Skip to main content
Security posture

How we handle access, data, and risk.

Federal buyers evaluate security before capability, and they are owed a straight answer rather than reassurance. Requirement specific answers, including anything about clearances, go to the contracting officer in writing rather than onto a web page.

Send us your security requirements

Operating practices

The rules we work by.

Supply chain review
Cleared a federal agency supply chain risk review, including foreign ownership, control, and influence.
Least access
People get the access the task requires and nothing beyond it. Access is reviewed when someone changes role and removed the day they leave a program.
Customer environment first
Wherever the work allows, we operate inside the customer's environment on the customer's tooling, so data does not have to travel to be worked on.
Written data handling
If data has to move, where it goes, where it rests, how long it stays, and who can reach it are agreed in writing first.
Managed devices
Company devices are inventoried, encrypted, patched, and centrally managed. Personal devices are not used for customer work.
Documented change
Changes to a production system follow a written change process with a rollback path, on every program, including small ones.
Subcontractor flowdown
Anyone we bring onto a program carries the same handling obligations we do, in writing, before they touch anything.
Incident notification
The customer hears from us first. We report what is known, what is not, and what we are doing, on the timeline the contract sets.

Requirement specific answers

Ask us in writing and get it in writing.

Questions about clearances, facility requirements, framework assessments, and contract security clauses depend entirely on the requirement. Publishing general claims about them would be marketing, and marketing is the wrong medium for a security answer.

Send the requirement, the clauses, and the security section of the statement of work to gov@netaesthetics.us. You will get a written response addressing each item, including anything we cannot meet as written. A clear no is more useful to you than a vague yes.

This website

We keep tracking light on purpose.

Government buyers should be able to research a vendor without being followed around the internet. We use a small, disclosed set of analytics tools, ask before setting anything that is not strictly necessary, and the site works fully if you decline.

What we use and why is listed in the cookie policy, and what we do with anything you send us is in the privacy policy.

FAQ

Questions about security

Clearance questions are answered directly to the contracting officer or prime for a specific requirement, not published on a web page. Send us the requirement and you will get a written answer.

We work inside the customer's environment and the customer's rules wherever possible. Where data must move, the handling is agreed in writing before any transfer, including where it rests and who can reach it.

Access is granted by role and reviewed when a person changes role or leaves. Nobody keeps access to a program they are no longer on.

The customer hears from us first, with what we know, what we do not know yet, and what we are doing. Notification timelines are set in the contract and we work to them.

Next step

Send us your security requirements.

We will respond in writing, item by item, including anything we cannot meet.

Request a capability briefingEmail directly

Last updated