Legal & policies

We hold ourselves to the standard we assess.

How we handle your information, the terms under which this site operates, our accessibility commitment, and how to report a security vulnerability to us.

01 Privacy Policy 02 Terms of Use 03 Accessibility 04 Vulnerability Disclosure

Last updated · August 2026

01 · Privacy Policy

We collect almost nothing. Deliberately.

A security consultancy that hoards visitor data would be advising against its own behavior. This site is built to know as little about you as possible.

Questions · gmhardy@nationalsecurity.com

What we collect

Correspondence you send us. When you email us or start a conversation, we receive your name, email address, and whatever you choose to include. We use it to respond, and to run the engagement if one follows. Standard server logs. Like nearly every site, our hosting infrastructure records IP addresses and requested pages for security monitoring and abuse prevention. Logs are retained briefly and reviewed only when investigating a problem.

What we do not do

No sale or rental of personal information — to anyone, ever No advertising trackers or third-party marketing pixels No profiling, scoring, or automated decision-making about visitors No retention of client-identifying material beyond the engagement's needs

Client & engagement information

Information shared with us under an engagement is governed by that engagement's agreement and any applicable non-disclosure terms — which are stricter than this policy. Assessment artifacts, evidence, and findings belong to the client and are handled, stored, and destroyed per the engagement terms.

Your choices

You may ask us at any time what personal information we hold about you, ask us to correct it, or ask us to delete it — email gmhardy@nationalsecurity.com. We honor these requests unless a legal or contractual obligation requires retention.

02 · Terms of Use

Plain terms for a plain purpose.

This site describes what we do. It is not the work itself — that begins with a signed engagement.

Informational purpose

Content on this site — including framework summaries, playbooks, checklists, and the documentation workspace — is provided for general information. It reflects our methodology, not advice for your specific facts. Nothing here creates a consulting relationship, and you should not act on it as a substitute for qualified advice under an engagement.

No warranty on regulatory currency

CMMC, FedRAMP, NIST publications, and DFARS clauses change. We keep this material current as a professional habit, but we make no warranty that any page reflects the regulation in force on the day you read it. Engagements are always executed against the current authoritative text.

Intellectual property

The methodology, playbooks, taskboards, and content on this site are the property of National Security Corporation. You may reference them with attribution; you may not republish them, resell them, or present them as your own deliverables. Framework names (CMMC, NIST, FedRAMP) belong to their respective owners.

Limitation of liability

To the maximum extent permitted by law, National Security Corporation is not liable for damages arising from use of this site or reliance on its content. Liability for engagement work is governed exclusively by the engagement agreement.

Changes

We may update these terms as the site evolves. The "Last updated" date above reflects the current version; continued use after a change constitutes acceptance.

03 · Accessibility

Built for every reader, including assistive technology.

We work with federal agencies and the contractors who serve them — Section 508 isn't an afterthought in our world.

WCAG 2.1 AA target · Section 508 aligned

Our commitment

National Security Corporation aims to conform to the Web Content Accessibility Guidelines (WCAG) 2.1 Level AA, consistent with the standards incorporated in Section 508 of the Rehabilitation Act. Accessibility review is part of how we build and revise this site, not a one-time audit.

Measures in place

Semantic structure with meaningful headings and landmarks Text alternatives on informative images; decorative art marked hidden Color contrast checked against AA thresholds in both themes Full keyboard operability — navigation, search, and taskboards Meaning never carried by color alone — status uses text plus color Layouts that reflow at high zoom and on small screens

Found a barrier?

If any part of this site is difficult to use with assistive technology, tell us at gmhardy@nationalsecurity.com with the page and the assistive technology you were using. We aim to acknowledge accessibility reports within 2 business days and to remediate confirmed barriers promptly.

04 · Vulnerability Disclosure Policy

Found something? We want to hear it — directly and first.

We tell clients that a mature security program welcomes disclosure. We operate the same way.

Report a vulnerability →

security@nationalsecurity.com

Scope & rules of engagement

In scope: this website and any internet-facing service we operate under nationalsecurity.com. Do not access, modify, or exfiltrate data that is not yours; use test accounts and minimal proof-of-concept only. No denial-of-service testing, physical intrusion, or social engineering of our people or clients. Client systems we assess are out of scope — they are covered by each engagement's own rules.

What to include

Affected URL or service Steps to reproduce Impact assessment Proof of concept, if available How you'd like to be credited

What you can expect from us

Acknowledgment within 3 business days A named point of contact through triage and remediation Status updates as we validate and fix Credit for the find, if you want it

Safe harbor

Research conducted in good faith and within this policy is authorized activity. We will not pursue or support legal action against you for it, and if a third party does, we will make clear your research was authorized. Good faith means: report promptly, don't exploit beyond demonstration, and give us reasonable time to remediate before public disclosure.