Security Commitment

At AeroVance, data security is foundational to our aerospace and defense mission. We implement defense-in-depth architectures, strict access controls, and continuous monitoring to safeguard Controlled Unclassified Information (CUI), ITAR/EAR-controlled data, and proprietary engineering assets. Our security program aligns with federal requirements and industry best practices to ensure confidentiality, integrity, and availability across the entire data lifecycle.

Core Security Controls

🔐 Encryption & Cryptography

AES-256 encryption at rest and TLS 1.3 in transit for all sensitive data. FIPS 140-2/3 validated modules for cryptographic operations.

🛡️ Identity & Access Management

Zero-trust architecture with MFA, role-based access control (RBAC), and least-privilege principles enforced across all systems.

🌐 Network & Endpoint Defense

Microsegmentation, next-gen firewalls, EDR/XDR solutions, and continuous vulnerability scanning across corporate and OT networks.

🔍 Audit & Monitoring

24/7 SOC monitoring, SIEM integration, immutable logging, and automated alerting for anomalous access or data exfiltration attempts.

📦 Supply Chain Security

Vendor risk assessments, secure code analysis, SBOM tracking, and strict data handling agreements for all third-party integrations.

📜 Personnel Security

Mandatory security training, background investigations, need-to-know verification, and continuous insider threat monitoring.

Compliance & Certifications

Our security framework is validated through rigorous third-party audits and continuous compliance monitoring.

ITAR / EARExport-controlled data management
NIST SP 800-171CUI protection framework
CMMC Level 2Defense supply chain readiness
ISO 27001Information security management
SOC 2 Type IISecurity & availability audit
DFARS 252.204-7012Cybersecurity incident reporting

Data Retention & Disposal Policy

AeroVance maintains a strict data lifecycle management program aligned with legal, regulatory, and operational requirements. Data is retained only as long as necessary and securely disposed of upon expiration.

Data Category Retention Period Storage Environment Disposition Method
Engineering & Design Files (CAD/PLM) 10 years post-project closure Encrypted Archive Cryptographic erasure / NIST 800-88 Purge
Contractor & Vendor Records 7 years Secure Document Management Secure shredding / Digital wiping
Security Clearances & Personnel Files Indefinite (active) / 5 years (terminated) Air-gapped HRIS Certified destruction / Media sanitization
Financial & Audit Logs 7 years Immutable Storage Logical deletion after retention expires
Communications & Email 3 years Cloud Archive (M365/Google) Policy-based auto-purge

Incident Response & Breach Notification

In the event of a suspected or confirmed security incident, AeroVance follows a structured response protocol to contain threats, preserve evidence, and notify affected parties within regulatory timeframes.

1

Detection & Triage

Automated SIEM alerts, employee reports, or penetration testing findings trigger immediate triage by the CSIRT team.

2

Containment & Eradication

Network isolation, credential rotation, and malware removal are executed to prevent lateral movement.

3

Forensic Investigation

Chain-of-custody logging, system imaging, and root-cause analysis conducted by certified investigators.

4

Notification & Recovery

Regulatory reporting (DIBNet, CISA, state laws), stakeholder communication, and system restoration with enhanced controls.

Security Inquiries & Audit Requests

For vendor security questionnaires, third-party audit coordination, or incident reporting, contact our Office of the Chief Information Security Officer (OCISO).

Contact OCISO Team

PGP Public Key available upon request | DFARS Incident Reporting: security@aerovance.com