Privacy Policy
Last updated: July 11, 2026
1. Information We Collect
We collect the information you provide directly, including your name, email address, organization name, password (stored as a secure hash, never in plain text), and the assessment data you enter, including control implementation status and implementation notes.
2. Do Not Submit CUI
Do not enter Controlled Unclassified Information or any classified or regulated data into CMMC Compass. This service is not authorized or designed to store such information.
3. How We Use Your Information
We use your information to provide the service, including generating SPRS scores, AI-drafted narratives, and exported compliance documents. We do not sell your information.
4. Third-Party Service Providers
We use the following third-party providers to operate the service:
- Anthropic, to generate AI-drafted narrative content from your implementation notes
- Resend, to send transactional emails such as password resets
- Vercel, for application hosting
- Neon, for database hosting
Each provider processes only the data necessary to perform its function.
5. Data Retention
We retain your account and assessment data for as long as your account remains active. You may request deletion of your account and associated data by contacting us.
6. Data Security
Passwords are hashed using industry-standard methods. Access to assessment data is scoped to your organization and is not visible to other customers.
7. Cookies
We use a session cookie solely for authentication purposes. We do not use tracking or advertising cookies.
8. Children's Privacy
This service is intended for business use and is not directed at individuals under 18.
9. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated to active customers.
10. Contact
Questions about this policy can be sent to jay@nymbussecurity.com.