Last updated: February 2026
We collect information you provide when creating an account (name, email, organization), compliance assessment data (NIST SP 800-171 control statuses, evidence files, implementation notes), and company details (CAGE code, DUNS number, contract numbers).
We also collect anonymized usage analytics with autocapture disabled. We do not capture page URLs, form inputs, or CUI-related content.
Your data is used solely to provide the CMMC compliance assessment service: generating compliance scores, gap analysis reports, System Security Plans, and team collaboration features. We do not sell, share, or monetize your compliance data.
All data is stored in an encrypted real-time database with encryption at rest and in transit. Authentication is handled by a SOC 2 Type II compliant identity provider. Evidence files use time-limited signed URLs. No permanent file URLs are persisted.
We use trusted, industry-standard third-party services for the following purposes:
Your data is retained as long as your account is active. You may request full data deletion at any time by contacting support. Upon deletion, all compliance data, evidence files, and account information are permanently removed within 30 days.
For privacy inquiries, contact privacy@cmmccommand.org.