CMMC Compass

Privacy Policy

Last updated: July 11, 2026

1. Information We Collect

We collect the information you provide directly, including your name, email address, organization name, password (stored as a secure hash, never in plain text), and the assessment data you enter, including control implementation status and implementation notes.

2. Do Not Submit CUI

Do not enter Controlled Unclassified Information or any classified or regulated data into CMMC Compass. This service is not authorized or designed to store such information.

3. How We Use Your Information

We use your information to provide the service, including generating SPRS scores, AI-drafted narratives, and exported compliance documents. We do not sell your information.

4. Third-Party Service Providers

We use the following third-party providers to operate the service:

  • Anthropic, to generate AI-drafted narrative content from your implementation notes
  • Resend, to send transactional emails such as password resets
  • Vercel, for application hosting
  • Neon, for database hosting

Each provider processes only the data necessary to perform its function.

5. Data Retention

We retain your account and assessment data for as long as your account remains active. You may request deletion of your account and associated data by contacting us.

6. Data Security

Passwords are hashed using industry-standard methods. Access to assessment data is scoped to your organization and is not visible to other customers.

7. Cookies

We use a session cookie solely for authentication purposes. We do not use tracking or advertising cookies.

8. Children's Privacy

This service is intended for business use and is not directed at individuals under 18.

9. Changes to This Policy

We may update this policy from time to time. Material changes will be communicated to active customers.

10. Contact

Questions about this policy can be sent to jay@nymbussecurity.com.