Real World Careers

One-pager for ISSO + privacy

Where the data lives, and what we do in a breach.

United States. Cloudflare. Encrypted in transit and at rest. FedRAMP not authorized. No SOC 2 report to attach. No completed NIST 800-171 / FISMA package. Breach notice: 72 hours to the named agency contact.

TopicAnswer
LocationCloudflare (US) Pages / Workers / D1 / R2
EncryptTLS in transit; at rest on Cloudflare managed storage
Retention36 months from kickoff unless the agency asks sooner
DeleteWithin 30 days of written agency request, except legal hold; we confirm in writing
BreachNotify named contact within 72 hours of confirmed unauthorized access involving that roster
SubprocessorsCloudflare, Stripe (cards only), Mailgun (invites)
FedRAMP / SOC 2 / 800-171Not authorized / no SOC 2 letter / no 800-171 SPRS score to show. Detail: security statement
PIA / SORNAgency determination. Vendor input: Privacy Act page

Also: faq-library · DPA