Information Security Standards for IT, Security, and Contracts Officers
Security, Infrastructure & Data Protection
Blue Ridge Federal operates under strict data protection protocols designed for government contractors and enterprise supply chains. This document outlines our cloud infrastructure controls. For highly restricted data environments, enterprise deployments can be operated locally behind your organization’s firewall under separately negotiated controls.
Security Protocol Summary
| Control Area | Implementation Standard |
|---|---|
| Model Training | Client data is strictly prohibited from being used for AI model training. |
| Encryption | AES-256-GCM at rest using tenant-isolated keys; enforced HTTPS (TLS) in transit. |
| Access Control | Zero standing access. Support access requires explicit, time-bound authorization by the client. |
| Data Retention | Automated deletion 30 days post-completion. Watched BOMs require an explicit, logged retention extension and are deleted 30 days after the subscription ends. |
| Data Traceability | Source-backed traceability: output values cite origin records; document-derived rows retain source page and line references. |
| External Lookups | Authorized U.S. distributors by default; other catalogs require owner opt-in. Lookups transmit part numbers and supplier codes only, never source files. |
| Compliance | CMMC Level 2 self-assessment registered in SPRS. SAM.gov registered (CAGE: 19PB1). |
| Incident Response | Documented response plan with mandatory notification within 72 hours of confirming that a client’s data was affected. |
Core Capabilities & Data Provenance
Blue Ridge Federal provides source-backed automated compliance cross-referencing for Bill of Materials (BOM) and enterprise item masters.
- Assessment Modules: Automated screening of uncrewed systems (Drone NDAA) and counter-drone technologies (C-UAS) against §889, §1260H, and export-control regulations, subject to the approved ruleset and agreed review scope. We also provide Blue UAS listing documentation support and SKU mapping for ERP integrations (SAP MDG, Maximo, NetSuite).
- Data Intake & Parsing: The system accepts structured datasets (CSV, JSON) and unstructured source documentation (PDF quotes, invoices, scanned packing lists). Extracted data strictly preserves its source page and line.
- Cryptographic Traceability: Country of origin and compliance status are never assumed. Every verified value maintains a SHA-256 fingerprint linking it to the exact supplier record and timestamp. Conflicting evidence between sources is explicitly flagged for mandatory human adjudication.
Infrastructure, Storage & Encryption
All system architecture is designed to prevent unauthorized data access and ensure strict tenant isolation.
- Encryption Standards: Data in transit is secured via strict HTTPS (HSTS). At rest, all artifacts are encrypted using AES-256-GCM. Each organization has a dedicated data key stored only in wrapped form. The key that unwraps it is held in the hosting platform’s secret store, never in the database.
- Tenant Isolation: Cryptographic binding ensures file fragments are inextricably linked to your specific organization. Data cannot be accessed, moved, or requested by cross-account entities.
- Infrastructure Partners: Hosting and encrypted file storage are managed via Cloudflare. Authentication is governed by WorkOS AuthKit. Self-service billing details are processed securely via Stripe.
- Retention Lifecycle: Standard processing artifacts are permanently purged 30 days after job completion. Watching a BOM requires the owner’s explicit acceptance of a retention extension, logged with the policy version and document. Watched BOMs are retained while the subscription is active and deleted 30 days after it ends. Separate purchased archive terms may apply. Job metadata (hashes, counts, timestamps) is retained for billing and audit trails. Cancelling a job before processing triggers immediate deletion of its source files.
Access Control, Compliance & Third-Party Integration
System administrators retain total oversight over who accesses data and which external services are authorized to process it.
- Zero Standing Access & Immutable Auditing: Blue Ridge Federal personnel possess zero standing access to client artifacts. Support interventions require an administrator to provision a temporary, revocable grant (24 hours to 7 days). All system actions—including processing, deletions, and administrative grants—are recorded in an append-only audit log that cannot be edited or deleted through the application.
- Opt-In Third-Party Processing: AI-assisted processing (via approved OpenAI or Anthropic APIs) is disabled by default and requires explicit administrator authorization. Supplier-evidence processing uses opaque row labels and excludes internal identifiers, organization names and job notes. Optional intake mapping sends column headers and up to 30 sample rows; optional document reading sends the document the user chooses to the approved API. U.S.-regional inference requires an approved, configured provider and is confirmed during the security review rather than assumed. OpenAI requests have response storage disabled; provider abuse-monitoring retention may still apply. Providers outside the approved list, including DeepSeek, are blocked by the processing service. Distributor lookups (Mouser, Digi-Key) transmit isolated part numbers and supplier codes only.
- CUI & Export-Controlled Data: The cloud service is designated exclusively for unclassified commercial data. Submissions must not contain CUI, ITAR-restricted, or classified materials. Regulated workflows require on-premise enterprise deployment under separately negotiated controls.
- CMMC & Institutional Readiness: Blue Ridge Federal’s CMMC Level 2 self-assessment is actively recorded in the DoD Supplier Performance Risk System (SPRS). This is a self-assessment, not C3PAO certification. Contracting officers may request scope and affirmation details during due diligence. In the event of a confirmed incident affecting client data, our Incident Response Plan mandates containment, assessment, and client notification within 72 hours of confirming that the client’s data was affected.
Reviewing us for your organization?
We will answer your questionnaire, confirm hosting details in writing and walk your security team through these controls on a call.
Page updated October 8, 2026.
