DefendR Privacy Policy
Who we are
DefendR is a product of Project KOS LLC, a Virginia limited liability company doing business as DefendR. DefendR provides CMMC Level 1 compliance documentation for defense industrial base suppliers. Questions about this policy go to hello@defendr.us.
Information DefendR collects
DefendR collects only what the service needs to operate:
- Account information: name, email address, and password credentials managed by our authentication provider.
- Company profile: company name, CAGE code, NAICS code, state of operations, employee count range, manufacturing types, IT and cloud environment, and related firmographic fields you provide during intake.
- Assessment responses: your answers to the compliance assessment, including the attestations that ground your generated documents.
- Generated documents: the documents DefendR produces from your assessment, retained in your account.
- Payment records: payment is processed by Stripe. DefendR receives transaction confirmations and does not store card numbers.
- Support messages and service email records.
- Technical logs necessary to operate and secure the service.
How DefendR uses information (data-use enumeration)
This section lists every category of use DefendR may make of your information. Category (a) is necessary to deliver the service you purchase. Categories (b) through (e) occur only with your express opt-in consent, captured as separate, unchecked-by-default choices at signup. Declining any of them does not affect your access to the compliance documentation product, and you may withdraw a consent at any time by writing to hello@defendr.us.
(a) Document generation and service delivery. Your profile and assessment responses are used to generate your compliance documents, to maintain your account and document record, and to provide support. This use is necessary to deliver the service.
(b) Aggregate, anonymized industry analytics. With your consent, your data may be included in aggregate, anonymized statistics about the defense industrial base, such as the share of small manufacturers in a sector that has implemented a given safeguard. Aggregate means cohort-level only: no statistic identifies you, and no output is published for a cohort small enough to identify you indirectly.
(c) Prime contractor supply chain intelligence, in attributable form. With your separate consent, DefendR may share your compliance documentation status, in a form that identifies your organization, with prime contractors you designate or that you work under, so those primes can rely on your verified documentation status.
(d) Cyber insurance routing, in attributable form. With your separate consent, DefendR may share your firmographic profile and compliance documentation status, in a form that identifies your organization, with insurance carriers for the purpose of routing you to coverage options. DefendR provides qualification signals only. Your security control attestations are compliance attestations; DefendR never supplies them to an insurer as verified evidence of control operation, and an insurer that underwrites you will run its own application and evidence process.
(e) Government acquisition intelligence, in attributable form. With your separate consent, DefendR may share your compliance documentation status, in a form that identifies your organization, with United States government acquisition or industrial base research consumers.
DefendR makes no other use of your information and does not sell your information.
What DefendR never does with your data
Customer-specific compliance posture, and in particular identifiable gap or weakness data tied to your organization or CAGE code, is held in trust. It is never sold, and never exposed to any third party except under the attributable-form categories above that you have expressly consented to, each of which shares documentation status rather than gap detail. Any analytics DefendR produces beyond your own account are aggregate and anonymized only, and DefendR does not construct datasets that could re-identify you through combinations such as CAGE code, NAICS code, state, and employee count.
The document verification page
Every generated document embeds a verification link and QR code. Anyone who holds that link can view a verification page showing your organization name, the document type, the generated date, the grounding version, the run identifier, and whether a more recent version of that document exists. The page shows no assessment content, no per-requirement status, and no gap detail. The verification page confirms document authenticity; it does not assert that any organization is compliant.
Service providers
DefendR uses a small set of service providers to operate: Supabase (database, authentication, and file storage), Stripe (payment processing), Resend (transactional email), Vercel (hosting), and Anthropic (document generation processing). Each processes data only to provide its service to DefendR.
Retention
Account, assessment, and document records are retained while your account is active, because your documents and their provenance record are the product. If you delete your account, DefendR deletes or anonymizes your information within a commercially reasonable period, except records DefendR must keep for legal, tax, or audit purposes.
Security
DefendR restricts access to customer data to what operating the service requires, uses role-scoped database access controls, and transmits data over encrypted connections. No method of storage or transmission is perfectly secure; DefendR will notify affected customers of a breach as required by law.
Your rights and choices
You may access and correct your profile and assessment information in your account at any time. You may request a copy or deletion of your information, or withdraw any consent under categories (b) through (e), by writing to hello@defendr.us. Transactional service emails (document delivery, account notices) are part of the service; they are not marketing email.
Children
DefendR is a business service and is not directed to individuals under 18.
Changes to this policy
If this policy changes, DefendR will post the updated policy at this address with a new effective date and, for material changes affecting the data-use categories above, notify account holders by email. A new data use is never applied to your information without the consent process described above.
Contact
Project KOS LLC (doing business as DefendR), Virginia, United States. hello@defendr.us.