Forward-thinking security
Security & compliance posture
Federal security-systems buying runs on trust twice over - trust in the equipment we put on your walls and in your network, and trust in the portal you order it through. Here is exactly how we approach both: supply-chain integrity, installed-systems assurance, identity and portal cyber posture, secure software, and accessibility - stated honestly, with claims we can substantiate.
Identity & access
CAC / PIV smart-card sign-in gate today, with production mutual-TLS to federal PKI on the roadmap.
Supply-chain & sourcing integrity
NDAA Section 889 screened and country of manufacture shown on every line, authorized-source procurement, no gray market.
Installed-systems assurance
Cameras, access control, and alarm systems configured to spec, installed to manufacturer standard, documented, and warranty-backed.
Portal cyber posture
TLS, HSTS, hardened headers, and a self-hosted, tracker-free ordering experience.
Installed-systems assurance
Our core trade is electronic security systems, not just IT resale - video surveillance, access control, intrusion/alarm, and the low-voltage cabling behind it. The assurance below applies to what actually goes on the wall and on your network, not just to this website.
Configured to your requirement. Camera counts, coverage, retention, access-control credentialing, and intrusion zones are engineered to the specific security requirement in your SOW/PWS or site survey - not deployed from a generic template.
On-premises option, no mandatory cloud. For IP video, our default deployment is Ubiquiti UniFi Protect running on hardware you own, on your own network. Recording and video stay on-premises, there is no recurring VMS license fee, and there is no mandatory dependency on a manufacturer cloud service. Remote or cloud-assisted access is opt-in and configured only if you want it.
Installed to manufacturer standard. Systems are installed and commissioned to the manufacturer's published installation standard and registered with the manufacturer, so the system is supportable by the manufacturer and not just by us.
Documented and warranty-backed. Every job closes out with as-built documentation, device labeling and asset tags, and credential/access-rights records handed to you - plus manufacturer warranty registered to your agency, not held back by a reseller.
What that looks like on site
- IP video: Ubiquiti UniFi Protect (on-prem, $0 recurring VMS license) as the default; Hanwha Wisenet / WAVE where a project specifies it or where enterprise VMS features are required
- Access control & intrusion: integrated to your workflow - credentialing, zones, and reporting - not bolted on after the fact
- Cabling: labeled, tested, and documented low-voltage runs, not a rat's nest behind the head-end
- Closeout package: as-builts, device/IP inventory, and warranty registration delivered at handoff
Every camera and access-control line we quote is screened under Section 889 before it ever reaches a proposal - see Supply-chain compliance below.
Identity, access & portal cyber posture
CAC / PIV gate, today. The ordering portal is gated by a smart-card sign-in flow. In the current build this captures and confirms the cardholder identity attached to each order - it is an ordering-identity gate, not yet a cryptographic PKI validation.
Mutual-TLS to federal PKI - roadmap. The production target is mutual-TLS client-certificate authentication, with the cardholder certificate validated against federal PKI through an ICAM / Login.gov-class identity broker before any order is accepted. We describe this as a roadmap item, not a live control, until it is actually wired up on a hosted deployment.
Zero-trust design. No implicit trust by network location. Every request is authenticated and authorized; sessions are short-lived; ordering identity is bound to each Request for Quote for a complete audit trail.
Least privilege & separation of duties. Roles (CO, COR, card holder, requisitioner) scope what a user can do. Approvals and order submission are auditable events.
Encryption, headers & transport
How the portal is designed to be deployed. This is a posture to verify on your specific hosted instance, not a guarantee about every possible host.
- In transit: configured for TLS 1.2+ (TLS 1.3 preferred) with HSTS and modern cipher suites at the hosting layer.
- At rest: this portal keeps your cart and requests in your browser only - no server-side storage. When a hosted backend stores order data, it is encrypted with AES-256-class protection.
- Headers & CSP: a hardened, strict-leaning set - Content-Security-Policy, X-Content-Type-Options, X-Frame-Options / frame-ancestors, Referrer-Policy, Permissions-Policy - ships in _headers and applies at the edge on a supporting host.
- No third-party scripts. Every script and stylesheet this site loads is self-hosted in assets/ - nothing is pulled from a third-party CDN, ad network, or analytics platform at runtime.
- Secrets: no credentials in client code; managed secrets and key rotation in a hosted deployment.
The hardened header set ships with this site (see _headers and the README); confirm it is enforced by your host.
Frameworks we align to
Everything in this section is our own self-assessment posture, stated as such. None of it is a claim of third-party certification, audit, or government authorization.
NIST SP 800-171
We follow the 800-171 control families for protecting Controlled Unclassified Information (CUI) that may appear in an order - access control, media protection, incident response, and audit.
Posture / self-assessment, not a third-party assessment. SPRS score and supporting attestations available on request where applicable.
CMMC 2.0 Level 1
Practices aligned to CMMC 2.0 Level 1 (basic safeguarding), with a roadmap toward Level 2 as contract requirements dictate.
Self-assessment only. We will not represent a C3PAO certification we have not earned.
FAR 52.204-21
Basic safeguarding of covered contractor information systems - the fifteen baseline controls - is part of our standard operating posture, on this portal and on the systems we design.
EO 14028
For software and configuration we deliver, we support secure-development expectations and can provide a Software Bill of Materials (SBOM) and attestation on request.
Supply-chain compliance
The fastest way a security-systems or IT order goes wrong is country-of-origin or prohibited-equipment rules. We screen for both, on every camera, panel, and part, before anything reaches you.
NDAA Section 889 - covered surveillance & telecom equipment
When a buyer asks for "NDAA compliant" cameras, this is the rule they mean: Section 889 of the FY2019 National Defense Authorization Act. We do not supply, specify, or install covered telecommunications or video-surveillance equipment under Section 889(a)(1)(A)/(B) - no Hikvision, Dahua, Huawei, ZTE, or Hytera, including OEM/white-label variants of that gear. Our video and access-control lines run on compliant manufacturers: Ubiquiti UniFi, Hanwha Wisenet, and Axis. Our reps & certs reflect Section 889 compliance on every quote, and each catalog item carries its NDAA 889 status.
NDAA Section 889 compliantTrade Agreements Act (TAA)
Our catalog is a full distribution catalog, so it carries both TAA-designated and non-designated product. We do not claim it is uniformly TAA compliant. Every item shows its country of manufacture and whether that country is TAA-designated, so you can see the answer before you order rather than after. Where your requirement is TAA-restricted, filter to designated origin or tell us and we will quote only compliant product and substantiate it. Country of origin is restated as a formal representation on every quote.
Country of origin shown per itemNDAA Section 5949 - covered semiconductors
Section 5949 of the FY2023 NDAA prohibits covered semiconductor products from SMIC, YMTC, CXMT and their affiliates in goods sold to the government. The prohibition takes effect for solicitations on and after 23 December 2027, so no vendor can truthfully represent full 5949 compliance today, and we do not claim it. What we do now: we track the rule, we will flag affected lines and make the formal representation as soon as it is required, and where your solicitation already imposes a 5949 or component-level restriction we will source and substantiate to it on request. Ask before you order and we will tell you what we can and cannot confirm on a given part.
Tracked, effective Dec 2027Authorized sources & anti-counterfeit
IT hardware sources through Dell Technologies (Federal) and TD SYNNEX distribution. Security equipment sources through manufacturer-authorized dealer channels for UniFi, Hanwha Wisenet, and Axis. Genuine, warrantied, traceable product only - no gray-market goods, ever.
No unauthorized substitution. What you quote is what ships and what gets installed. Any equivalent-product substitution is disclosed and requires your written approval before we proceed.
Sustainability
Where applicable to the product category, EPEAT- and ENERGY STAR-registered options are flagged so you can meet federal sustainable-acquisition goals (FAR Part 23).
EPEAT / ENERGY STARAccessibility - Section 508
This portal is designed to the Section 508 and WCAG 2.1 AA standards: semantic landmarks, keyboard operability, visible focus, sufficient color contrast, reduced-motion support, and a skip-to-content link. An accessibility statement and, on a hosted deployment, a formal Accessibility Conformance Report for the site are available on request.
Products we supply - including surveillance, access-control, and IT hardware lines - can be accompanied by manufacturer Accessibility Conformance Reports (ACR / VPAT) on request, to support your 508 market research and acquisition documentation.
Built-in accessibility features
- Keyboard-navigable catalog, cart, and RFQ
- ARIA live regions for cart and result updates
- Respects prefers-reduced-motion and dark mode
- Text alternatives and descriptive link text
Found a barrier? Tell us at contact and we'll remediate.
Privacy & data handling
- Data minimization. We collect only what an order needs - point of contact, agency, ship-to, and line items.
- Local by default. In this portal your cart and RFQ are assembled in your browser; nothing is transmitted until you choose to email or send it.
- No sale of data, no trackers. We never sell or broker your information. No third-party ad trackers or analytics scripts - every script and stylesheet on this site is self-hosted, none is loaded from a third-party CDN at runtime.
- Retention. Order records are retained only as needed for the transaction and applicable records requirements, then disposed of securely.
- No sensitive credentials. We never ask for passwords, card PINs, or SSNs through this site.
Vulnerability disclosure
We welcome good-faith security reports. If you believe you've found a vulnerability in this site, contact us and allow reasonable time to remediate before public disclosure.
- Report to
- Machine-readable
- /.well-known/security.txt
- Scope
- This ordering portal (williamstewart.us) and its subdomains
- Out of scope
- Systems we've installed at a customer site - those are governed by that customer's own security program; contact us directly for issues there
Consistent with widely adopted coordinated vulnerability disclosure practice (e.g., the approach CISA's BOD 20-01 established for federal agencies).
Questions about our security posture?
We're glad to share reps & certs, Section 889 attestations, SBOMs, SPRS references, manufacturer VPATs, and installed-system closeout documentation to support your acquisition file.
Request documentation