Security & Trust

We hold ourselves to the standard we sell.

We provide cybersecurity consulting and managed security services. Our internal security program is designed for the services, information, and systems we operate. This page is deliberately transparent about how we run our own security — without disclosing exploitable implementation details.

Insured · E&O + cyber liabilitySAM.gov registeredSBA small-business eligibleNIST CSF 2.0 alignedCMMC-aligned practicesISO/IEC 27001 alignedCISA guidance adopter

Last updated August 14, 2026

01 — Registrations, insurance & eligibility

Insured

StateDrive LLC carries errors & omissions (professional liability) and cyber liability coverage appropriate to cybersecurity consulting and managed security work. Certificates of insurance are available to clients and contracting officers on request.

SAM.gov registered

We hold an active SAM.gov registration for federal contracting. Our UEI and CAGE details are provided to contracting officers and primes during procurement or on request at [email protected].

SBA eligible

StateDrive qualifies as a small business under applicable SBA size standards for our NAICS codes, making us eligible for small-business set-asides and teaming arrangements. Applicable designations are stated exactly as held — never rounded up.

02 — Framework alignment

Our internal security program is aligned to NIST Cybersecurity Framework 2.0, using a risk-based approach across all six functions:

Govern

Risk strategy, roles, policy, and oversight are defined and reviewed

Identify

Assets, data flows, and risks are inventoried and prioritized

Protect

Identity, encryption, hardening, and least privilege by default

Detect

Centralized logging, monitoring, and alerting on our own systems

Respond

A written, practiced incident-response process with defined roles

Recover

Tested backups and restoration procedures with defined targets

CMMC: our internal practices are mapped to CMMC practice requirements (NIST SP 800-171 control families), and we build CMMC-aligned programs for clients in the defense supply chain. We state our own assessment status exactly as it stands and never claim a certification level that has not been formally assessed — current status is available to contracting officers on request.

ISO/IEC 27001: our control set is aligned to ISO/IEC 27001:2022 control objectives. Alignment is not certification, and we say so plainly — if your procurement requires certified vendors, ask us and we will give you a straight answer.

CISA: we adopt CISA guidance operationally — Known Exploited Vulnerabilities (KEV) remediation discipline, Cross-Sector Cybersecurity Performance Goals, and Secure-by-Design principles in everything we build.

03 — Practitioner credentials

The following are individual qualifications held by our founder/principal consultant — stated as personal credentials, not organizational certifications:

CISSPCISMSSCPCompTIA SecurityXCompTIA PenTest+CompTIA CySA+CompTIA Security+CompTIA Network+AWS Certified Cloud Practitioner

Verification available on request · engagement staffing is disclosed before work begins

04 — How we secure our own perimeter

We run our own infrastructure on the same zero-trust architecture we build for clients. High-level by design — enough to show the shape, nothing an attacker can use:

Zero inbound attack surface

Public services are published through outbound-only encrypted tunnels. Origin systems expose no inbound service ports and are not directly addressable from the internet.

Identity-aware access, not VPNs

Administrative surfaces sit behind an identity-aware access layer: every request is authenticated against SSO with MFA and evaluated per-request against policy — device and session included. There is no flat network to land on.

Edge filtering in front of everything

A web application firewall with managed and custom rules, volumetric DDoS mitigation, rate limiting, and bot mitigation screen traffic before it ever reaches an application.

Modern transport security

TLS 1.3 with HSTS on all public properties; internal hops are encrypted end to end. Security headers (CSP, frame denial, referrer policy) ship on every response.

Default-deny at the host

Host firewalls deny all inbound traffic except hardened, key-only administrative access with automatic brute-force lockout. Services run isolated, as least-privileged containers.

Email authentication

SPF, DKIM, and DMARC are configured on our sending domains to resist spoofing of our identity.

05 — Core internal protections

Phishing-resistant MFA

Multi-factor authentication is enforced on every account that touches company or client systems, with hardware-backed factors for administrative access.

Encryption in transit and at rest

TLS 1.3 for data in motion; disk- and volume-level encryption for data at rest on systems we control.

Managed, hardened endpoints

Company endpoints run managed EDR with enforced disk encryption, screen locks, and automatic patching.

Least privilege

Access is role-scoped and time-bound. Administrative rights are separated from daily-driver accounts and reviewed on a schedule.

Security logging & monitoring

Authentication, administrative, and edge events are centrally logged and monitored, with alerting on anomalous activity.

Vulnerability remediation

We track advisories and prioritize remediation using CISA KEV and exploitability data — the same discipline we sell.

Tested backups

Backups are encrypted, versioned, and restore-tested — a backup that has never been restored is a hypothesis, not a control.

Incident response

A written IR process with defined roles, severity levels, and communication paths — exercised, not just documented.

06 — Client data handling

What we collect and why

Contact submissions (name, email, company, message) are collected solely to respond to your inquiry. Engagement data is collected only as scoped in the contract, under NDA, and to the minimum necessary.

Access restrictions

Client data is accessible only to the principals working your engagement — no offshore processing, no resale, no training of AI models on client data.

Encryption

Client data is encrypted in transit and at rest on infrastructure we control.

Retention & deletion

Inquiry data is retained while relevant and deleted on request. Engagement artifacts are returned or destroyed at close-out per contract terms.

Your rights

Request access to or deletion of your data any time at [email protected]. We respond within three business days.

07 — Responsible disclosure

Found a security issue in anything we operate? We want to hear it — from anyone, without lawyers involved.

  • Report to: [email protected] — also published in /.well-known/security.txt. PGP key available on request.
  • Scope: statedrive.net and subdomains, and services we publicly operate. Client environments are out of scope — always.
  • Safe harbor: we will not pursue legal action for good-faith, in-scope research that avoids privacy violations, data destruction, service degradation, and social engineering. Stop and report the moment you can demonstrate an issue.
  • Acknowledgment: within three business days, with a straight answer on validity and remediation intent.
08 — Legal, subprocessors & assurances

Legal documents

Subprocessor categories

  • Edge network & zero-trust access provider — DDoS mitigation, WAF, DNS, and identity-aware access in front of our public and administrative surfaces.
  • Cloud infrastructure provider — Hosting for our public website and internal tooling.
  • Transactional email provider — Delivery of contact-form notifications to our team.

As a consulting practice we describe categories rather than publish a full architecture. Named lists are provided to clients under NDA.

Service assurances

  • First response — within one business day, usually much faster.
  • Incident notification — affected clients are notified without undue delay, and no later than 72 hours after we confirm an incident involving their data.
  • Escalation[email protected] reaches a principal, not a queue.

Questions about our posture?

Contracting officers, procurement teams, and security reviewers: we answer diligence questionnaires with straight answers and evidence.

[email protected] · response within one business day

Talk to us