Skip to content

Trust Center

Government Trust Center

A single destination for reviewers evaluating IEP ALLY APP LLC. This page is maintained by IEP ALLY APP LLC to answer common security, privacy, and contracting questions about IEP Ally Gov.

Search

Find security information quickly

Search pages, frameworks, policies, documents, and FAQ answers.

Corporate identity

Business identifiers

Identifiers used for registration, contracting, and supplier verification.
UEI
W1SKLXFF7XK8
CAGE
Pending Assignment
Primary NAICS
541511
Business Type
Small Business
SAM Status
Registration Processing

Program status

Security program areas

Self-reported, informational descriptions of program activity.
  • Secure Development Lifecycle

    Security activities mapped across requirements, build, test, and release.

  • Risk Management Program

    Risks identified, owned, and tracked to a documented decision.

  • Supply Chain Security Program

    Vendor review and dependency governance informed by NIST SP 800-161.

  • Business Continuity Planning

    Documented recovery expectations with periodic restoration testing.

  • Incident Response Preparedness

    Defined lifecycle, roles, and escalation criteria maintained internally.

  • Cloud Security Practices

    Identity-first controls, encryption, segmentation, and audit logging.

These badges describe internal program activities. They are not certifications, audit results, attestations, or third-party verifications.

Scorecard

Program status by area

An informational summary of implemented, in-progress, and planned practices. It is not an audit result or scored assessment.
Informational, self-reported security program status by area.
Program areaImplementedIn progressPlannedNotes
Policy Library2252Documented policy summaries published; remaining items in drafting or scheduled review.
Framework Alignment653Practices implemented, program alignment, and roadmap items across referenced frameworks.
Risk Reviews311Recurring internal risk review with a maintained register and treatment decisions.
Training211Onboarding and recurring awareness topics; expanded role-based training planned.
Vendor Assessments221Pre-onboarding evaluation in place; tiering and reassessment cadence maturing.

This scorecard is informational and self-reported. It reflects internal program activity counts and is not an audit, assessment result, score, rating, or certification.

Documents

Document library

Public materials are available immediately. Sensitive materials are released to verified requesters, and operational detail requires an NDA or an active contract.

Public

Available immediately from this site.

  • Federal Capability Statement

    Identifiers, core competencies, differentiators, NAICS and PSC codes on a single contracting-ready page.

  • Security Overview

    Public description of the security program, control areas, and framework familiarity.

  • Privacy Policy

    How information submitted through this site is collected, used, and protected.

  • Accessibility Statement

    Section 508 and WCAG 2.1 AA conformance approach and feedback path.

  • Terms of Use

    Terms governing use of this website and its published materials.

Upon Request

Provided to verified government, prime contractor, integrator, customer, or auditor requesters.

  • Basic Safeguarding Questionnaire

    Completed response covering the FAR 52.204-21 basic safeguarding requirements.

  • Cyber Supply Chain Risk Management Plan

    Summary of vendor evaluation, criticality tiering, provenance review, and flow-down practices.

  • Business Continuity Summary

    Continuity approach, recovery expectations, and testing cadence.

  • Incident Response Summary

    Lifecycle, roles, severity classification, and notification expectations.

  • Vendor Management Summary

    Onboarding evaluation, tiering, reassessment cadence, and offboarding.

  • Security Policy Summary

    Consolidated summary of the 29-policy library with owners, versions, and review dates.

NDA or Contract

Contains operational detail. Released only under an executed NDA or an active contract, with need to know.

  • System Security Plan

    Control implementation detail for a specific system or engagement boundary.

  • Network Architecture

    Environment topology, trust boundaries, and data flow detail.

  • Risk Register

    Identified risks with ratings, owners, and treatment decisions.

  • Asset Inventory

    Systems, services, and data stores with assigned owners.

  • Configuration Standards

    Baseline hardening standards applied to platforms and services.

  • Operational Runbooks

    Step-by-step operational procedures for production systems.

  • Recovery Procedures

    Detailed restoration sequences, dependencies, and validation steps.

Explore

All Security & Compliance pages

IEP ALLY APP LLC does not hold FedRAMP authorization, SOC 2 attestation, ISO 27001 certification, or CMMC certification. Framework references describe familiarity and practice alignment only. They do not represent certification, authorization, endorsement, audit, or verified compliance status.

Requesting security documentation?

Contracting officers, prime contractors, integrators, and auditors can request review materials through our secure documentation workflow.