One-pager for ISSO + privacy
Where the data lives, and what we do in a breach.
United States. Cloudflare. Encrypted in transit and at rest. FedRAMP not authorized. No SOC 2 report to attach. No completed NIST 800-171 / FISMA package. Breach notice: 72 hours to the named agency contact.
| Topic | Answer |
|---|---|
| Location | Cloudflare (US) Pages / Workers / D1 / R2 |
| Encrypt | TLS in transit; at rest on Cloudflare managed storage |
| Retention | 36 months from kickoff unless the agency asks sooner |
| Delete | Within 30 days of written agency request, except legal hold; we confirm in writing |
| Breach | Notify named contact within 72 hours of confirmed unauthorized access involving that roster |
| Subprocessors | Cloudflare, Stripe (cards only), Mailgun (invites) |
| FedRAMP / SOC 2 / 800-171 | Not authorized / no SOC 2 letter / no 800-171 SPRS score to show. Detail: security statement |
| PIA / SORN | Agency determination. Vendor input: Privacy Act page |
Also: faq-library · DPA