DefendRPrivacy Policy

DefendR Privacy Policy

Draft for operator and counsel review. Not yet in effect; the effective date is set at publication.

Who we are

DefendR is a product of Project KOS LLC, a Virginia limited liability company doing business as DefendR. DefendR provides CMMC Level 1 compliance documentation for defense industrial base suppliers. Questions about this policy go to hello@defendr.us.

Information DefendR collects

DefendR collects only what the service needs to operate:

  • Account information: name, email address, and password credentials managed by our authentication provider.
  • Company profile: company name, CAGE code, NAICS code, state of operations, employee count range, manufacturing types, IT and cloud environment, and related firmographic fields you provide during intake.
  • Assessment responses: your answers to the compliance assessment, including the attestations that ground your generated documents.
  • Generated documents: the documents DefendR produces from your assessment, retained in your account.
  • Payment records: payment is processed by Stripe. DefendR receives transaction confirmations and does not store card numbers.
  • Support messages and service email records.
  • Technical logs necessary to operate and secure the service.

How DefendR uses information (data-use enumeration)

This section lists every category of use DefendR may make of your information. Category (a) is necessary to deliver the service you purchase. Categories (b) through (e) occur only with your express opt-in consent, captured as separate, unchecked-by-default choices at signup. Declining any of them does not affect your access to the compliance documentation product, and you may withdraw a consent at any time by writing to hello@defendr.us.

(a) Document generation and service delivery. Your profile and assessment responses are used to generate your compliance documents, to maintain your account and document record, and to provide support. This use is necessary to deliver the service.

(b) Aggregate, anonymized industry analytics. With your consent, your data may be included in aggregate, anonymized statistics about the defense industrial base, such as the share of small manufacturers in a sector that has implemented a given safeguard. Aggregate means cohort-level only: no statistic identifies you, and no output is published for a cohort small enough to identify you indirectly.

(c) Prime contractor supply chain intelligence, in attributable form. With your separate consent, DefendR may share your compliance documentation status, in a form that identifies your organization, with prime contractors you designate or that you work under, so those primes can rely on your verified documentation status.

(d) Cyber insurance routing, in attributable form. With your separate consent, DefendR may share your firmographic profile and compliance documentation status, in a form that identifies your organization, with insurance carriers for the purpose of routing you to coverage options. DefendR provides qualification signals only. Your security control attestations are compliance attestations; DefendR never supplies them to an insurer as verified evidence of control operation, and an insurer that underwrites you will run its own application and evidence process.

(e) Government acquisition intelligence, in attributable form. With your separate consent, DefendR may share your compliance documentation status, in a form that identifies your organization, with United States government acquisition or industrial base research consumers.

DefendR makes no other use of your information and does not sell your information.

What DefendR never does with your data

Customer-specific compliance posture, and in particular identifiable gap or weakness data tied to your organization or CAGE code, is held in trust. It is never sold, and never exposed to any third party except under the attributable-form categories above that you have expressly consented to, each of which shares documentation status rather than gap detail. Any analytics DefendR produces beyond your own account are aggregate and anonymized only, and DefendR does not construct datasets that could re-identify you through combinations such as CAGE code, NAICS code, state, and employee count.

The document verification page

Every generated document embeds a verification link and QR code. Anyone who holds that link can view a verification page showing your organization name, the document type, the generated date, the grounding version, the run identifier, and whether a more recent version of that document exists. The page shows no assessment content, no per-requirement status, and no gap detail. The verification page confirms document authenticity; it does not assert that any organization is compliant.

Service providers

DefendR uses a small set of service providers to operate: Supabase (database, authentication, and file storage), Stripe (payment processing), Resend (transactional email), Vercel (hosting), and Anthropic (document generation processing). Each processes data only to provide its service to DefendR.

Operator decision required. Counsel review point: confirm the named-processor list and whether data-processing agreements with each provider should be referenced here. Naming Anthropic is an honesty-over-concealment call (it is accurate disclosure, not marketing framing); confirm you are comfortable with it appearing here.

Retention

Account, assessment, and document records are retained while your account is active, because your documents and their provenance record are the product. If you delete your account, DefendR deletes or anonymizes your information within a commercially reasonable period, except records DefendR must keep for legal, tax, or audit purposes.

Operator decision required. Set the post-deletion retention period (for example, 30 or 90 days) and confirm whether document provenance records for previously issued verification links should survive account deletion or go dark with it. That choice affects what a relying party sees when scanning a document issued before deletion.

Security

DefendR restricts access to customer data to what operating the service requires, uses role-scoped database access controls, and transmits data over encrypted connections. No method of storage or transmission is perfectly secure; DefendR will notify affected customers of a breach as required by law.

Your rights and choices

You may access and correct your profile and assessment information in your account at any time. You may request a copy or deletion of your information, or withdraw any consent under categories (b) through (e), by writing to hello@defendr.us. Transactional service emails (document delivery, account notices) are part of the service; they are not marketing email.

Children

DefendR is a business service and is not directed to individuals under 18.

Changes to this policy

If this policy changes, DefendR will post the updated policy at this address with a new effective date and, for material changes affecting the data-use categories above, notify account holders by email. A new data use is never applied to your information without the consent process described above.

Contact

Project KOS LLC (doing business as DefendR), Virginia, United States. hello@defendr.us.