Forward-thinking security

Security & compliance posture

Federal buying runs on trust. Here is exactly how we approach identity, data, supply-chain integrity, secure software, and accessibility — stated honestly, with claims we can substantiate.

Plain-language commitment: where a framework below reflects our internal posture / self-assessment, we say so. We do not represent a third-party certification we do not hold. Ask us for our current attestations and we will provide them.

Identity & access

CAC / PIV smart-card sign-in and a zero-trust design so ordering is attributable and least-privilege.

Supply-chain integrity

TAA and Section 889 compliance, authorized-source sourcing, and counterfeit prevention on every line.

Safeguarding & secure software

NIST SP 800-171 practices, CMMC 2.0 alignment, and EO 14028 secure-development expectations.

Identity, access & zero trust

CAC / PIV first. The ordering portal is gated by a smart-card sign-in. In production this is enforced as mutual-TLS client-certificate authentication, with the cardholder certificate validated against federal PKI through an ICAM / Login.gov-class identity broker before any order is accepted.

Zero-trust design. No implicit trust by network location. Every request is authenticated and authorized; sessions are short-lived; ordering identity is bound to each Request for Quote for a complete audit trail.

Least privilege & separation of duties. Roles (CO, COR, card holder, requisitioner) scope what a user can do. Approvals and order submission are auditable events.

Encryption & transport

How the portal is configured to be deployed. Verify these are active on your specific hosted deployment.

  • In transit: configured for TLS 1.2+ (TLS 1.3 preferred) with HSTS and modern cipher suites at the hosting layer.
  • At rest: this portal keeps your cart and requests in your browser only — no server-side storage. When a hosted backend stores order data, it is encrypted with AES-256-class protection.
  • Headers: a hardened set — Content-Security-Policy, X-Content-Type-Options, X-Frame-Options / frame-ancestors, Referrer-Policy, Permissions-Policy — ships in _headers and applies at the edge on a supporting host.
  • Secrets: no credentials in client code; managed secrets and key rotation in a hosted deployment.

The hardened header set ships with this site (see _headers and the README); confirm it is enforced by your host.

Frameworks we align to

Safeguarding

NIST SP 800-171

We follow the 800-171 control families for protecting Controlled Unclassified Information (CUI) that may appear in an order — access control, media protection, incident response, and audit.

Posture / self-assessment. SPRS score available on request where applicable.

Maturity

CMMC 2.0

Practices aligned to CMMC 2.0 Level 1 (basic safeguarding), with a roadmap toward Level 2 as contract requirements dictate.

Self-assessment. We will not represent a C3PAO certification we have not earned.

FAR

FAR 52.204-21

Basic safeguarding of covered contractor information systems — the fifteen baseline controls — is part of our standard operating posture.

Secure software

EO 14028

For software and configuration we deliver, we support secure-development expectations and can provide a Software Bill of Materials (SBOM) and attestation on request.

Supply-chain compliance

The fastest way an IT order goes wrong is country-of-origin or prohibited-equipment rules. We screen for both before anything reaches you.

Trade Agreements Act (TAA)

Products are offered from TAA-designated countries. TAA status is flagged per line in the catalog and restated on every quote. Where a stricter requirement applies, we source and substantiate to it.

TAA compliant sourcing

Section 889

We do not supply covered telecommunications or video-surveillance equipment (e.g., Huawei, ZTE, Hytera, Hikvision, Dahua). Our reps & certs reflect Section 889(a)(1)(A) and (B) compliance.

Section 889 compliant

Authorized sources & anti-counterfeit

We source through Dell Technologies (Federal) and TD SYNNEX distribution — genuine, warrantied, traceable product. No gray-market goods.

Sustainability

EPEAT- and ENERGY STAR-registered options are flagged so you can meet federal sustainable-acquisition goals (FAR Part 23).

EPEAT / ENERGY STAR

Accessibility — Section 508

This portal is designed to the Section 508 and WCAG 2.1 AA standards: semantic landmarks, keyboard operability, visible focus, sufficient color contrast, reduced-motion support, and a skip-to-content link. An accessibility statement and, on a hosted deployment, a formal ACR for the site are available on request.

Products we supply can be accompanied by Accessibility Conformance Reports (ACR / VPAT) from the manufacturer on request, to support your 508 market research and acquisition documentation.

Built-in accessibility features

  • Keyboard-navigable catalog, cart, and RFQ
  • ARIA live regions for cart and result updates
  • Respects prefers-reduced-motion and dark mode
  • Text alternatives and descriptive link text

Found a barrier? Tell us at contact and we'll remediate.

Privacy & data handling

  • Data minimization. We collect only what an order needs — point of contact, agency, ship-to, and line items.
  • Local by default. In this portal your cart and RFQ are assembled in your browser; nothing is transmitted until you choose to email or send it.
  • No sale of data. We never sell or broker your information. No third-party ad trackers.
  • Retention. Order records are retained only as needed for the transaction and applicable records requirements, then disposed of securely.
  • No sensitive credentials. We never ask for passwords, card PINs, or SSNs through this site.

Vulnerability disclosure

We welcome good-faith security reports. If you believe you've found a vulnerability in this site, contact us and allow reasonable time to remediate before public disclosure.

Report to
Machine-readable
/.well-known/security.txt
Scope
This ordering portal and its subdomains

Consistent with widely adopted coordinated vulnerability disclosure practice (e.g., the approach CISA's BOD 20-01 established for federal agencies).

Questions about our security posture?

We're glad to share reps & certs, SBOMs, SPRS references, and manufacturer VPATs to support your acquisition file.

Request documentation