Security and Trust — Sylvan Assurance, LLC
Last reviewed: 2026-07-06. Reviewed every quarter, and after any real control change. Contact: support@sylvanassurance.com.
1. Company at a glance
Sylvan Assurance, LLC is a Vermont limited liability company. We publish downloadable compliance and security toolkits. Our buyers are small product teams and incident-response operators. We also serve fractional Chief Information Security Officers and Managed Service Providers. We do not run a multi-tenant Software-as-a-Service product. Our deliverables are self-contained PDF and Excel files. Customers download them once and own them.
Our website is a static site served from Cloudflare Pages. Payments are handled by Lemon Squeezy as Merchant of Record. Our free-guide email is handled by our email-service provider (see §5).
We sell downloadable files. We do not run a service that processes customer data. So the questions a typical Trust Profile answers apply to us differently than to a SaaS vendor. Those questions include "where is my data", "who can access it", and "what is your uptime commitment". The sections below answer them in the form that fits our model.
2. Compliance and certifications
Currently certified or attested
Sylvan Assurance holds no third-party certifications at this time. At our current scale, demand does not yet justify the cost of a System and Organization Controls 2 (SOC 2) audit. The same is true for an International Organization for Standardization (ISO)/IEC 27001 certificate. We will not claim certifications we do not hold.
Aligned without certification
- General Data Protection Regulation (Regulation (EU) 2016/679). As a controller, we process very little: free-guide email addresses (opt-in) and support email. Given the volume, we act as our own Data Protection Officer for now. Our Privacy Policy at
sylvanassurance.com/privacydescribes our processing in detail. Rights requests can be sent tosupport@sylvanassurance.com. - National Institute of Standards and Technology Cybersecurity Framework — Identify and Protect functions. Our infrastructure choices reflect a deliberate protect-first posture. Cloudflare Pages. Server-side traffic counts. No client-side tracking. No behavioural analytics. No customer data stored on our systems. The Detect, Respond, and Recover functions are narrow in scope. There is very little to detect, respond to, or recover from. No customer database. No operational service. No production runtime executing customer code.
- Privacy-first by design. Our distinctive stance: every free assessment we publish runs entirely in the visitor's browser. We never receive assessment answers. This is not a marketing claim that can be quietly walked back; the architecture enforces it. The assessment pages have no telemetry endpoints, no analytics scripts, and no form submissions for answer data. The Content Security Policy permits no outside script sources. The only data we collect is the email address a visitor chooses to give us for the free guide.
Frameworks we have evaluated and explicitly do not align to
We are transparent about what we are not doing.
- Software Bill of Materials (SBOM) production for our toolkit content. Our deliverables are PDFs and Excel files, not software. An SBOM does not meaningfully apply.
- Continuous penetration testing. Our public attack surface is a static website. We rely on Cloudflare's infrastructure protections and our payment processor's controls. We will look again if our architecture grows beyond static content.
3. Identity, access, and authentication
Customers do not create accounts or passwords with us. Paid assessment apps unlock in the browser with the licence key from the purchase receipt — key activation rather than a login. The documents themselves are downloads you keep. The questions in this section therefore apply to our internal admin access.
All admin access to Sylvan Assurance systems requires Multi-Factor Authentication. That covers the domain registrar, Cloudflare, the payment processor, the email provider, and corporate email. We use either a hardware security key on the FIDO2 / WebAuthn passwordless standard (preferred) or a Time-based One-Time Password app. One-time passwords sent by text message are switched off wherever the provider allows it.
We use a password manager with end-to-end encrypted storage for login details. Recovery codes are stored offline.
Customer sign-in for purchases is handled by our payment processor (Lemon Squeezy). Our email-service provider handles sign-in for email subscriptions. Sylvan Assurance does not hold customer passwords. The only customer credential we issue is the purchase licence key that unlocks the assessment app in your browser.
Access reviews happen at every quarter-end. Given the small team, the review is broad. It covers all active credentials, the providers' access logs, and any active sessions on each platform. Contributors are added and removed under a documented workflow.
4. Data handling and encryption
This section answers what we do with the small amount of data we hold.
What we collect
- Email addresses given to us by choice, when a visitor finishes a free assessment and asks for the related free guide.
- Purchase information (name, email address, billing country, order reference) for paid-toolkit purchases. Lemon Squeezy processes it as Merchant of Record.
- Support correspondence sent to
support@sylvanassurance.com. - Aggregate website traffic counts (page views and country, with nothing that identifies a person) via Cloudflare's server-side counts. No scripts added to the page, no cookies.
What we explicitly do not collect
- Free-assessment answers. Every free assessment runs entirely in the visitor's browser. Answers are scored on the device and shown to the visitor. They are never sent to us or to any third party.
- Behavioural analytics. We do not use Google Analytics, Mixpanel, Heap, FullStory, Hotjar, or any similar client-side analytics tool.
- Tracking cookies. The site sets no advertising or tracking cookies. The only cookies set are strictly necessary ones in the payment-processor checkout.
- Cross-site tracking. We do not embed pixels, web beacons, or scripts that would let third parties follow visitors across other sites.
- Sensitive categories. We do not collect biometric data or government ID numbers. We do not collect racial or ethnic origin, religious beliefs, political opinions, or trade-union membership. We do not collect sexual-orientation, criminal-record, or health data.
- Data about children. Our services are not aimed at, and not knowingly used by, anyone under 16.
Encryption at rest
Free-guide email addresses are stored at our email-service provider. The provider encrypts subscriber data at rest with Advanced Encryption Standard 256-bit. Purchase information is stored at Lemon Squeezy and encrypted at rest per their documented controls. Support email is stored at our mailbox provider with mailbox-level encryption.
We do not run our own database, file server, or object store. Outside the three provider systems above, there is no stored customer data under Sylvan Assurance's control.
Encryption in transit
All web traffic to sylvanassurance.com is served over Transport Layer Security version 1.2 or higher. Version 1.3 is supported and preferred. HTTP Strict Transport Security is enforced. Connections to our providers' Application Programming Interfaces are encrypted the same way.
Data retention
- Free-guide email addresses. Kept while the subscriber stays opted in. Removed within seven days of unsubscribe.
- Purchase records. Kept for seven years to meet US tax-record rules. Once that window passes, the parts that identify a person can be anonymised on request.
- Support email. Kept for two years from last contact, then deleted.
5. Hosting and sub-processors
Hosting
The website at sylvanassurance.com is hosted on Cloudflare Pages. Pages are served from Cloudflare's global edge. Sylvan Assurance runs no origin server of its own.
Sub-processors
We publish our current sub-processor list because we have nothing to hide. The list is also short.
| Sub-processor | Service | Data categories processed | Jurisdiction | Agreement |
|---|---|---|---|---|
| Cloudflare, Inc. | Website hosting, edge delivery, and server-side traffic counts | Aggregate request data (nothing that identifies a person beyond country) | United States | Cloudflare Subscription Agreement + Data Processing Addendum |
| Lemon Squeezy (LMSQUEEZY LLC) | Payment processing as Merchant of Record | Purchase information (name, email, billing country, order reference) | United States | Lemon Squeezy Merchant Agreement. Lemon Squeezy is itself the Merchant of Record. It handles US sales tax, EU/UK VAT (Value-Added Tax), and AU/CA GST (Goods and Services Tax) collection and payment |
| MailerLite (email-service provider) | Stores and sends the free-guide emails; runs the automated email series | Email address; open and click events | European Union | MailerLite Data Processing Agreement |
Mailbox provider (current: iCloud+ for support@sylvanassurance.com) | Inbound and outbound support email | Email contents and metadata | United States | Apple iCloud terms |
This list can change — an addition, a removal, or a move of jurisdiction. If it does, we will announce it here. We will give 30 days' notice when reasonably possible.
6. Incident response
Sylvan Assurance keeps a written Incident Response Plan adapted from the First 4 Hours toolkit we publish. Using our own toolkit has been useful: it surfaced two small improvements, both folded back into the Solo Edition.
The plan covers spotting the problem, containing it, removing it, recovering, and the review afterwards. Given the small team, the incident commander, communications, and technical lead roles are held in-house. Documented escalation paths exist. For legal questions: a Vermont-licensed attorney. For incidents on a sub-processor's side: that sub-processor's incident-response team. For personal-data breaches affecting people in the European Union: the data-protection regulator (the GDPR supervisory authority).
The plan is reviewed yearly and tabletop-tested yearly. The next scheduled tabletop is 2027-05-30, or the first real incident, whichever comes first.
Breach notification commitment
Once we confirm a security incident that touches customer data, we commit to telling the affected customers without undue delay. Where people in the European Union are affected and the law requires it, we will notify the right regulator. That notice happens within the 72-hour window in Article 33 of the General Data Protection Regulation. The GDPR 72-Hour Battle-Card we publish (free) describes our own steps as well as the legal ones. They are the same steps.
Sylvan Assurance does not host customer data on its own systems. So the most likely breach scenarios involve our sub-processors. In every such case, our role is simple. Receive the sub-processor's incident notice. Assess the impact on our customers. Notify those customers, and any regulator that applies.
Security incident reporting
Anyone — researchers, customers, others — can report a possible security issue to security@sylvanassurance.com. Use the subject line "Security report". Machine-readable contact details are published at /.well-known/security.txt (per RFC 9116). We acknowledge security reports within two business days. We follow a coordinated disclosure process. We agree reasonable disclosure timelines up front; 90 days is our default. We will publicly credit the reporter when reasonable, if the reporter wants credit.
We do not currently pay money for security reports. Credit and a hand-written thank-you are what we can offer at this time.
7. Vulnerability and security testing
Penetration testing
We do not currently hire a third party to penetration-test the static corporate website. The attack surface is small: a static site behind Cloudflare, with no server-side application code under our control. The cost does not currently justify the engagement. We will look again each year on the LLC's anniversary. We will also look whenever the architecture changes in a real way (for example, adding a dynamic application).
Dependency scanning
The website uses a small amount of first-party JavaScript for progressive enhancement. For example, the guided picker on the home page points visitors to the right starting point. It is written by hand and served as a same-origin file, with no third-party libraries, no package manager, and no build or bundler step beyond a static wrangler pages deploy. So there is no dependency tree to scan. A site-wide Content-Security-Policy enforces this: script-src 'self' permits only same-origin scripts and blocks inline and third-party JavaScript across every page, including the free assessments.
Our internal toolchain (Python, and Node.js for utility scripts) is kept up to date. We update within seven days of any critical disclosure affecting a component we actively use.
Infrastructure scanning
Our infrastructure footprint is the static-site bucket on Cloudflare Pages, our domain registrar, and our provider accounts. Cloudflare publishes its own security and compliance posture. It holds System and Organization Controls 2 (SOC 2), International Organization for Standardization (ISO)/IEC 27001, and others. We rely on those for the underlying layer. We periodically check our Cloudflare account settings against the hardening checklist Cloudflare publishes for Pages projects.
8. Business continuity
Our service is keeping sylvanassurance.com up. It also means keeping purchased toolkits — and the documents inside them — open to their owners.
| Service | Recovery Time Objective | Recovery Point Objective |
|---|---|---|
| Corporate website (Cloudflare Pages) | Inherits Cloudflare's published availability target. The site can be redeployed from source within 30 minutes if needed | Negligible — the whole site source lives in version control; the "data" to recover is just the static site |
| Access to purchased toolkits and their documents | Toolkit access inherits Cloudflare's published uptime target. Licence activation inherits Lemon Squeezy's. If either is down, we can send documents by email on request | Negligible — the files are static and easy to copy |
| Free-guide email delivery | Inherits the email provider's availability; manual delivery is the fallback | Usually one business day (in-flight automation may need a manual restart) |
No Sylvan Assurance system holds the only copy of any customer data. So the usual Recovery Point Objective sums do not apply in the normal sense.
Backups: the website source is held in encrypted version control on a workstation with full-disk encryption, plus an encrypted off-machine backup. Toolkit source files and build scripts are backed up the same way. The free-guide email list is exported from the provider monthly and stored in the same encrypted backup.
9. Security contact
For security questions, reports of weak spots, or requests for more detail:
Email: security@sylvanassurance.com (subject: "Security report")
Machine-readable contact: /.well-known/security.txt (RFC 9116)
Vulnerability Disclosure Policy: Coordinated disclosure, with a 90-day default timeline. Public credit on request. No cash rewards at this time.
Response commitment: We acknowledge security reports within two business days. We aim to classify severity within about five business days. We send updates at least every 14 days.
For procurement and questionnaire requests, contact support@sylvanassurance.com. We respond using the same TrustReady-format answer-bank entries we sell to others. That is a live demonstration of how the toolkit performs.
Trust portal access (optional)
We do not currently run a separate trust portal behind a Non-Disclosure Agreement. Everything we can reasonably say in public is said above. If a prospective customer needs detail that does not belong in a public document, contact support@sylvanassurance.com. We will work out the right form for it, case by case.
Recent updates (change log — most recent five)
- 2026-07-17: Security reporting moved to a dedicated
security@sylvanassurance.comaddress, separate from customer support, and asecurity.txtfile published — in line with the July 2026 joint coordinated-vulnerability-disclosure guidance from CISA, the NSA, JPCERT/CC, NCSC-NL, and NCSC-UK. - 2026-07-06: Section 7 updated — the site now uses first-party same-origin JavaScript files for progressive enhancement, with no third-party dependencies.
- 2026-06-28: Email-service provider: MailerLite (EU). Privacy Policy and sub-processor table updated.
- 2026-05-30: Trust Profile reviewed and republished.
- 2026-05-30: Sub-processor list — four entries: Cloudflare, Lemon Squeezy, the email provider, and the mailbox provider.
Footer
Trust Profile last reviewed: 2026-07-06
Next scheduled review: 2026-10-06
Document owner: Sylvan Assurance leadership (Security & Trust function)
Executive sponsor: Sylvan Assurance leadership
This Trust Profile is a public statement of Sylvan Assurance's security posture as of the last review date. It is informational, not contractual. Specific contractual commitments are made in our Terms of Use, Refund Policy, and Privacy Policy, all published on
sylvanassurance.com. Where we reference frameworks, we describe alignment, not certification. That applies to the General Data Protection Regulation and the National Institute of Standards and Technology Cybersecurity Framework. We hold no third-party certifications at this time and will not claim any we do not hold.