Real World Careers

One-pager for ISSO + privacy

Where the data lives, and what we do in a breach.

United States. Cloudflare. Encrypted in transit and at rest. FedRAMP not authorized. No SOC 2 report to attach. No completed NIST 800-171 / FISMA package. Breach notice: 72 hours to the named agency contact.

TopicAnswer
LocationCloudflare (US) Pages / Workers / D1 / R2
EncryptTLS in transit; at rest on Cloudflare managed storage
RetentionThe PDF is held 14 days for the office download, then deleted. Invoice, buyer email, and seat used/unused remain. Answers are not stored
DeleteA PDF still inside the 14 days is deleted on written request. We cannot delete the agency’s own copy
What we holdBuyer email, seat codes, and the PDF during those 14 days. No names. No SSN. No employee number. No medical. No clearance. No USAJOBS accounts
BreachNotify named contact within 72 hours of confirmed unauthorized access involving those IDs or scores. There is no personnel file here to leak
SubprocessorsCloudflare, Stripe (cards only), Mailgun (invites)
FedRAMP / SOC 2 / 800-171Not authorized / no SOC 2 letter / no 800-171 SPRS score to show. SSP-lite · vendor security assessment
508Criterion-level ACR (vendor self-assessment, 29 Aug 2026)
Selection / UGESPNot sold for ranking or cutoffs. Validation gap-assessment
PIA / SORNAgency determination. Vendor input: Privacy Act page

Also: faq-library · DPA · full packet