We hold ourselves to the standard we sell.
We provide cybersecurity consulting and managed security services. Our internal security program is designed for the services, information, and systems we operate. This page is deliberately transparent about how we run our own security — without disclosing exploitable implementation details.
Last updated August 14, 2026
Insured
StateDrive LLC carries errors & omissions (professional liability) and cyber liability coverage appropriate to cybersecurity consulting and managed security work. Certificates of insurance are available to clients and contracting officers on request.
SAM.gov registered
We hold an active SAM.gov registration for federal contracting. Our UEI and CAGE details are provided to contracting officers and primes during procurement or on request at [email protected].
SBA eligible
StateDrive qualifies as a small business under applicable SBA size standards for our NAICS codes, making us eligible for small-business set-asides and teaming arrangements. Applicable designations are stated exactly as held — never rounded up.
Our internal security program is aligned to NIST Cybersecurity Framework 2.0, using a risk-based approach across all six functions:
Risk strategy, roles, policy, and oversight are defined and reviewed
Assets, data flows, and risks are inventoried and prioritized
Identity, encryption, hardening, and least privilege by default
Centralized logging, monitoring, and alerting on our own systems
A written, practiced incident-response process with defined roles
Tested backups and restoration procedures with defined targets
CMMC: our internal practices are mapped to CMMC practice requirements (NIST SP 800-171 control families), and we build CMMC-aligned programs for clients in the defense supply chain. We state our own assessment status exactly as it stands and never claim a certification level that has not been formally assessed — current status is available to contracting officers on request.
ISO/IEC 27001: our control set is aligned to ISO/IEC 27001:2022 control objectives. Alignment is not certification, and we say so plainly — if your procurement requires certified vendors, ask us and we will give you a straight answer.
CISA: we adopt CISA guidance operationally — Known Exploited Vulnerabilities (KEV) remediation discipline, Cross-Sector Cybersecurity Performance Goals, and Secure-by-Design principles in everything we build.
The following are individual qualifications held by our founder/principal consultant — stated as personal credentials, not organizational certifications:
Verification available on request · engagement staffing is disclosed before work begins
We run our own infrastructure on the same zero-trust architecture we build for clients. High-level by design — enough to show the shape, nothing an attacker can use:
Zero inbound attack surface
Public services are published through outbound-only encrypted tunnels. Origin systems expose no inbound service ports and are not directly addressable from the internet.
Identity-aware access, not VPNs
Administrative surfaces sit behind an identity-aware access layer: every request is authenticated against SSO with MFA and evaluated per-request against policy — device and session included. There is no flat network to land on.
Edge filtering in front of everything
A web application firewall with managed and custom rules, volumetric DDoS mitigation, rate limiting, and bot mitigation screen traffic before it ever reaches an application.
Modern transport security
TLS 1.3 with HSTS on all public properties; internal hops are encrypted end to end. Security headers (CSP, frame denial, referrer policy) ship on every response.
Default-deny at the host
Host firewalls deny all inbound traffic except hardened, key-only administrative access with automatic brute-force lockout. Services run isolated, as least-privileged containers.
Email authentication
SPF, DKIM, and DMARC are configured on our sending domains to resist spoofing of our identity.
Phishing-resistant MFA
Multi-factor authentication is enforced on every account that touches company or client systems, with hardware-backed factors for administrative access.
Encryption in transit and at rest
TLS 1.3 for data in motion; disk- and volume-level encryption for data at rest on systems we control.
Managed, hardened endpoints
Company endpoints run managed EDR with enforced disk encryption, screen locks, and automatic patching.
Least privilege
Access is role-scoped and time-bound. Administrative rights are separated from daily-driver accounts and reviewed on a schedule.
Security logging & monitoring
Authentication, administrative, and edge events are centrally logged and monitored, with alerting on anomalous activity.
Vulnerability remediation
We track advisories and prioritize remediation using CISA KEV and exploitability data — the same discipline we sell.
Tested backups
Backups are encrypted, versioned, and restore-tested — a backup that has never been restored is a hypothesis, not a control.
Incident response
A written IR process with defined roles, severity levels, and communication paths — exercised, not just documented.
What we collect and why
Contact submissions (name, email, company, message) are collected solely to respond to your inquiry. Engagement data is collected only as scoped in the contract, under NDA, and to the minimum necessary.
Access restrictions
Client data is accessible only to the principals working your engagement — no offshore processing, no resale, no training of AI models on client data.
Encryption
Client data is encrypted in transit and at rest on infrastructure we control.
Retention & deletion
Inquiry data is retained while relevant and deleted on request. Engagement artifacts are returned or destroyed at close-out per contract terms.
Your rights
Request access to or deletion of your data any time at [email protected]. We respond within three business days.
Found a security issue in anything we operate? We want to hear it — from anyone, without lawyers involved.
- Report to: [email protected] — also published in /.well-known/security.txt. PGP key available on request.
- Scope: statedrive.net and subdomains, and services we publicly operate. Client environments are out of scope — always.
- Safe harbor: we will not pursue legal action for good-faith, in-scope research that avoids privacy violations, data destruction, service degradation, and social engineering. Stop and report the moment you can demonstrate an issue.
- Acknowledgment: within three business days, with a straight answer on validity and remediation intent.
Legal documents
- Privacy policy
- Terms of service
- Cookie disclosure
- DPA & security addendum — available on request
Subprocessor categories
- Edge network & zero-trust access provider — DDoS mitigation, WAF, DNS, and identity-aware access in front of our public and administrative surfaces.
- Cloud infrastructure provider — Hosting for our public website and internal tooling.
- Transactional email provider — Delivery of contact-form notifications to our team.
As a consulting practice we describe categories rather than publish a full architecture. Named lists are provided to clients under NDA.
Service assurances
- First response — within one business day, usually much faster.
- Incident notification — affected clients are notified without undue delay, and no later than 72 hours after we confirm an incident involving their data.
- Escalation — [email protected] reaches a principal, not a queue.
Questions about our posture?
Contracting officers, procurement teams, and security reviewers: we answer diligence questionnaires with straight answers and evidence.
[email protected] · response within one business day