Since 2018
Privacy-safe enterprise data
VOSB & SDVOSB
U.S. Veteran-Owned, Service-Disabled
SCC Transfers
EU/UK/CH per privacy policy
GDPR · CCPA · CPRA
Consent-first data sourcing
Certification posture
| Framework | Status | Notes |
|---|---|---|
| Standard Contractual Clauses (EU/UK/CH) | In use | International transfers per privacy policy |
| IAB TCF v2.4 | Aligned | Consent envelope inherits from CMP partners |
| SOC 2 Type II | In progress | Target completion Q3 2026 |
| ISO 27001 | Planned | After SOC 2 remediation window |
| NIST 800-53 alignment | Aligned | Mapped for federal-style deployments |
| ODNI CAI Policy Framework | Aligned | Sensitive-category exclusions |
Technical safeguards
In transit
- TLS 1.2+ with HSTS on production origins
- Strict Content Security Policy aligned to documented third-party allowances
At rest
- AES-256-equivalent encryption for cloud-managed storage tiers
- Encrypted backups via cloud-native services
Access
- MFA for GSDSI personnel
- RBAC on production systems
- SSO internally; entitled customer tenants can require SAML/OIDC
- Quarterly entitlement reviews
Breach-notification SLA
- Tier 1 (confirmed unauthorized access to identified customer datasets): notify contract administrators within 72 hours of confirmation where GDPR-class timelines apply.
- Tier 2 (suspected incidents): preliminary notice within 5 business days with confirm-or-clear update inside 14 days.
- Tier 3 (systems incident without buyer-data impact): internal runbooks + quarterly rollup to enterprise distribution lists where contracted.
Researcher disclosure
See SECURITY.md and security.txt for coordinated disclosure routing. Operational questions: compliance@gsdsi.com.
Contacts
- Privacy & Compliance: privacy@gsdsi.com
- Compliance escalation: compliance@gsdsi.com
