family offices and boutique managers; the vendor reports 225+ clients and 4,500+ supported users across US, UK, Hong Kong and Singapore offices. source
- Drawbridge Cyber Risk Intelligence — A cyber risk scoring platform plus managed cybersecurity services sold only to hedge funds, private equity firms and their portfolio companies; the vendor reports serving 1,200+ funds. source
- ELLA — A controlled large language model application ECI launched in November 2023 so alternative investment firms can use AI inside their compliance and permission rules. source
- Proximity Cloud — Fully managed low-latency compute, colocation and connectivity for trading firms and asset managers, alongside Exchange Cloud for venues and Beeks Analytics; the group is a publicly listed plc. source
What to ask
These come from the same question bank our request-for-proposal process uses, so a guide
and an RFP never drift apart. The four sections below carry the most weight in that bank.
Functional fit
Whether the system does the job for YOUR instruments, markets and volumes — not for the demonstration portfolio. The questions separate what runs in production today from what is on the roadmap, because that distinction disappears in a sales meeting and reappears during implementation. It also asks what still has to be typed in by hand, which every system has and few volunteer.
- Which asset classes does the product support in production today?
- Is there a full audit trail of who changed what and when, and can it be exported?
- Does the system enforce segregation of duties between front and back office?
- Is maker-checker approval supported on material actions, and is it configurable by action type?
- Can a valuation be sourced and approved independently of the people who trade?
Security and resilience
Whether the vendor's security is independently attested or merely asserted. The questions ask for certifications you can read, penetration tests you can see the summary of, and recovery objectives that are written down. Incident history is asked directly, because a vendor that has handled a breach well is often a safer choice than one that has never been tested.
- Which independent attestations do you hold currently?
- Will you provide the most recent report under a non-disclosure agreement?
- Is data encrypted in transit and at rest?
- Is single sign-on supported, and is multi-factor authentication enforced?
- Can your own staff see our data, and is that access logged and reviewable by us?
Commercial terms
Total cost across the whole term, and what happens if you leave. Year one is asked separately from years two to five because year one hides where the money goes. The section asks explicitly what is NOT included, since the gap between the quote and the invoice lives there, and it asks about exit terms while you still have the leverage to negotiate them.
- How is the product priced?
- What is the total first-year cost for our stated requirement, including implementation?
- What is the total annual cost in years two through five?
- What is NOT included in that figure?
- Is there a contractual cap on annual price increases?
Artificial intelligence
If a model touches your data, on what terms. This section exists because the answers differ enormously between vendors and are rarely offered unprompted. It asks whether your data trains models serving other clients, whether you can opt out and keep full function, whether a human reviews output before it affects a book or a client report, and who is liable when a model is wrong. Skip it only if you genuinely do not care.
- Does the product use machine learning or generative AI anywhere in its normal operation?
- Is client data ever used to train models that serve other clients?
- Can we opt out of AI features entirely and keep full product function?
- Does our data leave your infrastructure to reach those providers?
- Is a human review step required before an AI output affects a book, a trade or a client report?
You can send all 150 of these questions to the vendors you choose,
and get every answer back side by side. Run an RFP — it is free to
you and free to them.
See all 17 products in Cloud and managed IT
· Glossary