Forward-thinking security
Security & compliance posture
Federal buying runs on trust. Here is exactly how we approach identity, data, supply-chain integrity, secure software, and accessibility — stated honestly, with claims we can substantiate.
Identity & access
CAC / PIV smart-card sign-in and a zero-trust design so ordering is attributable and least-privilege.
Supply-chain integrity
TAA and Section 889 compliance, authorized-source sourcing, and counterfeit prevention on every line.
Safeguarding & secure software
NIST SP 800-171 practices, CMMC 2.0 alignment, and EO 14028 secure-development expectations.
Identity, access & zero trust
CAC / PIV first. The ordering portal is gated by a smart-card sign-in. In production this is enforced as mutual-TLS client-certificate authentication, with the cardholder certificate validated against federal PKI through an ICAM / Login.gov-class identity broker before any order is accepted.
Zero-trust design. No implicit trust by network location. Every request is authenticated and authorized; sessions are short-lived; ordering identity is bound to each Request for Quote for a complete audit trail.
Least privilege & separation of duties. Roles (CO, COR, card holder, requisitioner) scope what a user can do. Approvals and order submission are auditable events.
Encryption & transport
How the portal is configured to be deployed. Verify these are active on your specific hosted deployment.
- In transit: configured for TLS 1.2+ (TLS 1.3 preferred) with HSTS and modern cipher suites at the hosting layer.
- At rest: this portal keeps your cart and requests in your browser only — no server-side storage. When a hosted backend stores order data, it is encrypted with AES-256-class protection.
- Headers: a hardened set — Content-Security-Policy, X-Content-Type-Options, X-Frame-Options / frame-ancestors, Referrer-Policy, Permissions-Policy — ships in _headers and applies at the edge on a supporting host.
- Secrets: no credentials in client code; managed secrets and key rotation in a hosted deployment.
The hardened header set ships with this site (see _headers and the README); confirm it is enforced by your host.
Frameworks we align to
NIST SP 800-171
We follow the 800-171 control families for protecting Controlled Unclassified Information (CUI) that may appear in an order — access control, media protection, incident response, and audit.
Posture / self-assessment. SPRS score available on request where applicable.
CMMC 2.0
Practices aligned to CMMC 2.0 Level 1 (basic safeguarding), with a roadmap toward Level 2 as contract requirements dictate.
Self-assessment. We will not represent a C3PAO certification we have not earned.
FAR 52.204-21
Basic safeguarding of covered contractor information systems — the fifteen baseline controls — is part of our standard operating posture.
EO 14028
For software and configuration we deliver, we support secure-development expectations and can provide a Software Bill of Materials (SBOM) and attestation on request.
Supply-chain compliance
The fastest way an IT order goes wrong is country-of-origin or prohibited-equipment rules. We screen for both before anything reaches you.
Trade Agreements Act (TAA)
Products are offered from TAA-designated countries. TAA status is flagged per line in the catalog and restated on every quote. Where a stricter requirement applies, we source and substantiate to it.
TAA compliant sourcingSection 889
We do not supply covered telecommunications or video-surveillance equipment (e.g., Huawei, ZTE, Hytera, Hikvision, Dahua). Our reps & certs reflect Section 889(a)(1)(A) and (B) compliance.
Section 889 compliantAuthorized sources & anti-counterfeit
We source through Dell Technologies (Federal) and TD SYNNEX distribution — genuine, warrantied, traceable product. No gray-market goods.
Sustainability
EPEAT- and ENERGY STAR-registered options are flagged so you can meet federal sustainable-acquisition goals (FAR Part 23).
EPEAT / ENERGY STARAccessibility — Section 508
This portal is designed to the Section 508 and WCAG 2.1 AA standards: semantic landmarks, keyboard operability, visible focus, sufficient color contrast, reduced-motion support, and a skip-to-content link. An accessibility statement and, on a hosted deployment, a formal ACR for the site are available on request.
Products we supply can be accompanied by Accessibility Conformance Reports (ACR / VPAT) from the manufacturer on request, to support your 508 market research and acquisition documentation.
Built-in accessibility features
- Keyboard-navigable catalog, cart, and RFQ
- ARIA live regions for cart and result updates
- Respects prefers-reduced-motion and dark mode
- Text alternatives and descriptive link text
Found a barrier? Tell us at contact and we'll remediate.
Privacy & data handling
- Data minimization. We collect only what an order needs — point of contact, agency, ship-to, and line items.
- Local by default. In this portal your cart and RFQ are assembled in your browser; nothing is transmitted until you choose to email or send it.
- No sale of data. We never sell or broker your information. No third-party ad trackers.
- Retention. Order records are retained only as needed for the transaction and applicable records requirements, then disposed of securely.
- No sensitive credentials. We never ask for passwords, card PINs, or SSNs through this site.
Vulnerability disclosure
We welcome good-faith security reports. If you believe you've found a vulnerability in this site, contact us and allow reasonable time to remediate before public disclosure.
- Report to
- Machine-readable
- /.well-known/security.txt
- Scope
- This ordering portal and its subdomains
Consistent with widely adopted coordinated vulnerability disclosure practice (e.g., the approach CISA's BOD 20-01 established for federal agencies).
Questions about our security posture?
We're glad to share reps & certs, SBOMs, SPRS references, and manufacturer VPATs to support your acquisition file.
Request documentation