SecBaseline
Privacy Policy
Privacy and data handling for the SecBaseline security and compliance suite.
- Effective date
- August 22, 2026
- Operated by
- Cyber Security Tech Solutions
SecBaseline is designed to collect and retain only the information reasonably needed to operate, secure, and improve the service. Cyber Security Tech Solutions does not sell personal information and does not use SecBaseline user content for third-party advertising.
Covered SecBaseline services
This document applies to the SecBaseline suite and the following websites and subdomains, together with related pages, APIs, authentication flows, and features that link to this document:
- secbaseline.com
- stig.secbaseline.com
- cis.secbaseline.com
- oscal.secbaseline.com
- ssp.secbaseline.com
- crosswalk.secbaseline.com
It also applies to future SecBaseline tools hosted under secbaseline.com unless a different policy or agreement is presented for that tool.
Who we are and what this policy covers
SecBaseline is a security baseline, compliance, remediation-planning, control-mapping, OSCAL, and System Security Plan tool suite operated by Cyber Security Tech Solutions. For purposes of applicable privacy law, Cyber Security Tech Solutions is the controller of personal information collected through SecBaseline unless we expressly state otherwise.
This Privacy Policy explains what information we collect, why we use it, when it may be disclosed, how long we keep it, the choices available to you, and how we protect it.
Our data handling principles
- Data minimization. We seek to collect only information needed to provide, secure, support, and maintain SecBaseline.
- Purpose limitation. We use information for the purposes described in this Policy and do not repurpose user content for unrelated advertising.
- Least practical retention. We retain information only for as long as reasonably necessary for the applicable purpose, subject to legal, security, backup, and dispute-resolution needs.
- Security by design. We use administrative, technical, and organizational safeguards appropriate to the nature of the information and the risks of processing.
- No sale of personal information. We do not sell personal information for money or other valuable consideration.
- No behavioral advertising. We do not use SecBaseline user content to build advertising profiles or serve cross-context behavioral advertising.
Information we collect
3.1 Information you provide directly
- Account and authentication information, such as your email address, account identifier, authentication status, and related account metadata when a SecBaseline feature supports sign-in.
- User content, such as STIG checklists, CKL or CKLB files, CIS assessment output, findings lists, benchmark excerpts you are authorized to use, system descriptions, control implementation narratives, SSP content, OSCAL content, POA&M-related content, validation inputs, and other material you choose to submit.
- Configuration and workspace information, such as project names, system names, control status, categorization selections, mappings, notes, and saved outputs where a feature allows you to save work.
- Support and contact information, including information you provide when you contact Cyber Security Tech Solutions, request support, submit feedback, or report a security issue.
3.2 Information collected automatically
- Basic device and connection information, such as IP address, browser type, operating system, device type, referring or exit pages, and approximate location derived from IP address.
- Service usage information, such as pages or features used, timestamps, request metadata, authentication events, error events, and performance information.
- Security and abuse-prevention data, such as rate-limit events, suspicious request indicators, authentication failures, and other records reasonably necessary to detect, prevent, or investigate misuse or attacks.
- Cookies or similar local technologies that are necessary for authentication, session management, security, user preferences, and core functionality. SecBaseline does not use these technologies for third-party behavioral advertising.
3.3 Information we ask you not to submit
SecBaseline is a public Internet service and is not represented as a classified information system, a FedRAMP-authorized service, a DoD Impact Level environment, or an environment approved for every regulated data type. Unless a specific SecBaseline feature is expressly designated in writing by Cyber Security Tech Solutions as approved for a particular data type, do not submit:
- Classified information or information marked for handling on classified systems.
- Controlled Unclassified Information (CUI), export-controlled technical data, ITAR-controlled data, or other government-restricted information.
- Passwords, private keys, API keys, access tokens, authentication secrets, or other live credentials.
- Protected health information, full payment-card data, Social Security numbers, or other highly sensitive regulated personal information.
- Malware, exploit payloads, or content whose possession, upload, or processing would violate law or third-party rights.
You are responsible for reviewing and, where appropriate, redacting or sanitizing content before submission. If you accidentally submit information that should not have been submitted, contact us promptly at the address in the Contact section.
How we use information
- Provide SecBaseline features, including parsing findings, explaining controls, mapping frameworks, validating OSCAL, rendering compliance artifacts, drafting or maintaining SSP content, and producing requested exports.
- Authenticate users, maintain sessions, save work where a feature supports persistence, and restore user-requested content.
- Operate, troubleshoot, debug, and improve reliability, usability, accessibility, and performance.
- Protect SecBaseline, our users, and Cyber Security Tech Solutions against fraud, abuse, malicious activity, unauthorized access, and security incidents.
- Respond to support requests, feedback, legal requests, and security reports.
- Comply with applicable law, enforce our Terms of Service, protect legal rights, and resolve disputes.
- Create de-identified or aggregated information that cannot reasonably be linked to an identified or identifiable person, and use that information for security, reliability, and product improvement.
We do not use your private SecBaseline user content to advertise to you or others. We do not sell user content or personal information.
AI-assisted processing
Some SecBaseline features use artificial intelligence to explain, organize, summarize, or draft content. Other functions, including certain calculations, classifications, schema checks, mappings, and transformations, may be performed deterministically in code. When an AI-assisted feature is used, the portions of your input reasonably necessary to perform the requested function may be transmitted to an AI service provider acting on our behalf.
We seek to minimize the content sent to service providers and to use provider settings and contractual terms appropriate for business or API use where available. AI-generated output may be inaccurate or incomplete and should not be treated as an authoritative compliance, legal, accreditation, or security determination.
How we disclose information
We may disclose information only as reasonably necessary in the following circumstances:
- Service providers. Hosting, content delivery, web application firewall, authentication, database, storage, email, support, AI inference, error monitoring, and security providers may process information on our behalf to provide their services to us.
- Legal and safety. We may disclose information when we reasonably believe disclosure is required by law, legal process, or a valid government request, or is necessary to protect the rights, property, safety, or security of users, Cyber Security Tech Solutions, or others.
- Business transactions. Information may be transferred as part of a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar transaction, subject to applicable law and appropriate confidentiality protections.
- At your direction. We may disclose information when you ask us to, such as when you create an export, use a sharing feature, connect an integration, or direct content to another service.
Third parties to whom we sell or may sell personal information: None. Cyber Security Tech Solutions does not sell SecBaseline personal information.
Third-party standards, sources, links, and services
SecBaseline references or interoperates with security standards, schemas, mappings, and third-party resources, including materials associated with DISA, DoD, NIST, and the Center for Internet Security. Those organizations and any linked third-party websites operate under their own privacy practices. SecBaseline is not affiliated with DISA, DoD, NIST, or the Center for Internet Security.
CIS Benchmark content is subject to the Center for Internet Security's licensing terms. You are responsible for ensuring that any CIS Benchmark content you submit to SecBaseline is obtained and used under a license or other authorization that permits your use.
Cookies and similar technologies
SecBaseline may use cookies, local storage, or similar technologies that are reasonably necessary for sign-in, session continuity, security, load balancing, fraud prevention, preferences, and core service functions. We do not use SecBaseline cookies for third-party behavioral advertising.
Your browser may allow you to block or delete cookies. Blocking cookies that are necessary for authentication or core functionality may prevent parts of SecBaseline from working.
Data retention
We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, including to provide the service, maintain account or saved workspace functionality, secure the service, comply with law, maintain appropriate business records, and establish, exercise, or defend legal claims.
- Transient processing. Inputs used by features designed for immediate processing may be held only long enough to complete the request and support short-term operational, security, or error-handling needs.
- Saved content. If you choose a feature that saves projects, SSPs, findings, mappings, or other workspace content, that content may be retained until you delete it, close the applicable account, or it is no longer reasonably necessary to provide the feature.
- Security logs. Security, access, and abuse-prevention logs may be retained for a reasonable period and may be kept longer when needed to investigate an incident, prevent abuse, satisfy legal obligations, or protect the service.
- Backups. Deleted information may remain in encrypted or access-restricted backups for a limited period until those backups are overwritten under normal retention cycles.
When retention is no longer reasonably necessary, we delete, de-identify, or otherwise dispose of the information in accordance with our operational and legal requirements.
Security
Cyber Security Tech Solutions uses reasonable administrative, technical, and organizational safeguards intended to protect the confidentiality, integrity, and availability of information processed by SecBaseline. Safeguards may include access controls, encryption in transit, secure development practices, rate limiting, network and application protections, logging, vulnerability management, and least-privilege practices where appropriate.
No Internet service, storage system, authentication mechanism, or transmission method can be guaranteed to be completely secure. Accordingly, we cannot guarantee that unauthorized access, loss, misuse, or disclosure will never occur.
Your privacy rights and choices
Depending on where you live and the laws that apply, you may have rights concerning your personal information. These may include the right to request access, confirmation, correction, deletion, portability, or a copy of certain information, and the right to opt out of certain sales, targeted advertising, or profiling.
SecBaseline does not sell personal information or use it for third-party behavioral advertising. Where applicable law provides a right to revoke consent, you may also withdraw consent for processing that is based on consent.
To exercise a privacy right, email info@cybersecuritytechsolutions.com with the subject line "Privacy Request - SecBaseline". We may need to verify your identity and authority before completing a request. Authorized agents may submit requests where permitted by law, subject to verification requirements.
We will not unlawfully discriminate against you for exercising an applicable privacy right. If applicable law provides a right to appeal a decision on a privacy request, you may appeal by replying to our response and stating that you are requesting an appeal.
Rhode Island privacy notice
Cyber Security Tech Solutions operates from Rhode Island and provides this notice in a manner intended to address the Rhode Island Data Transparency and Privacy Protection Act where it applies.
- Controller: Cyber Security Tech Solutions.
- Categories of personal data collected: account and authentication information; user-submitted security and compliance content; saved workspace or configuration information; support and contact information; device, usage, connection, security, and error data; and necessary cookie or local-storage data.
- Purposes: providing and securing SecBaseline; authentication and saved workspace functionality; support; reliability and product improvement; legal compliance; and protection of rights and security.
- Third parties to whom personal information is sold or may be sold: None.
- Contact method for privacy requests: info@cybersecuritytechsolutions.com.
Certain rights and controller obligations under Rhode Island law apply only when statutory thresholds or other conditions are met. Nothing in this Policy limits any right you have under applicable law.
International users
SecBaseline is operated from the United States. If you access the service from another country, your information may be processed in the United States or other countries where our service providers operate. Where required by applicable law, we will use an appropriate legal basis and transfer mechanism for processing or transferring personal information.
For users in jurisdictions that require a legal basis for processing, our bases may include performance of a contract, legitimate interests in operating and securing the service, compliance with legal obligations, and consent where consent is required.
Children
SecBaseline is intended for cybersecurity, information technology, compliance, audit, and related professional or educational use. It is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided personal information to SecBaseline, contact us so we can review and take appropriate action.
Security research and vulnerability reports
If you believe you have identified a security vulnerability affecting SecBaseline, please report it responsibly to Cyber Security Tech Solutions. Do not access, retain, alter, or disclose another user's data, disrupt the service, perform destructive testing, or exceed the minimum testing needed to demonstrate a potential issue.
Changes to this Privacy Policy
We may update this Privacy Policy to reflect changes to SecBaseline, our data practices, service providers, legal requirements, or security practices. The effective date at the top of the Policy indicates when the current version became effective. If a change materially affects how we use personal information, we will provide notice as required by applicable law.
Relationship to the Terms of Service
Your use of SecBaseline is also governed by the SecBaseline Terms of Service. If there is a conflict between this Privacy Policy and the Terms of Service concerning the handling of personal information, this Privacy Policy controls to the extent of that conflict.
Contact
Cyber Security Tech Solutions
Rhode Island, United States
- Email: info@cybersecuritytechsolutions.com
- Phone: (401) 585-2570
- Website: www.cybersecuritytechsolutions.com