San Antonio, TX · Military City, USA UEI L58JZMKRCLM5  ·  CAGE 203C1  ·  NAICS 541511  ·  SAM.gov Active
FOUND SOMETHING?

Report it to us directly.

If you have found a security vulnerability in a system BrandShyp operates, we want to hear from you. Email [email protected] with “Security” in the subject line. You may report anonymously.

We are a small firm and we do not run a 24/7 security desk. The response times below are what we can actually meet, not what sounds impressive.

WHERE WE STAND

Our security & compliance posture

Stated plainly, including what is done and what is still in progress. We do not claim credentials we have not earned.

SELF-ASSESSED

CMMC Level 2 & NIST 800-171

Our NIST SP 800-171 self-assessment is complete and affirmed in SPRS as CMMC Level 2 (Self-Assessment), backed by a CUI enclave using FIPS-validated cryptography. A readiness posture, not a C3PAO certification.

IN PROGRESS

SOC 2 (Security Criteria)

We hold our own systems to the SOC 2 Security Trust Services Criteria and run the same assessment we publish as a free tool. Readiness is in progress; no third-party attestation has been engaged yet. We reuse our NIST 800-171 overlap and track every gap in a POA&M.

Use the free tool
OPERATING

Ongoing practice

This vulnerability disclosure policy, dependency vulnerability scanning with SBOM generation on our own code, enforced MFA, endpoint hardening, and encrypted nightly backups.

WHAT WE COMMIT TO

Our response

Deliberately conservative targets that we can meet.

3 DAYS

Acknowledgement

We confirm we received your report within three business days.

10 DAYS

Triage

An initial assessment and severity rating within ten business days.

30 DAYS

Updates

A status update every thirty days while work continues, and a notification when it is resolved.

SCOPE

What is and is not covered

In scope

  • brandshyp.org and its subdomains
  • The free tools and public APIs hosted there
  • Client websites BrandShyp hosts or maintains, to the extent we control them

Out of scope

  • Third-party services we merely use (report those to the provider)
  • Findings requiring physical access, social engineering of our staff, or a compromised end-user device
  • Volumetric denial-of-service testing
  • Automated scanner output with no demonstrated, exploitable impact
SAFE HARBOR

Research in good faith is welcome

If you make a good-faith effort to comply with this policy, BrandShyp will not pursue or support legal action against you for your research.

In return, we ask that you:

  • Avoid privacy violations, data destruction, and service degradation
  • Access only the minimum data needed to demonstrate the issue, and never save, transfer, or use third-party data you encounter
  • Give us reasonable time to remediate before disclosing publicly

BrandShyp does not currently offer monetary bounties. We will credit researchers who wish to be named once an issue is resolved.

Machine-readable version: /.well-known/security.txt (RFC 9116).

SECURITY IS THE PRODUCT

We hold the line on our own systems

BrandShyp maintains a NIST 800-171 aligned security program and publishes free compliance tools for the contractors we work alongside. If you need that discipline applied to your environment, talk to us.