Trust & Data Handling
Security and data handling at Plavidian
Campaigns, government offices, and commercial mailers hand us voter files, constituent data, and customer lists. This page states plainly how that data is handled. Every claim here describes practice that exists today; where we have not verified something, we say nothing rather than round up.
Accounts & Access
Individual accounts, separated roles
Two-step verification on every Plavidian account
Every Plavidian staff account requires a second factor from an authenticator app, not just a password. It is mandatory and cannot be switched off. Customers can turn it on for their own accounts from the account menu.
Authenticated accounts
Access requires an individual account. There are no shared logins. Passwords are stored as salted PBKDF2-HMAC-SHA256 hashes, never in plain text and never in a form anyone at Plavidian can read.
Password rules that hold up
At least twelve characters, screened against commonly used and previously breached values, and checked so a password cannot repeat a recent one. Any credential we issue must be replaced by you before it can be used for anything else.
Role separation
Customer accounts and administrative accounts are separate roles. Customer users cannot reach administrative functions, and each customer account sees its own jobs and files.
Sessions end on their own
An idle session signs itself out, so a portal left open on a shared production terminal does not stay open. Repeated failed sign-ins temporarily lock the account rather than allowing unlimited guesses.
Login activity is logged
Sign-ins are recorded with time and source, giving each account an activity record its owner can rely on. No card data is stored: invoicing runs through Xero and card details never enter our application.
Your Data, Handled Carefully
A file you send us cannot turn into a file that attacks you
Spreadsheet formulas are neutralised
A mailing list can carry a field that looks like ordinary text but behaves as a live formula the moment the file is opened in Excel. Every report and list we generate is written so those values stay text. It protects you, and it protects our own operators opening your file.
Uploads are read, not run
Plavidian's application does not intentionally execute uploaded macros, scripts, or active document content. Files are parsed or rendered only for authorized production and review functions, using libraries configured to prevent embedded scripts from running.
Not sent to outside analysis services
Customer files remain within Plavidian's controlled production environment and its contracted cloud infrastructure. They are not submitted to unrelated third-party scanning, enrichment, analytics, or AI services. For voter, donor, and constituent data, handing files to an outside analyst would defeat the point of protecting them.
Encryption
Encrypted in transit and at rest
Traffic to Plavidian Connect is encrypted in transit (TLS 1.2 or higher), and customer files and database records are encrypted at rest with 256-bit AES on Microsoft Azure.
Chain of Custody
Documented from data receipt to USPS induction
Most security pages describe intentions. Ours points at an artifact. The Plavidian Assurance™ Report documents what was produced on a job and how the run reconciled to the customer's list, which is chain of custody a customer can hold in their hands rather than a policy they have to take on faith. When camera verification runs on a job, every piece read is part of that record.
AI Features
Exactly what our AI does and does not see
The Plavidian Expert answers USPS questions from a curated knowledge base we maintain. Retrieval runs on our own systems: the relevant USPS reference material is looked up locally and sent to the Anthropic API together with the question you typed. That is the whole payload. Customer mailing lists, job files, and artwork are never sent to any AI service, and under Anthropic's API terms, API inputs and outputs are not used to train models. We can be specific here because we built the data path and read it before writing this paragraph.
Campaign Confidentiality
Your list produces your mailing
Customer files are scoped to the customer's own account in Plavidian Connect: your proofs, artwork, and lists are visible to your account and to the production staff working your job. Questions about how a specific data set will be handled are welcome before you send it: info@plavidian.com.
Data Retention
Kept while it is useful, then removed
Portal data tied to a job - uploaded files, mailing lists, and the per-piece camera scan records from a run - is retained for five years from the date the job is completed, then deleted. The job's own record, including postal and billing history, is kept longer where accounting and tax rules require it. This means your mailing list and scan data do not sit in the portal indefinitely: once a job has been done for five years, the working data behind it is removed.
What You Will Not Find Here
No badges we have not earned
We do not claim certifications we do not hold, and we avoid words like comprehensive and military-grade on principle. If your organization runs vendor security questionnaires, send one: info@plavidian.com. Our privacy practices and data compliance commitments are published at Privacy and Data Compliance.
What we do hold
USPS Full-Service Certified Mail Service Provider. Verifiable on the USPS PostalPro register of certified providers, linked from our About page.
Member, American Association of Political Consultants.
Production runs on Microsoft Azure in United States regions, with TLS 1.2+ encryption in transit and AES-256 encryption at rest provided by the platform.
Where we stand on NIST SP 800-171
Plavidian Connect was assessed against all 110 requirements of NIST SP 800-171 rev. 2, scoring 104 of 110 under the DoD Assessment Methodology (self-assessed July 29, 2026, recorded in our System Security Plan). The standard itself, and why we chose it over commercial frameworks, is explained on our NIST SP 800-171 page.
Federal and Government Work
Where we stand on NIST SP 800-171
NIST Special Publication 800-171 is the federal standard for protecting Controlled Unclassified Information held on a contractor's systems. It matters to any organization that may handle agency data, and it is increasingly what a prime contractor asks about before subcontracting work.
What the assessment covers
All 110 requirements, scored: 108 implemented. The engineering controls are verified as part of each release, and the supporting practices, an exercised incident response plan, security awareness training with records, personnel screening and offboarding, physical protection, and media destruction, are adopted as written policy incorporated into the System Security Plan.
Raising the bar further
Two enhancements are scheduled and tracked in the plan with dates: extending mandatory two-step verification from every staff account to customer sign-in (December 2026), and moving application-layer cryptography onto FIPS-validated modules (2027). Most vendors in this market publish neither a score nor a roadmap; we publish both.
Ready for DoD reporting
Our current Basic assessment score of 104 of 110 (assessment date July 29, 2026) is documented in the summary-level format that DFARS 252.204-7019 and 252.204-7020 require for posting to the DoD's Supplier Performance Risk System (SPRS), and will be posted when we pursue or perform work carrying those clauses. We are actively executing the Plan of Action and Milestones on the two remaining items, M-01 and P-12, each with a named corrective action and target date.
DFARS 252.204-7012 readiness
We meet the safeguarding, documentation, and cyber incident reporting requirements of DFARS 252.204-7012: implementation status is recorded in a System Security Plan and POA&M as the clause requires, and our exercised Incident Response Plan carries the 72-hour DoD reporting path and 90-day media preservation duty for any incident affecting covered defense information. Contracts carrying these clauses can be accepted with those mechanisms already in place.
CMMC Level 1
CMMC Level 1 is pass/fail against the 15 basic safeguarding requirements of FAR 52.204-21, with no plan of action permitted at that level. Our July 29, 2026 assessment covers every one of them (they map to 17 NIST SP 800-171 controls on our assessment sheet, all implemented), and neither of our two open NIST SP 800-171 items is a Level 1 requirement, so Plavidian meets Level 1 outright. The formal Level 1 self-assessment and senior-official affirmation are posted to SPRS when we pursue or perform work that requires them.
On whether your data is CUI
Whether information counts as Controlled Unclassified Information depends on the contract it arrives under, not on the file type. We do not treat commercial mailing lists as CUI. Where an agency supplies data under a contract that designates it, that contract's requirements govern and take precedence wherever they are stricter than our own.
Our controls are built so that designated data can be accepted when a contract calls for it, and so that voter, donor, and constituent files receive the same handling whether or not a designation applies.
Read the plan yourself
The System Security Plan is version-dated and includes a Plan of Action and Milestones listing every open item, its risk level, the corrective action, and the date we are working to. It also documents our cryptographic inventory and where each function sits relative to validated modules.
Customers, prime contractors, and contracting officers can request the current version under NDA: info@plavidian.com. Send your vendor security questionnaire at the same time and we will complete it against the plan rather than from memory.
Questions before you send a file?
info@plavidian.com · 760-666-3130 · 2210 E Vista Way Ste 6, Vista, CA 92084
