Skip to main content
Back to Home

Privacy Policy

Last updated: February 2026

1. Information We Collect

We collect information you provide when creating an account (name, email, organization), compliance assessment data (NIST SP 800-171 control statuses, evidence files, implementation notes), and company details (CAGE code, DUNS number, contract numbers).

We also collect anonymized usage analytics with autocapture disabled. We do not capture page URLs, form inputs, or CUI-related content.

2. How We Use Your Data

Your data is used solely to provide the CMMC compliance assessment service: generating compliance scores, gap analysis reports, System Security Plans, and team collaboration features. We do not sell, share, or monetize your compliance data.

3. Data Storage & Security

All data is stored in an encrypted real-time database with encryption at rest and in transit. Authentication is handled by a SOC 2 Type II compliant identity provider. Evidence files use time-limited signed URLs. No permanent file URLs are persisted.

4. Third-Party Services

We use trusted, industry-standard third-party services for the following purposes:

  • Identity & Authentication: enterprise-grade user management with MFA support
  • Database & File Storage: encrypted real-time database with automatic backups
  • Payment Processing: PCI DSS compliant payment provider
  • AI Compliance Analysis: Professional plan only; only control metadata and company name are sent, never user documents or CUI
  • Error Monitoring: all user text masked, page URLs stripped
  • Product Analytics: anonymized, autocapture disabled
  • Email Delivery: transactional email service
  • Job Orchestration: scheduled tasks (deadline alerts, drift checks)
  • Rate Limiting: no user data stored

5. Data Retention & Deletion

Your data is retained as long as your account is active. You may request full data deletion at any time by contacting support. Upon deletion, all compliance data, evidence files, and account information are permanently removed within 30 days.

6. Contact

For privacy inquiries, contact privacy@cmmccommand.org.