Skip to content
Trust

Security Program

Summary controls for enterprise and federal diligence. Operational detail beyond this page is shared under NDA to active prospects and customers.

Last updated:

Since 2018

Privacy-safe enterprise data

VOSB & SDVOSB

U.S. Veteran-Owned, Service-Disabled

SCC Transfers

EU/UK/CH per privacy policy

GDPR · CCPA · CPRA

Consent-first data sourcing

Certification posture

FrameworkStatusNotes
Standard Contractual Clauses (EU/UK/CH)In useInternational transfers per privacy policy
IAB TCF v2.4AlignedConsent envelope inherits from CMP partners
SOC 2 Type IIIn progressTarget completion Q3 2026
ISO 27001PlannedAfter SOC 2 remediation window
NIST 800-53 alignmentAlignedMapped for federal-style deployments
ODNI CAI Policy FrameworkAlignedSensitive-category exclusions

Technical safeguards

In transit

  • TLS 1.2+ with HSTS on production origins
  • Strict Content Security Policy aligned to documented third-party allowances

At rest

  • AES-256-equivalent encryption for cloud-managed storage tiers
  • Encrypted backups via cloud-native services

Access

  • MFA for GSDSI personnel
  • RBAC on production systems
  • SSO internally; entitled customer tenants can require SAML/OIDC
  • Quarterly entitlement reviews

Breach-notification SLA

  • Tier 1 (confirmed unauthorized access to identified customer datasets): notify contract administrators within 72 hours of confirmation where GDPR-class timelines apply.
  • Tier 2 (suspected incidents): preliminary notice within 5 business days with confirm-or-clear update inside 14 days.
  • Tier 3 (systems incident without buyer-data impact): internal runbooks + quarterly rollup to enterprise distribution lists where contracted.

Researcher disclosure

See SECURITY.md and security.txt for coordinated disclosure routing. Operational questions: compliance@gsdsi.com.

Contacts

✓ Opt-Out Request Honored via Global Privacy Control