1. Overview
FrameworkMapper is operated by Midwest Cyber, LLC, a Nebraska limited liability company with a principal address of 1022 Brickyard Dr, Hooper, NE 68031, together with Viosoph, LLC (collectively, "we," "us," "our"). This Privacy Policy describes how we collect, use, share, and safeguard information when you visit frameworkmapper.com, use the FrameworkMapper application, or otherwise interact with us (collectively, the "Service").
FrameworkMapper helps cybersecurity practitioners, managed service partners, and the organizations they serve perform compliance assessments against frameworks such as the CIS Critical Security Controls, NIST Cybersecurity Framework v2.0, NIST SP 800-53, NIST SP 800-171, CMMC Levels 1 and 2, the HIPAA Security Rule, GovRAMP, and the Texas Cybersecurity Framework.
By using the Service, you agree to the practices described here. If you do not agree, please discontinue use.
2. Information We Collect
2.1 Information you provide directly
- Account information. When you create an account or accept an invitation, we collect your name, email address, organization name, role within the organization, and the password (managed by our identity provider — see below).
- Organization profile. Partner and client organizations may provide a billing address, contact email, phone, website, and (for partners) public listing details such as a logo, description, and service area.
- Billing information. When you purchase or subscribe, our payment processor (Square, Inc.) collects and tokenizes your payment card. We never receive or store full card numbers, CVV values, or expiration data on our infrastructure. We retain a tokenized customer ID, the card brand, and the last four digits as a reference for future transactions and receipts.
- Assessment content. When you complete an assessment, we receive maturity scores, free-text notes, evidence descriptions, tool selections, and any links you choose to attach. This content is encrypted at rest (see Section 5).
- Tool inventory ("My Tools"). The list of security tools you mark as in-use or wishlisted. Stored both in your browser's local storage and (for authenticated users) on our servers, scoped to your organization.
- Tax and education-discount documentation. If you request tax exemption or an education discount, we receive any supporting document you upload (e.g., an exemption certificate or institutional letter). Stored as a base64-encoded blob in our database.
- Public form submissions. Sales / MSSP inquiries and vendor "notify me" signups capture your name, email, organization, and any free-form message.
- Communications. Email, chat, or other correspondence with us, including support requests.
Please do not upload sensitive regulated data. FrameworkMapper is a planning and prioritization tool, not an approved system of record for regulated evidence. Do not upload or enter protected health information (PHI) about identifiable patients, controlled unclassified information (CUI), government-classified information, payment-card data, or personal information about minors. Describe your evidence in general terms instead of attaching the underlying sensitive records. See our Terms of Service for the full acceptable-use rules.
2.1.1 Handling regulated data — what would be required
Customers in compliance-sensitive verticals occasionally ask whether they could use FrameworkMapper as part of a workflow that does handle regulated data. The default answer is no, and the upload prohibition above governs the platform in its current form. If you have a use case that requires processing regulated data through FrameworkMapper, the following would need to be in place first — we don't currently offer any of these arrangements:
- HIPAA-covered data (PHI). A signed Business Associate Agreement (BAA) between Midwest Cyber, LLC and Viosoph, LLC and the covered entity, plus the platform changes required to meet the HIPAA Security Rule (encryption-at-rest controls, audit logging suitable for HIPAA, access controls, breach-notification commitments). No BAAs are in effect today.
- Controlled Unclassified Information (CUI) under DoD / NIST 800-171. FedRAMP Moderate authorization or a documented Moderate-Equivalent posture, plus DFARS 252.204-7012 flow-down compliance. The platform is not FedRAMP-authorized and we do not currently process CUI for any customer.
- Federal data subject to FedRAMP. Agency-level Authority to Operate (ATO). The platform is not authorized at any FedRAMP impact level.
- Cardholder data (PCI). A signed Attestation of Compliance (AoC) as a PCI DSS service provider, plus quarterly ASV scans and the operational controls specified in PCI DSS 4.0. Our payment processor (Square) is PCI-compliant for the transactions it handles; FrameworkMapper itself is not a PCI environment.
- EU / UK personal data subject to GDPR. A Data Processing Addendum (DPA) with appropriate Standard Contractual Clauses, plus the data-subject-rights workflow GDPR requires (access, rectification, erasure, portability within prescribed timelines). We do not currently offer a DPA.
Until any of these arrangements is explicitly in place and disclosed in writing, treat the platform as approved only for the non-regulated planning data described in this Privacy Policy. For larger-scale or regulated engagements, contact us before uploading anything that would otherwise fall under one of the categories above.
2.2 Information collected automatically
- Server logs. Standard request metadata — IP address, user agent, timestamp, request path, response status — is processed by our infrastructure provider (Cloudflare) and used for security, abuse prevention, and operational troubleshooting.
- Local storage. Your browser stores your tool list, framework selections, in-progress assessment drafts, and similar app-state on your device. This is not sent to us except when you explicitly save or sync.
- Analytics (limited and gated). See Section 6 below.
2.3 Information from third parties
- Identity providers. If you sign in with Google, we receive the email address and name associated with your Google account from Firebase Authentication.
- Square. Transaction status, receipt URLs, dispute notifications, and tokenized card metadata.
3. How We Use Information
We use the information described above to:
- Provide, maintain, and secure the Service, including authentication, authorization, and account recovery.
- Carry out assessments, score maturity, generate reports and certificates, and persist your work.
- Map your tool inventory to control coverage across frameworks (the core FrameworkMapper feature).
- Process payments, issue receipts and invoices, manage subscriptions and credits, apply discounts and tax exemptions, and notify you of upcoming charges or expirations.
- Send transactional and account-related email — for example, invitation confirmations, retention notices, payment receipts, and security alerts. We send these via Microsoft Graph API using a Microsoft 365 mailbox we operate.
- Respond to support requests and inquiries.
- Detect, investigate, and prevent fraud, abuse, security incidents, and violations of our Terms of Service.
- Comply with legal obligations and enforce our agreements.
- Improve the Service through aggregated, de-identified analysis of feature usage.
We do not sell or rent your personal information, and we do not use your information for cross-context behavioral advertising.
5. Data Security
We use industry-standard technical and organizational measures to protect your information:
- Encryption in transit. All connections to our website and API use TLS 1.2+. HTTP Strict Transport Security (HSTS) is enforced.
- Encryption at rest. Assessment content (scores, notes, evidence text, tool selections) is encrypted with AES-256-GCM using envelope encryption: a per-organization data encryption key (DEK) is wrapped by a key encryption key (KEK) held as a Cloudflare Workers secret. The KEK is never written to the database.
- Tokenization. Payment cards are handled exclusively by Square's PCI-DSS Level 1 environment; we never see or store card numbers, CVV, or full expiration data.
- Access controls. Role-based access within the application; least-privilege on operational systems; multi-factor authentication required for administrative access.
- Hardened defaults. Strict Content Security Policy with per-request nonces, restrictive Permissions Policy disallowing camera, microphone, geolocation, USB, and payment APIs unless explicitly granted, and X-Frame-Options to prevent clickjacking.
- Auditing. Sensitive assessment events (creation, completion, sharing, retention extension, deletion) are logged in an append-only audit table.
No method of transmission or storage is 100% secure. We cannot guarantee that unauthorized third parties will never gain access. If we ever experience a security incident affecting your information, we will notify you and any required regulators in accordance with applicable law.
7. Your Rights & Choices
7.1 Account access and deletion
You can review and update most of your account information from the in-app settings page. You can delete your account at any time from your portal settings; doing so will erase your encrypted assessment payloads, deactivate your authentication record, and (if you were the last member of your organization) cascade-delete the organization. Some metadata may be retained for compliance, audit, or legitimate business purposes (see Section 8).
7.2 Communications
Transactional emails (receipts, invitations, security notices, retention warnings) are required for the Service to function and are not subject to opt-out. Any marketing emails we send will include an unsubscribe link.
7.3 Region-specific rights
Depending on where you live, you may have additional rights under applicable law:
- California (CCPA / CPRA). You have the right to know what personal information we have collected about you, to request deletion, to correct inaccuracies, to limit the use of sensitive personal information, and to be free from retaliation for exercising these rights. We do not sell or share personal information for cross-context behavioral advertising.
- European Economic Area / United Kingdom / Switzerland. If we begin offering the Service to residents of these regions, you will have rights under the GDPR / UK GDPR including access, rectification, erasure, restriction, portability, and objection. Today, the Service is offered to U.S. customers only and we do not target the Service to residents of these regions.
- Other U.S. states with comprehensive privacy laws (Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and others as enacted) provide rights similar to those listed above.
To exercise any right, contact us using the details in Section 12. We will verify your identity before responding and reply within the timeframes required by your local law (generally 30 to 45 days).
7.4 Backup export
You can download an encrypted backup of any assessment you own from the assessment page. The backup is wrapped with a password you choose at export time; we cannot recover it if you lose the password.
8. Data Retention
- Account records are retained for as long as your account is active.
- Assessment content shared with a client organization is retained according to your subscription tier — 12 months on Free / Essential plans. Additional retention period may apply or change in the future.
- Retention notices are sent at 30 days and 7 days before purge.
- Tombstones. After purge, we retain a non-PII audit record (the assessment ID, organization ID, and dates) for compliance and reference. The encrypted content is irrecoverably deleted.
- Billing and tax records are retained for the period required by U.S. tax and accounting law, typically seven (7) years.
- Server and security logs are retained for up to 90 days for operational and security purposes.
- AI usage metadata (token counts, model, success/failure — never prompt content) is retained for billing and capacity planning.
9. International Users
The Service is operated from the United States and is intended for use by U.S.-based customers. Data is processed and stored on infrastructure located in the United States. If you access the Service from outside the U.S., you understand and consent to the transfer of your information to the U.S., which may have data-protection laws that differ from those of your jurisdiction.
We have not yet implemented the additional safeguards (Standard Contractual Clauses, EU-U.S. Data Privacy Framework certifications, GDPR Article 27 representative, etc.) that we expect to put in place before offering the Service in the European Economic Area, United Kingdom, or Switzerland. Until then, we ask EEA / UK / Swiss residents to refrain from creating accounts.
10. Children's Privacy
FrameworkMapper is a business-to-business compliance tool intended exclusively for use by adults (age 18+) acting on behalf of an organization. We do not knowingly collect personal information from children under 13 (or under 16 in jurisdictions where that is the applicable threshold).
The Texas Cybersecurity Framework (TCF) assessment, which is targeted at K-12 school districts, is an institutional maturity assessment of the district's cybersecurity controls. It does not collect, process, or store student records or any personally identifiable information about children. All data captured is about the district's organizational practices.
If you believe a child has provided us with personal information, please contact us immediately and we will delete it.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page and, for material changes, provide additional notice (such as an email or a banner on the Service) at least 14 days before the change takes effect. Your continued use of the Service after the effective date constitutes acceptance of the revised policy.
12. Contact
If you have questions, requests, or complaints about this Privacy Policy or our handling of your information, contact us:
Midwest Cyber, LLC and Viosoph, LLC
Attn: Privacy
1022 Brickyard Dr
Hooper, NE 68031
United States
Email: privacy@frameworkmapper.com
If you are not satisfied with our response, you may have the right to lodge a complaint with the data-protection authority in your jurisdiction.
Notice. This Privacy Policy describes practices accurate as of the effective date above. It is provided for transparency and is not legal advice. Your use of the Service is also governed by our Terms of Service.