How we handle access, data, and risk.
Federal buyers evaluate security before capability, and they are owed a straight answer rather than reassurance. Requirement specific answers, including anything about clearances, go to the contracting officer in writing rather than onto a web page.
Operating practices
The rules we work by.
- Supply chain review
- Cleared a federal agency supply chain risk review, including foreign ownership, control, and influence.
- Least access
- People get the access the task requires and nothing beyond it. Access is reviewed when someone changes role and removed the day they leave a program.
- Customer environment first
- Wherever the work allows, we operate inside the customer's environment on the customer's tooling, so data does not have to travel to be worked on.
- Written data handling
- If data has to move, where it goes, where it rests, how long it stays, and who can reach it are agreed in writing first.
- Managed devices
- Company devices are inventoried, encrypted, patched, and centrally managed. Personal devices are not used for customer work.
- Documented change
- Changes to a production system follow a written change process with a rollback path, on every program, including small ones.
- Subcontractor flowdown
- Anyone we bring onto a program carries the same handling obligations we do, in writing, before they touch anything.
- Incident notification
- The customer hears from us first. We report what is known, what is not, and what we are doing, on the timeline the contract sets.
Requirement specific answers
Ask us in writing and get it in writing.
Questions about clearances, facility requirements, framework assessments, and contract security clauses depend entirely on the requirement. Publishing general claims about them would be marketing, and marketing is the wrong medium for a security answer.
Send the requirement, the clauses, and the security section of the statement of work to gov@netaesthetics.us. You will get a written response addressing each item, including anything we cannot meet as written. A clear no is more useful to you than a vague yes.
This website
We keep tracking light on purpose.
Government buyers should be able to research a vendor without being followed around the internet. We use a small, disclosed set of analytics tools, ask before setting anything that is not strictly necessary, and the site works fully if you decline.
What we use and why is listed in the cookie policy, and what we do with anything you send us is in the privacy policy.
Questions about security
Clearance questions are answered directly to the contracting officer or prime for a specific requirement, not published on a web page. Send us the requirement and you will get a written answer.
We work inside the customer's environment and the customer's rules wherever possible. Where data must move, the handling is agreed in writing before any transfer, including where it rests and who can reach it.
Access is granted by role and reviewed when a person changes role or leaves. Nobody keeps access to a program they are no longer on.
The customer hears from us first, with what we know, what we do not know yet, and what we are doing. Notification timelines are set in the contract and we work to them.
Send us your security requirements.
We will respond in writing, item by item, including anything we cannot meet.
Last updated