This policy covers the CMMC Level 1 readiness assessment at this site. It describes exactly what the assessment collects, where it goes, and how to get it removed. Effective August 3, 2026.
GRYHAT Cybersecurity, Mission Viejo, California. We provide CMMC training, readiness assessments, and compliance consulting to defense contractors. You can reach us atandy@gryhat.com or(714) 794-2803.
Only what the assessment actually asks for, plus what your browser sends:
No payment details, no government identifiers, and no account credentials. This form never asks for them and you should never enter them.
Do not paste actual Federal Contract Information, Controlled Unclassified Information, or system configuration details into the assessment. It asks only about the presence or absence of practices. It does not need, want, or handle the regulated data itself.
We do not sell your personal information for money, and we do not use it for automated decision-making that produces legal effects. Your score is a readiness indicator you asked for, not a decision made about you.
We advertise this assessment on Meta and LinkedIn. When you complete the assessment or request a report, those platforms are told that a conversion happened so we can tell which ads are working. Under California law that counts as “sharing” for cross-context behavioral advertising, and we would rather say so plainly than hide behind the fact that no money changes hands.
Two things limit it. First, we send conversion events and identifiers — never your assessment answers, your score, or which practices you failed. Those stay with us. Second, if your browser sends a Global Privacy Control signal, our tag manager does not load at all, so no advertising or measurement tags run for you. Most privacy browsers and extensions send GPC automatically. You can also opt out by emailing us.
Your submission is stored in a private, non-public blob store. It is not published, not listed, and not indexed. These are the only third parties that touch it:
| Processor | What they do | Location |
|---|---|---|
| Vercel | Hosting and private blob storage for assessment submissions | United States |
| Resend | Delivery of your gap report and related email | United States |
| PostHog | Product analytics — which steps of the assessment are completed | United States |
| Google Tag Manager | Loads our measurement and advertising tags | United States |
| Meta, LinkedIn | Advertising measurement — told that a conversion happened, so we can see which ads work | United States |
| Cal.com | Scheduling, only if you choose to book a call | United States |
We will also disclose information where we are legally required to, or to protect our rights or the security of the service.
Your gap report lives at a private URL containing a long random token. It is marked no-index so search engines do not list it, but anyone you forward the link to can open it — that is deliberate, so you can send it to your prime or your IT provider. Treat the link the way you would treat the report itself. Ask us and we will revoke it.
Until you ask us to delete it, or twenty-four months after our last contact with you, whichever comes first. Deletion requests are honored regardless of where that clock is.
Under the CCPA as amended by the CPRA, California residents have the right to know what personal information we hold, to request a copy of it, to correct it, and to have it deleted. You also have the right to opt out of the sharing described under “Advertising and measurement” above, and the right not to be discriminated against for exercising any of these rights.
We do not collect sensitive personal information as the CPRA defines it. In the preceding twelve months we have collected the identifiers, commercial information, and internet activity described above, from you directly, for the business purposes listed above.
To exercise any right, email andy@gryhat.com with the address you used. We will verify the request by replying to that address and will respond within 45 days. We honor Global Privacy Control signals where your browser sends them.
Submissions are transmitted over TLS and stored in a private blob store that is not publicly readable. Access is limited to GRYHAT personnel who need it. No system is perfect, and we will not claim otherwise — if we learn of a breach affecting your information, we will notify you as required by California law.
This is a business service and is not directed to anyone under 18. We do not knowingly collect information from minors.
If this policy changes materially we will update the effective date above and, where the change affects information we already hold, notify the address you gave us.
GRYHAT Cybersecurity · Mission Viejo, California
andy@gryhat.com ·(714) 794-2803