Security Commitment
At AeroVance, data security is foundational to our aerospace and defense mission. We implement defense-in-depth architectures, strict access controls, and continuous monitoring to safeguard Controlled Unclassified Information (CUI), ITAR/EAR-controlled data, and proprietary engineering assets. Our security program aligns with federal requirements and industry best practices to ensure confidentiality, integrity, and availability across the entire data lifecycle.
Core Security Controls
🔐 Encryption & Cryptography
AES-256 encryption at rest and TLS 1.3 in transit for all sensitive data. FIPS 140-2/3 validated modules for cryptographic operations.
🛡️ Identity & Access Management
Zero-trust architecture with MFA, role-based access control (RBAC), and least-privilege principles enforced across all systems.
🌐 Network & Endpoint Defense
Microsegmentation, next-gen firewalls, EDR/XDR solutions, and continuous vulnerability scanning across corporate and OT networks.
🔍 Audit & Monitoring
24/7 SOC monitoring, SIEM integration, immutable logging, and automated alerting for anomalous access or data exfiltration attempts.
📦 Supply Chain Security
Vendor risk assessments, secure code analysis, SBOM tracking, and strict data handling agreements for all third-party integrations.
📜 Personnel Security
Mandatory security training, background investigations, need-to-know verification, and continuous insider threat monitoring.
Compliance & Certifications
Our security framework is validated through rigorous third-party audits and continuous compliance monitoring.
Data Retention & Disposal Policy
AeroVance maintains a strict data lifecycle management program aligned with legal, regulatory, and operational requirements. Data is retained only as long as necessary and securely disposed of upon expiration.
| Data Category | Retention Period | Storage Environment | Disposition Method |
|---|---|---|---|
| Engineering & Design Files (CAD/PLM) | 10 years post-project closure | Encrypted Archive | Cryptographic erasure / NIST 800-88 Purge |
| Contractor & Vendor Records | 7 years | Secure Document Management | Secure shredding / Digital wiping |
| Security Clearances & Personnel Files | Indefinite (active) / 5 years (terminated) | Air-gapped HRIS | Certified destruction / Media sanitization |
| Financial & Audit Logs | 7 years | Immutable Storage | Logical deletion after retention expires |
| Communications & Email | 3 years | Cloud Archive (M365/Google) | Policy-based auto-purge |
Incident Response & Breach Notification
In the event of a suspected or confirmed security incident, AeroVance follows a structured response protocol to contain threats, preserve evidence, and notify affected parties within regulatory timeframes.
Detection & Triage
Automated SIEM alerts, employee reports, or penetration testing findings trigger immediate triage by the CSIRT team.
Containment & Eradication
Network isolation, credential rotation, and malware removal are executed to prevent lateral movement.
Forensic Investigation
Chain-of-custody logging, system imaging, and root-cause analysis conducted by certified investigators.
Notification & Recovery
Regulatory reporting (DIBNet, CISA, state laws), stakeholder communication, and system restoration with enhanced controls.
Security Inquiries & Audit Requests
For vendor security questionnaires, third-party audit coordination, or incident reporting, contact our Office of the Chief Information Security Officer (OCISO).
Contact OCISO TeamPGP Public Key available upon request | DFARS Incident Reporting: security@aerovance.com