Legal & policies
How we handle your information, the terms under which this site operates, our accessibility commitment, and how to report a security vulnerability to us.
Last updated · August 2026
01 · Privacy Policy
A security consultancy that hoards visitor data would be advising against its own behavior. This site is built to know as little about you as possible.
Questions · gmhardy@nationalsecurity.com
What we collect
What we do not do
Client & engagement information
Information shared with us under an engagement is governed by that engagement's agreement and any applicable non-disclosure terms — which are stricter than this policy. Assessment artifacts, evidence, and findings belong to the client and are handled, stored, and destroyed per the engagement terms.
Your choices
You may ask us at any time what personal information we hold about you, ask us to correct it, or ask us to delete it — email gmhardy@nationalsecurity.com. We honor these requests unless a legal or contractual obligation requires retention.
02 · Terms of Use
This site describes what we do. It is not the work itself — that begins with a signed engagement.
Informational purpose
Content on this site — including framework summaries, playbooks, checklists, and the documentation workspace — is provided for general information. It reflects our methodology, not advice for your specific facts. Nothing here creates a consulting relationship, and you should not act on it as a substitute for qualified advice under an engagement.
No warranty on regulatory currency
CMMC, FedRAMP, NIST publications, and DFARS clauses change. We keep this material current as a professional habit, but we make no warranty that any page reflects the regulation in force on the day you read it. Engagements are always executed against the current authoritative text.
Intellectual property
The methodology, playbooks, taskboards, and content on this site are the property of National Security Corporation. You may reference them with attribution; you may not republish them, resell them, or present them as your own deliverables. Framework names (CMMC, NIST, FedRAMP) belong to their respective owners.
Limitation of liability
To the maximum extent permitted by law, National Security Corporation is not liable for damages arising from use of this site or reliance on its content. Liability for engagement work is governed exclusively by the engagement agreement.
Changes
We may update these terms as the site evolves. The "Last updated" date above reflects the current version; continued use after a change constitutes acceptance.
03 · Accessibility
We work with federal agencies and the contractors who serve them — Section 508 isn't an afterthought in our world.
WCAG 2.1 AA target · Section 508 aligned
Our commitment
National Security Corporation aims to conform to the Web Content Accessibility Guidelines (WCAG) 2.1 Level AA, consistent with the standards incorporated in Section 508 of the Rehabilitation Act. Accessibility review is part of how we build and revise this site, not a one-time audit.
Measures in place
Found a barrier?
If any part of this site is difficult to use with assistive technology, tell us at gmhardy@nationalsecurity.com with the page and the assistive technology you were using. We aim to acknowledge accessibility reports within 2 business days and to remediate confirmed barriers promptly.
04 · Vulnerability Disclosure Policy
We tell clients that a mature security program welcomes disclosure. We operate the same way.
Report a vulnerability →security@nationalsecurity.com
Scope & rules of engagement
What to include
What you can expect from us
Safe harbor
Research conducted in good faith and within this policy is authorized activity. We will not pursue or support legal action against you for it, and if a third party does, we will make clear your research was authorized. Good faith means: report promptly, don't exploit beyond demonstration, and give us reasonable time to remediate before public disclosure.