Skip to content

Security & Compliance

Security FAQ

Direct answers to the questions that appear in supplier assessments and technical evaluations. Where the honest answer is no, we say no.

Questions

Frequently asked security questions

Do you support multi-factor authentication?
Yes. Multi-factor authentication is required for administrative access to cloud consoles, source control, email, and deployment systems. For applications we build, MFA is offered as a standard design option and is recommended for any privileged role.
How do you manage vulnerabilities?
Vulnerabilities are identified through dependency scanning, static and dynamic analysis, platform advisories, and reports received through our responsible disclosure process. Each finding is triaged by severity and exposure, assigned an owner, remediated on a risk-prioritized timeline, and verified after the fix.
How are backups protected?
Backups run on a defined schedule, are encrypted at rest, and are access-restricted separately from routine production operations. Restoration is validated periodically so recovery is a tested capability rather than an assumption.
How is customer data protected?
Customer data is encrypted in transit and at rest, access is limited by role to personnel with a delivery need, and administrative access is logged. Customers retain ownership of their data; it is never sold and is not used for unrelated purposes.
Do you use secure development practices?
Yes. Our lifecycle includes security requirements, threat modeling for sensitive systems, mandatory peer review, secret detection, dependency scanning, static and dynamic analysis, and auditable deployments through protected pipelines.
How do you assess suppliers?
Vendors and subprocessors are evaluated before onboarding, tiered by criticality and data access, and reassessed on a recurring cadence or when their role changes. Our approach is informed by NIST SP 800-161 cyber supply chain risk management concepts.
Are you FedRAMP authorized, SOC 2 certified, or CMMC certified?
No. We do not hold FedRAMP authorization, SOC 2 attestation, ISO 27001 certification, or CMMC certification, and we do not claim them. Our practices are designed around those frameworks, and formal validation appears on our compliance roadmap as a future goal.
Can you complete a security questionnaire or supplier assessment?
Yes. Submit the questionnaire through the security documentation request workflow. We complete contracting-office, prime contractor, and integrator questionnaires and can provide supporting summaries under NDA where the material is sensitive.
How do you handle personnel security?
Access is granted on a need-to-know basis after onboarding, personnel acknowledge acceptable use and security expectations, and access is revoked promptly at separation or role change. Background screening is performed where a contract requires it.
How should a researcher report a vulnerability?
Use our responsible disclosure process. Reports are submitted through the secure contact workflow, and good-faith research conducted within the stated scope is covered by our safe harbor statement.

Search

Looking for something else?

Search across every Security & Compliance page, framework, policy summary, and document.

Search pages, frameworks, policies, documents, and FAQ answers.

IEP ALLY APP LLC does not hold FedRAMP authorization, SOC 2 attestation, ISO 27001 certification, or CMMC certification. Framework references describe familiarity and practice alignment only. They do not represent certification, authorization, endorsement, audit, or verified compliance status.

Requesting security documentation?

Contracting officers, prime contractors, integrators, and auditors can request review materials through our secure documentation workflow.