One-pager for ISSO + privacy
Where the data lives, and what we do in a breach.
United States. Cloudflare. Encrypted in transit and at rest. FedRAMP not authorized. No SOC 2 report to attach. No completed NIST 800-171 / FISMA package. Breach notice: 72 hours to the named agency contact.
| Topic | Answer |
|---|---|
| Location | Cloudflare (US) Pages / Workers / D1 / R2 |
| Encrypt | TLS in transit; at rest on Cloudflare managed storage |
| Retention | The PDF is held 14 days for the office download, then deleted. Invoice, buyer email, and seat used/unused remain. Answers are not stored |
| Delete | A PDF still inside the 14 days is deleted on written request. We cannot delete the agency’s own copy |
| What we hold | Buyer email, seat codes, and the PDF during those 14 days. No names. No SSN. No employee number. No medical. No clearance. No USAJOBS accounts |
| Breach | Notify named contact within 72 hours of confirmed unauthorized access involving those IDs or scores. There is no personnel file here to leak |
| Subprocessors | Cloudflare, Stripe (cards only), Mailgun (invites) |
| FedRAMP / SOC 2 / 800-171 | Not authorized / no SOC 2 letter / no 800-171 SPRS score to show. SSP-lite · vendor security assessment |
| 508 | Criterion-level ACR (vendor self-assessment, 29 Aug 2026) |
| Selection / UGESP | Not sold for ranking or cutoffs. Validation gap-assessment |
| PIA / SORN | Agency determination. Vendor input: Privacy Act page |
Also: faq-library · DPA · full packet