Security and Trust — Sylvan Assurance, LLC

Last reviewed: 2026-07-06. Reviewed every quarter, and after any real control change. Contact: support@sylvanassurance.com.


1. Company at a glance

Sylvan Assurance, LLC is a Vermont limited liability company. We publish downloadable compliance and security toolkits. Our buyers are small product teams and incident-response operators. We also serve fractional Chief Information Security Officers and Managed Service Providers. We do not run a multi-tenant Software-as-a-Service product. Our deliverables are self-contained PDF and Excel files. Customers download them once and own them.

Our website is a static site served from Cloudflare Pages. Payments are handled by Lemon Squeezy as Merchant of Record. Our free-guide email is handled by our email-service provider (see §5).

We sell downloadable files. We do not run a service that processes customer data. So the questions a typical Trust Profile answers apply to us differently than to a SaaS vendor. Those questions include "where is my data", "who can access it", and "what is your uptime commitment". The sections below answer them in the form that fits our model.


2. Compliance and certifications

Currently certified or attested

Sylvan Assurance holds no third-party certifications at this time. At our current scale, demand does not yet justify the cost of a System and Organization Controls 2 (SOC 2) audit. The same is true for an International Organization for Standardization (ISO)/IEC 27001 certificate. We will not claim certifications we do not hold.

Aligned without certification

Frameworks we have evaluated and explicitly do not align to

We are transparent about what we are not doing.


3. Identity, access, and authentication

Customers do not create accounts or passwords with us. Paid assessment apps unlock in the browser with the licence key from the purchase receipt — key activation rather than a login. The documents themselves are downloads you keep. The questions in this section therefore apply to our internal admin access.

All admin access to Sylvan Assurance systems requires Multi-Factor Authentication. That covers the domain registrar, Cloudflare, the payment processor, the email provider, and corporate email. We use either a hardware security key on the FIDO2 / WebAuthn passwordless standard (preferred) or a Time-based One-Time Password app. One-time passwords sent by text message are switched off wherever the provider allows it.

We use a password manager with end-to-end encrypted storage for login details. Recovery codes are stored offline.

Customer sign-in for purchases is handled by our payment processor (Lemon Squeezy). Our email-service provider handles sign-in for email subscriptions. Sylvan Assurance does not hold customer passwords. The only customer credential we issue is the purchase licence key that unlocks the assessment app in your browser.

Access reviews happen at every quarter-end. Given the small team, the review is broad. It covers all active credentials, the providers' access logs, and any active sessions on each platform. Contributors are added and removed under a documented workflow.


4. Data handling and encryption

This section answers what we do with the small amount of data we hold.

What we collect

What we explicitly do not collect

Encryption at rest

Free-guide email addresses are stored at our email-service provider. The provider encrypts subscriber data at rest with Advanced Encryption Standard 256-bit. Purchase information is stored at Lemon Squeezy and encrypted at rest per their documented controls. Support email is stored at our mailbox provider with mailbox-level encryption.

We do not run our own database, file server, or object store. Outside the three provider systems above, there is no stored customer data under Sylvan Assurance's control.

Encryption in transit

All web traffic to sylvanassurance.com is served over Transport Layer Security version 1.2 or higher. Version 1.3 is supported and preferred. HTTP Strict Transport Security is enforced. Connections to our providers' Application Programming Interfaces are encrypted the same way.

Data retention


5. Hosting and sub-processors

Hosting

The website at sylvanassurance.com is hosted on Cloudflare Pages. Pages are served from Cloudflare's global edge. Sylvan Assurance runs no origin server of its own.

Sub-processors

We publish our current sub-processor list because we have nothing to hide. The list is also short.

Sub-processorServiceData categories processedJurisdictionAgreement
Cloudflare, Inc.Website hosting, edge delivery, and server-side traffic countsAggregate request data (nothing that identifies a person beyond country)United StatesCloudflare Subscription Agreement + Data Processing Addendum
Lemon Squeezy (LMSQUEEZY LLC)Payment processing as Merchant of RecordPurchase information (name, email, billing country, order reference)United StatesLemon Squeezy Merchant Agreement. Lemon Squeezy is itself the Merchant of Record. It handles US sales tax, EU/UK VAT (Value-Added Tax), and AU/CA GST (Goods and Services Tax) collection and payment
MailerLite (email-service provider)Stores and sends the free-guide emails; runs the automated email seriesEmail address; open and click eventsEuropean UnionMailerLite Data Processing Agreement
Mailbox provider (current: iCloud+ for support@sylvanassurance.com)Inbound and outbound support emailEmail contents and metadataUnited StatesApple iCloud terms

This list can change — an addition, a removal, or a move of jurisdiction. If it does, we will announce it here. We will give 30 days' notice when reasonably possible.


6. Incident response

Sylvan Assurance keeps a written Incident Response Plan adapted from the First 4 Hours toolkit we publish. Using our own toolkit has been useful: it surfaced two small improvements, both folded back into the Solo Edition.

The plan covers spotting the problem, containing it, removing it, recovering, and the review afterwards. Given the small team, the incident commander, communications, and technical lead roles are held in-house. Documented escalation paths exist. For legal questions: a Vermont-licensed attorney. For incidents on a sub-processor's side: that sub-processor's incident-response team. For personal-data breaches affecting people in the European Union: the data-protection regulator (the GDPR supervisory authority).

The plan is reviewed yearly and tabletop-tested yearly. The next scheduled tabletop is 2027-05-30, or the first real incident, whichever comes first.

Breach notification commitment

Once we confirm a security incident that touches customer data, we commit to telling the affected customers without undue delay. Where people in the European Union are affected and the law requires it, we will notify the right regulator. That notice happens within the 72-hour window in Article 33 of the General Data Protection Regulation. The GDPR 72-Hour Battle-Card we publish (free) describes our own steps as well as the legal ones. They are the same steps.

Sylvan Assurance does not host customer data on its own systems. So the most likely breach scenarios involve our sub-processors. In every such case, our role is simple. Receive the sub-processor's incident notice. Assess the impact on our customers. Notify those customers, and any regulator that applies.

Security incident reporting

Anyone — researchers, customers, others — can report a possible security issue to security@sylvanassurance.com. Use the subject line "Security report". Machine-readable contact details are published at /.well-known/security.txt (per RFC 9116). We acknowledge security reports within two business days. We follow a coordinated disclosure process. We agree reasonable disclosure timelines up front; 90 days is our default. We will publicly credit the reporter when reasonable, if the reporter wants credit.

We do not currently pay money for security reports. Credit and a hand-written thank-you are what we can offer at this time.


7. Vulnerability and security testing

Penetration testing

We do not currently hire a third party to penetration-test the static corporate website. The attack surface is small: a static site behind Cloudflare, with no server-side application code under our control. The cost does not currently justify the engagement. We will look again each year on the LLC's anniversary. We will also look whenever the architecture changes in a real way (for example, adding a dynamic application).

Dependency scanning

The website uses a small amount of first-party JavaScript for progressive enhancement. For example, the guided picker on the home page points visitors to the right starting point. It is written by hand and served as a same-origin file, with no third-party libraries, no package manager, and no build or bundler step beyond a static wrangler pages deploy. So there is no dependency tree to scan. A site-wide Content-Security-Policy enforces this: script-src 'self' permits only same-origin scripts and blocks inline and third-party JavaScript across every page, including the free assessments.

Our internal toolchain (Python, and Node.js for utility scripts) is kept up to date. We update within seven days of any critical disclosure affecting a component we actively use.

Infrastructure scanning

Our infrastructure footprint is the static-site bucket on Cloudflare Pages, our domain registrar, and our provider accounts. Cloudflare publishes its own security and compliance posture. It holds System and Organization Controls 2 (SOC 2), International Organization for Standardization (ISO)/IEC 27001, and others. We rely on those for the underlying layer. We periodically check our Cloudflare account settings against the hardening checklist Cloudflare publishes for Pages projects.


8. Business continuity

Our service is keeping sylvanassurance.com up. It also means keeping purchased toolkits — and the documents inside them — open to their owners.

ServiceRecovery Time ObjectiveRecovery Point Objective
Corporate website (Cloudflare Pages)Inherits Cloudflare's published availability target. The site can be redeployed from source within 30 minutes if neededNegligible — the whole site source lives in version control; the "data" to recover is just the static site
Access to purchased toolkits and their documentsToolkit access inherits Cloudflare's published uptime target. Licence activation inherits Lemon Squeezy's. If either is down, we can send documents by email on requestNegligible — the files are static and easy to copy
Free-guide email deliveryInherits the email provider's availability; manual delivery is the fallbackUsually one business day (in-flight automation may need a manual restart)

No Sylvan Assurance system holds the only copy of any customer data. So the usual Recovery Point Objective sums do not apply in the normal sense.

Backups: the website source is held in encrypted version control on a workstation with full-disk encryption, plus an encrypted off-machine backup. Toolkit source files and build scripts are backed up the same way. The free-guide email list is exported from the provider monthly and stored in the same encrypted backup.


9. Security contact

For security questions, reports of weak spots, or requests for more detail:

Email: security@sylvanassurance.com (subject: "Security report")

Machine-readable contact: /.well-known/security.txt (RFC 9116)

Vulnerability Disclosure Policy: Coordinated disclosure, with a 90-day default timeline. Public credit on request. No cash rewards at this time.

Response commitment: We acknowledge security reports within two business days. We aim to classify severity within about five business days. We send updates at least every 14 days.

For procurement and questionnaire requests, contact support@sylvanassurance.com. We respond using the same TrustReady-format answer-bank entries we sell to others. That is a live demonstration of how the toolkit performs.


Trust portal access (optional)

We do not currently run a separate trust portal behind a Non-Disclosure Agreement. Everything we can reasonably say in public is said above. If a prospective customer needs detail that does not belong in a public document, contact support@sylvanassurance.com. We will work out the right form for it, case by case.


Recent updates (change log — most recent five)


Footer

Trust Profile last reviewed: 2026-07-06

Next scheduled review: 2026-10-06

Document owner: Sylvan Assurance leadership (Security & Trust function)

Executive sponsor: Sylvan Assurance leadership

This Trust Profile is a public statement of Sylvan Assurance's security posture as of the last review date. It is informational, not contractual. Specific contractual commitments are made in our Terms of Use, Refund Policy, and Privacy Policy, all published on sylvanassurance.com. Where we reference frameworks, we describe alignment, not certification. That applies to the General Data Protection Regulation and the National Institute of Standards and Technology Cybersecurity Framework. We hold no third-party certifications at this time and will not claim any we do not hold.