This Privacy Policy applies to the processing of personal information by NtelSec, Inc., a Delaware corporation with principal offices in Reston, Virginia ("NtelSec," "we," "us," or "our"), including on our websites at https://ntelsec.com and https://mc.ntelsec.com (the Mission Control portal), and our other online or offline offerings which link to, or are otherwise subject to, this Privacy Policy (collectively, the "Services"). This is the single privacy policy for all NtelSec offerings; upon its effective date it supersedes all earlier NtelSec and CUI Vault privacy policies.
Disclosure regarding Customer Data. This Privacy Policy does not apply to personal information that we process on behalf of our customers pursuant to a written agreement we have entered into with such customers ("Customer Data") — for example, content our customers place in the CUI Vault Enclave. Our customers' respective privacy notices or policies govern their collection and use of Customer Data, and our processing of Customer Data is governed by the contracts we have in place with our customers, not this Privacy Policy. Any questions or requests relating to Customer Data should be directed to the relevant customer.
1. Updates to This Privacy Policy
We may update this Privacy Policy from time to time. If we do, we'll let you know by posting the updated Privacy Policy on our website with a new "Last updated" date, and/or we may send other communications where required.
2. Personal Information We Collect
A. Personal information you provide to us directly
- Account information — name, business email address, phone number, job title, employment type, worksite, organization, and other information collected during account creation and onboarding.
- Purchases — details associated with your purchases. Payments are processed by our third-party payment processor (Stripe); we do not directly collect or store payment card numbers, but we may receive information associated with your payment (e.g., billing details and transaction confirmations).
- Electronic signatures — name, email, and related fields you provide when signing onboarding documents through our e-signature provider.
- Support and communications — information you send us in support tickets, email, or scheduling requests.
- Compliance artifacts you upload — documents you submit through the Mission Control portal (e.g., training certificates, evidence). Do not upload CUI to Mission Control; content processed inside a customer's enclave is Customer Data (see the carve-out above).
B. Personal information collected automatically
- Device and usage information — IP address, user agent, timestamps, pages visited, feature interactions, and error and security events (authentication attempts, MFA status, role changes, audit trails).
- Approximate location — we derive approximate location (country/region/city) from your IP address using a third-party geolocation service to detect sign-ins from new locations and protect your account.
- Cookies and similar technologies — see our Cookie Notice for the categories we use and your choices.
C. Personal information collected from third parties
- Payment processors — transaction confirmations and billing details.
- Scheduling and referral sources — if you book a call through our scheduling provider or arrive via a reseller or partner, we receive the contact details and booking information you provided there.
3. How We Use Personal Information
A. Provide the Services
- Managing your account and communicating with you;
- Providing access to areas, functionalities, and features of the Services, including provisioning accounts in the CUI Vault Enclave (Microsoft GCC High) and in our security awareness training platform;
- Answering requests for support;
- Processing payments and administering subscriptions and reseller relationships.
B. Administrative purposes
- Network and information security, fraud prevention, and detecting and responding to security incidents;
- Authenticating and verifying individual identities, including requests to exercise your rights under this Privacy Policy;
- Measuring interest and engagement in the Services and improving them;
- Creating de-identified and/or aggregated information (including usage trends). If we create or receive de-identified information, we will not attempt to re-identify it, unless permitted by, or required to comply with, applicable law;
- Auditing, enforcing our agreements and policies, and complying with our legal obligations, including cooperating with DoD, DCMA, C3PAOs, or your prime contractor where required by contract or law.
C. Marketing
We may use personal information to provide you with marketing materials as permitted by applicable law. You can opt out of marketing email at any time using the unsubscribe link in each message.
D. Automated decision making
Our processing of your personal information will not result in a decision based solely on automated processing that has a legal or similarly significant effect on you unless such a decision is necessary as part of a contract we have with you, we have your consent, or we are permitted by law to engage in such automated decision making.
4. How We Disclose Personal Information
A. Service providers and sub-processors
We disclose personal information to service providers that assist us with the provision of the Services, under contracts that restrict their use of it. These include:
- Hosting and infrastructure providers — U.S.-based cloud hosting for our websites and the Mission Control portal, and Microsoft Azure Government / Microsoft 365 GCC High for the CUI Vault Enclave (see Section 6);
- Payment and payout processing — Stripe (including Stripe Connect);
- Advertising measurement — Google (see Section 4.E and our Cookie Notice);
- Other service providers — providers of electronic signature, security awareness training, customer relationship management, transactional email delivery, call scheduling, bot protection, and IP geolocation services.
A complete, current list of our sub-processors is available to customers under their agreement or on request from privacy@ntelsec.com.
B. Government contracting parties
We may disclose personal information to prime contractors, C3PAOs, or Government authorities when required by contract or law, or to correct a material misrepresentation regarding use of the Services.
C. To protect us or others
We may access, preserve, and disclose information if we, in good faith, believe doing so is required or appropriate to comply with law enforcement or national security requests and legal process; protect your, our, or others' rights, property, or safety; enforce our policies or contracts; or assist with an investigation of suspected or actual illegal activity.
D. Business transfers
If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, purchase or sale of assets, or transition of service to another provider, your personal information may be disclosed or transferred as part of that transaction.
E. Advertising partners
On our marketing website we share limited identifiers (cookie identifiers, IP address, and conversion events) with Google to measure the effectiveness of our advertising. Under some U.S. state privacy laws this measurement may be considered "sharing" of personal information for cross-context behavioral advertising. We do not sell personal information for money. You can opt out of this sharing at any time via the "Do Not Sell or Share My Personal Information" link in our footer, the Cookie Settings link, or a Global Privacy Control (GPC) signal, which we honor.
5. Your Privacy Choices and Rights
- Email communications: use the unsubscribe link in any marketing email. You will continue to receive transactional and service messages.
- Cookies and advertising: manage preferences via the Cookie Settings link in our footer or your browser. See the Cookie Notice.
- Opt-out preference signals: we honor Global Privacy Control (GPC) signals as an opt-out of analytics and advertising cookies and of "sharing" as described in Section 4.E. We do not respond to other "Do Not Track" browser signals.
- State privacy rights: depending on your state of residence you may have rights to know/access, correct, delete, and port your personal information, and to opt out of certain processing. See our U.S. State Privacy Notice.
- GDPR/UK GDPR: where those laws apply, you may have rights of access, rectification, erasure, restriction, portability, and objection.
To exercise your rights, email privacy@ntelsec.com. We will verify your identity and respond within the timeframes required by applicable law. If we act as a processor/service provider for your organization, we may refer your request to your organization. When we honor a deletion request, we may retain limited records (for example, security audit logs and records of the deletion itself) where retention is required for security, legal compliance, or the establishment or defense of legal claims.
6. Data Location and Transfers
Personal information covered by this Privacy Policy (account, billing, portal, and marketing data) is hosted on commercial cloud infrastructure in the United States. Customer content in the CUI Vault Enclave is hosted exclusively in Microsoft Azure Government and Microsoft 365 GCC High facilities located in the United States and does not leave U.S. Government cloud regions. If limited cross-border processing of non-enclave personal information occurs, we apply appropriate safeguards (e.g., Standard Contractual Clauses and the UK Addendum) and restrict access to the minimum necessary.
7. Security and Incident Notification
We implement administrative, technical, and physical safeguards appropriate to the sensitivity of the information we process, including multi-factor authentication, encryption in transit and at rest, role-based access control, audit logging, and vulnerability management. The CUI Vault Enclave additionally uses FIPS 140-2 validated cryptographic mechanisms (TLS 1.2+ and AES-256) and NIST SP 800-88 Rev. 1 media sanitization.
If we become aware of a security incident affecting your personal information, we will notify you without undue delay, consistent with applicable law and our contracts with you.
8. Retention of Personal Information
We store personal information for as long as you use the Services, or as necessary to fulfill the purposes for which it was collected, provide the Services, resolve disputes, establish legal defenses, conduct audits, pursue legitimate business purposes, enforce our agreements, and comply with applicable law. To determine the appropriate retention period we consider legal requirements, the amount, nature, and sensitivity of the information, the purposes for which we process it, and whether we can achieve those purposes through other means. As guidelines, subject to legal holds and applicable law:
- Customer content: retained for your subscription term and returned and/or deleted following termination in accordance with your agreement;
- Security and access logs: retained for at least 12 months for security, forensics, and compliance;
- Billing and contract records: retained as required by tax and corporate law.
9. Children's Personal Information
The Services are not directed to children under 16, and we do not knowingly collect personal information from children.
10. Third-Party Websites and Applications
The Services may contain links to other websites and applications that we do not control. We encourage you to read the privacy policies of each website and application you interact with. We are not responsible for the privacy practices or content of third-party services.
11. Contact Us
If you have questions about our privacy practices or this Privacy Policy, or to exercise your rights:
NtelSec, Inc.
Attn: Privacy
12007 Sunrise Valley Drive, Suite 310
Reston, VA 20191, USA
privacy@ntelsec.comVersion 2.0 (July 14, 2026) — supersedes the CUI Vault Privacy Policy v1.0 (July 28, 2025).