Refresh 31 made TDR mandatory for all MAS SINs — grace period ends Dec 31, 2026. Request Wave 3 access →
// Security

How we protect contractor data.

MAS Pilot processes government contractor data. We take that seriously.

// Pre-launch posture

MAS Pilot is in controlled early access. The statements below describe what is implemented today on the marketing site and Wave 1/2 testing environment, and what is planned for the production platform. We are explicit about the distinction because contractor data deserves that clarity.

// Implemented today (as of deployment of this page)
Transport

TLS 1.2+ everywhere

maspilot.io is served over HTTPS through Cloudflare with TLS 1.2 or 1.3. HTTP requests are upgraded. HSTS is set for 2 years with includeSubDomains; preload.

Browser hardening

CSP + anti-framing + COOP/CORP

Content Security Policy, X-Frame-Options: DENY, X-Content-Type-Options: nosniff, Referrer-Policy, Cross-Origin-Opener-Policy, and a locked-down Permissions-Policy are enforced on every page.

Minimal collection

Only what we need to contact you

The waitlist form collects name, phone, work email, company, contract-type category, and an optional 12-character UEI (Unique Entity ID). We do not collect pricing data or cardholder information on the marketing site.

// Current waitlist infrastructure — disclosed

Wave 3 waitlist submissions are handled by a first-party Cloudflare Worker on maspilot.io and stored in our managed Supabase database, hosted in a US region. We do not use a third-party form service. Applicant confirmation and internal notification emails are sent through Resend. During the current cut-over, a legacy Google Apps Script mirror to a private Google Sheet may also receive a copy; it is retired once the migration is complete. A signed Data Processing Addendum will be in place before any contractor pricing or pre-award data is collected.

The marketing form is protected by Cloudflare Turnstile, a same-origin check, edge rate limiting, and honeypot and timing heuristics to deter automated abuse.

// Planned for production platform (not yet live — do not rely on these for any submission)
Planned · Encryption at rest

AES-256 for stored data

All stored account data and compliance results will be encrypted at rest using provider-managed keys. Transactional pricing data uploaded for checking is designed to be processed in-memory and not persisted beyond the checking session.

Planned · Access controls

Least-privilege, MFA, audit logs

Role-based access, MFA for administrative roles, and application-level audit logs for contractor-impacting actions. Independent attestation (SOC 2 Type II) is on the roadmap prior to general availability.

Planned · Verification

Third-party pen test + attestation

Annual third-party penetration testing and a SOC 2 readiness assessment are planned before production launch. Customers evaluating an enterprise pilot can request the current status under NDA.

// Reporting a vulnerability

If you've found a security issue in anything maspilot.io serves, please report it responsibly before public disclosure. We aim to acknowledge within 3 business days. Safe-harbor: good-faith research — no data destruction, no social engineering, no DoS, no targeting of individual users — will not be pursued legally.

PGP / signed reports: available on request. A machine-readable disclosure policy is published at /.well-known/security.txt.

[email protected]
// Notice — not legal advice

MAS Pilot's outputs — compliance findings, IFF calculations, SRP exports, FAR/GSAM clause analyses, compliance scores — are analytical software outputs, not legal advice. Contractors remain solely responsible for submission accuracy, certifications under GSAR 552.238-80, and all GSAM and FAR compliance. Consult qualified counsel before relying on any output for a contractual or regulatory submission.