Skip to content
← DefenseScore
Legal

Privacy Policy

v1.0 — Effective August 8, 2026
On this page
  1. 1. Scope.
  2. 2. Information we collect.
  3. 3. Information we do not want.
  4. 4. Customer Data and the Customer's own staff data — our role.
  5. 5. How we use information (controller role).
  6. 6. What we do NOT do with your information.
  7. 7. Sharing and disclosure.
  8. 8. Cookies and tracking.
  9. 9. Retention.
  10. 10. Security.
  11. 11. International transfers.
  12. 12. Your rights.
  13. 13. Regional disclosures.
  14. 14. Not Legal, Insurance, or Investment Advice.
  15. 15. Children's privacy.
  16. 16. Updates.
  17. 17. Contact.

Privacy Policy — DefenseScore Effective date: at product launch

This Privacy Policy describes how DefenseScore (operated by Ellis Intelligence LLC, a Colorado limited liability company, "we", "us", "our") collects, uses, and shares information when you visit defensescore.com or use the Service. For how we process Customer Data — including organization name, CAGE code, scope, SSP information, control-status entries, POA&M items — on behalf of our Customers, see §4 and the Data Processing Addendum at defensescore.com/dpa.

1. Scope.

This Policy covers: visitors to defensescore.com; Customer (business) account holders and their authorized users; and the Customer's own staff whose information reaches the Service through a Customer — but only to explain that, for that data, the Customer is the controller and we act as the Customer's processor (see §4 and §12).

2. Information we collect.

(a) Directly from Customers and visitors: organization name, CAGE code, account contact information, billing information (tokenized via Stripe — we do not store card numbers), and communications you send us. (b) Automatically: device and connection data, usage data, and the two strictly necessary cookies described in the Cookies and Tracking section. No advertising, analytics, or preference cookies. (c) Customer Data — processor role: organization name, CAGE code, scope, SSP information, control-status entries, POA&M items. We process this category only on the Customer's instructions to operate the Service (see §4).

3. Information we do not want.

The Service is designed to process DIB self-assessment (NIST SP 800-171 / SPRS / POA&M) compliance-tracking data. Do not collect or upload through the Service more than is necessary, and in particular do not upload: classified information; CUI beyond what the control-status fields require; personal financial account numbers. If we discover such information collected or uploaded inadvertently, we will notify the responsible Customer and request deletion, and may sanitize or delete it without prior notice if necessary to prevent privacy or regulatory exposure.

4. Customer Data and the Customer's own staff data — our role.

4.1 Processor / Service Provider. With respect to all the Customer's own staff data processed through the Service, the Customer is the controller (or "business") and we are the processor (or "service provider"). We process that data only on the Customer's documented instructions to provide the Service, and not for our own purposes. 4.2 Where we host the collection surface. Where the Service includes a Customer-configurable surface that collects information directly from the Customer's own staff, we host and render that surface and collect what is entered, but we do so as the Customer's processor and on the Customer's behalf; that person's relationship is with the Customer, not with DefenseScore. 4.3 Minimization. We collect and process only the categories of the Customer's own staff data described in §2(c), and request no more than the Service needs to operate; see §3 for the categories we affirmatively refuse to accept. 4.4 No sale, no share. We do not sell the Customer's own staff data or Customer Data, and we do not share it for cross-context behavioral advertising. 4.5 No training on Customer Data. We do not use Customer Data to train any model, fine-tune any shared model, or improve a Service used by other customers. 4.6 Tenant isolation. flat per-tenant — role is mapped separately at each layer of the chain. 4.7 Audit-log integrity. Where the Service maintains an audit or custody log of actions taken on the Customer's own staff data, that log is itself Customer Data under §2(c) and is available to the Customer's authorized users.

5. How we use information (controller role).

For marketing-site visitors and Customer account/billing contacts, we use information to provide, operate, secure and improve the Service; authenticate users and prevent unauthorized access; process payments and manage subscriptions; communicate about the Service, security incidents and Terms changes; send marketing communications to Customer billing contacts (opt-out anytime); produce aggregated, de-identified usage analytics; and comply with legal obligations. We do not sell personal information and do not share it for cross-context behavioral advertising.

6. What we do NOT do with your information.

We do not sell personal information and do not share it for cross-context behavioral advertising. We do not use Customer tenant data to train any model or to improve a Service used by other customers. We do not share tenant data with third parties except as described in §7 (subprocessors, legal compliance, business transfers). DefenseScore is not affiliated with, endorsed by, sponsored by, or officially recognized or supported by the U.S. Department of Defense, DCSA, the CMMC Accreditation Body, SPRS, or any other U.S. federal or state government agency. No surface of the Service uses a seal, badge, ribbon, watermark, or certificate-style graphic that could suggest such affiliation, endorsement, official recognition, predictive authority, or agency action.

7. Sharing and disclosure.

(a) Subprocessors at defensescore.com/subprocessors, operating under equivalent data-protection restrictions. (b) AI-assisted drafting (Anthropic, via the shared ellis_ai gateway) of control-gap finding narratives, POA&M entries, and readiness executive summaries — the SPRS score itself is computed deterministically in-app and is never model-generated — AI processing. Customer-entered assessment content submitted in the relevant feature: the NIST SP 800-171 control identifier and label, the current-implementation state text and any technology-stack list for a finding narrative, the weakness description for a POA&M entry, and the SPRS score, gap counts, point impact and remediation-hour totals for an executive summary (one inference call per generated narrative, POA&M entry, or executive summary; the organization's own name is replaced with a generic placeholder and is not sent) are sent to our AI/model provider to draft the finding narratives, POA&M entries, and executive summaries the Service then shows you. Before anything is sent, we perform best-effort masking of personally identifying values in the payload — including email, phone, government ID/SSN/EIN, and payment card or bank account numbers — and restore them only in the response shown to you; this is a control we build and enforce ourselves, not a retention commitment we rely on the provider to make. Our AI/model provider is Anthropic, PBC, listed on our subprocessor page at defensescore.com/subprocessors. (c) Subprocessor changes: we will notify the Customer's designated account contacts by email or in-product notice at least 30 days before adding or replacing a subprocessor, and will update the published list at the same time. Notice is deemed given when sent. A Customer may object on reasonable data-protection grounds within 30 days of the date notice is given; if a Customer timely objects, we will not use the new subprocessor to process that Customer's data while we work with the Customer to resolve the objection. (d) Legal compliance. (e) Business transfers, with notice to Customers. (f) With the Customer's written instruction. We do not share the Customer's own staff data or Customer Data with data brokers, advertising networks, or any third party for purposes outside operating the Service.

8. Cookies and tracking.

The DefenseScore website (defensescore.com) The Site does not use advertising or analytics cookies and does not load third-party trackers. Because we self-host fonts and front-end assets, your browser does not request resources from third-party servers as a result of visiting the Site. The DefenseScore application (app.defensescore.com) The application uses two cookies, both strictly necessary. Neither is used to advertise to you or to follow you across other websites. A session cookie, set by the application when you sign in. It keeps you signed in and protects forms against cross-site request forgery. It is removed when your session ends. The application cannot be used while it is blocked. A Cloudflare access cookie (CF_AppSession, and after sign-in CF_Authorization), set by Cloudflare when your browser first reaches app.defensescore.com — before you sign in. It runs the access-control check that sits in front of the application. Cloudflare provides this service to us as a processor and is listed on our subprocessor page. We do not set advertising cookies, retargeting or behavioral-tracking pixels, or cross-site tracking cookies of any kind, and we do not integrate with data brokers. We do not set analytics cookies, and we do not set preference or "functional" cookies. We do count a small number of anonymous events — for example, that a pricing section was viewed or a contact link was clicked. Those counts are kept as day-level totals only. They set no cookie, use no visitor identifier, and record no IP address, device information, or anything else about you. Your choices. You can block or delete cookies in your browser's settings, and the Site will work normally with every cookie blocked. Blocking the two application cookies means you will not be able to sign in to app.defensescore.com — that is the only thing that stops working. Changes and questions. If we start using a different kind of cookie, we change this section before we do, not after. Questions: privacy@ellisintel.com. Also published standalone at defensescore.com/cookies — identical language, both locations canonical.

9. Retention.

Customer account data: while active + up to 7 years for accounting and legal purposes. Customer Data: for the subscription term, available for export throughout; deleted within 30 days of a Customer's written deletion request. Absent such a request, upon termination we retain Customer Data for thirty (30) days following the effective date of termination, to preserve the evidentiary and statutory record-keeping basis for the underlying record, and will thereafter delete it within 30 days, except as required by law to retain. Minimized identity/contact data: retained only as long as needed for its purpose and not subject to the post-termination period above. Marketing data: until opt-out. Aggregated, de-identified data: indefinitely.

10. Security.

We use industry-standard technical and organizational measures designed to protect Customer data, including encryption and access controls. We do not claim SOC 2, ISO 27001, or any audited certification on this pre-launch product; we will update this section as our security program and independent assessments mature. No method of transmission or storage is perfectly secure. Breach notification to affected Customers per the DPA: without undue delay, and in any event within five (5) business days of becoming aware; provided that where the strictest applicable state breach-notification law or a sector-specific notice trigger requires a Customer to act on a shorter timeline, we will use commercially reasonable efforts to notify the Customer within whatever shorter period is necessary for the Customer to meet that deadline.

11. International transfers.

Processing occurs in the United States. DefenseScore is offered to United States customers; we do not currently accept customers established in the European Economic Area, the United Kingdom, or Switzerland, and the Service is not designed for the transfer of personal data from those jurisdictions. Before we accept any such customer we will publish the transfer mechanism that applies and update this section. If you access defensescore.com from outside the United States, the limited information described in §2(b) is processed in the United States.

12. Your rights.

Marketing-site visitors and Customer billing contacts: you have the rights afforded by applicable law to access, correct, delete, or port your information and to opt out of sale/share and certain processing. We do not sell or share this information. Email privacy@ellisintel.com or write to 1500 N Grant St, Ste N, Denver, CO 80203, USA; we will verify your request and respond within the time applicable law requires. the Customer's own staff whose data is processed by a Customer using DefenseScore: the Customer is the controller of that data. Direct your privacy request to that company, not to DefenseScore. We act only as the Customer's processor. We will cooperate with the Customer to fulfill valid access, deletion, correction, or opt-out requests per the DPA and applicable law, and we do not respond directly to data-subject requests unless the responsible Customer explicitly authorizes and instructs us to do so.

13. Regional disclosures.

California (CCPA/CPRA). California residents have the rights in §12. In the past 12 months we have collected the categories described in §2 and used them solely as described in §5. We have not "sold" or "shared" personal information as those terms are defined under the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020. You have the right not to be discriminated against for exercising these rights. Colorado (Colorado Privacy Act). Colorado residents have rights of access, correction, deletion, portability, and to opt out of targeted advertising, sale, and profiling in furtherance of decisions producing legal or similarly significant effects — we conduct none of these. You may appeal a declined request by replying to our response; if you have concerns you may contact the Colorado Attorney General. Other U.S. states. Residents of other states with comprehensive privacy laws have the rights those laws provide; use the contacts in §12. EEA / UK / Switzerland. To the extent Regulation (EU) 2016/679 (the General Data Protection Regulation) or the UK GDPR applies, our legal bases are our legitimate interests in operating and securing the Service and, where you contact us or hold an account, performance of a contract and our legitimate interest in responding. You have rights of access, rectification, erasure, restriction, portability and objection, and you may lodge a complaint with your local supervisory authority. See §11 for our current transfer posture.

14. Not Legal, Insurance, or Investment Advice.

DefenseScore is not affiliated with, endorsed by, sponsored by, or officially recognized or supported by the U.S. Department of Defense, DCSA, the CMMC Accreditation Body, SPRS, or any other U.S. federal or state government agency. DefenseScore is a software tool. It does not provide legal, insurance, investment, or certification advice, representation, or compliance assurance. Use of the Service does not guarantee compliance with any law or standard. Each Customer remains solely responsible for its own compliance. The Service's clocks, reminders, templates and generated documents are designed to assist; they are not a substitute for professional advice.

15. Children's privacy.

The Service is for business users and is not directed to individuals under 13. We do not permit account creation by anyone under 13, and we do not knowingly collect information from children under 13 through the marketing site or account flows; see §3. If we learn we have collected information from a child under 13, we will delete it promptly. A Customer that receives a request concerning a minor is the controller of that request.

16. Updates.

We will provide 30 days' email notice to Customer billing contacts for material changes to this Policy. Notice is deemed given when sent; the 30-day period runs from the send date, and failure to read a notice does not extend it.

17. Contact.

privacy@ellisintel.com — privacy matters. legal@ellisintel.com — other legal matters. 1500 N Grant St, Ste N, Denver, CO 80203, USA.


DefenseScore is a product of Ellis Intelligence LLC. This page is posted for transparency and is not legal advice. See also our Terms of Service. Questions about this document? Email legal@ellisintel.com.

Self-assessment tool — not a C3PAO. DefenseScore is a self-assessment software tool. It is not a C3PAO, not an assessment, not legal or compliance advice, and does not certify CMMC compliance.

You own your submission. The score and POA&M are computed from information you provide; you are solely responsible for what you submit to SPRS and for the accuracy of your self-assessment.

Rev 2 / DoD methodology. Computed to NIST SP 800-171 Rev 2 per the DoD Assessment Methodology v1.2.1; verify against the current DoD guidance for your contract.

Terms. As-is, no warranties; acceptance-on-use.

Not affiliated with the U.S. Government. DefenseScore is not affiliated with, endorsed by, sponsored by, or acting on behalf of the U.S. Department of Defense (DoD), the Defense Contract Management Agency (DCMA), the Supplier Performance Risk System (SPRS), NIST, or any other government agency or standards body, and nothing on this site or the Service is, or should be read as, an official communication, determination, or prediction by any of them.

© 2026 Ellis Intelligence LLC  ·  d/b/a DefenseScore  ·  Colorado single-member LLC  ·  Terms  ·  Privacy  ·  Cookies  ·  Acceptable Use  ·  DPA  ·  Subprocessors