How we protect contractor data.
MAS Pilot processes government contractor data. We take that seriously.
MAS Pilot is in controlled early access. The statements below describe what is implemented today on the marketing site and Wave 1/2 testing environment, and what is planned for the production platform. We are explicit about the distinction because contractor data deserves that clarity.
TLS 1.2+ everywhere
maspilot.io is served over HTTPS through Cloudflare with TLS 1.2 or 1.3. HTTP requests are upgraded. HSTS is set for 2 years with includeSubDomains; preload.
CSP + anti-framing + COOP/CORP
Content Security Policy, X-Frame-Options: DENY, X-Content-Type-Options: nosniff, Referrer-Policy, Cross-Origin-Opener-Policy, and a locked-down Permissions-Policy are enforced on every page.
Only what we need to contact you
The waitlist form collects name, phone, work email, company, contract-type category, and an optional 12-character UEI (Unique Entity ID). We do not collect pricing data or cardholder information on the marketing site.
Wave 3 waitlist submissions are handled by a first-party Cloudflare Worker on maspilot.io and stored in our managed Supabase database, hosted in a US region. We do not use a third-party form service. Applicant confirmation and internal notification emails are sent through Resend. During the current cut-over, a legacy Google Apps Script mirror to a private Google Sheet may also receive a copy; it is retired once the migration is complete. A signed Data Processing Addendum will be in place before any contractor pricing or pre-award data is collected.
The marketing form is protected by Cloudflare Turnstile, a same-origin check, edge rate limiting, and honeypot and timing heuristics to deter automated abuse.
AES-256 for stored data
All stored account data and compliance results will be encrypted at rest using provider-managed keys. Transactional pricing data uploaded for checking is designed to be processed in-memory and not persisted beyond the checking session.
Least-privilege, MFA, audit logs
Role-based access, MFA for administrative roles, and application-level audit logs for contractor-impacting actions. Independent attestation (SOC 2 Type II) is on the roadmap prior to general availability.
Third-party pen test + attestation
Annual third-party penetration testing and a SOC 2 readiness assessment are planned before production launch. Customers evaluating an enterprise pilot can request the current status under NDA.
If you've found a security issue in anything maspilot.io serves, please report it responsibly before public disclosure. We aim to acknowledge within 3 business days. Safe-harbor: good-faith research — no data destruction, no social engineering, no DoS, no targeting of individual users — will not be pursued legally.
PGP / signed reports: available on request. A machine-readable disclosure policy is published at /.well-known/security.txt.
[email protected] →MAS Pilot's outputs — compliance findings, IFF calculations, SRP exports, FAR/GSAM clause analyses, compliance scores — are analytical software outputs, not legal advice. Contractors remain solely responsible for submission accuracy, certifications under GSAR 552.238-80, and all GSAM and FAR compliance. Consult qualified counsel before relying on any output for a contractual or regulatory submission.