Trust
Security and procurement practices, published in full.
For your purchasing office, your IT security review and your counsel: what LFW does with your data and your systems, in writing, with a date on each document. Read it before you ask, and ask about anything it leaves out.
Policies.
Four documents, each describing what LFW does today. Each carries its version and the date it last changed, like the agreements on a separate page.
- Information security policy Version 1.0, October 6, 2026 What LFW protects, where its systems run, how releases are built, how data is backed up, and how a problem is reported. Read
- Access control policy Version 1.0, October 6, 2026 Who can reach what: client accounts in the client’s name, sign-in without passwords, delegated access to client systems, and how access is revoked. Read
- Incident response plan Version 1.0, October 6, 2026 What counts as an incident, who is told and when, how LFW’s own systems and a client site are restored, and what is written down afterward. Read
- Acceptable use policy Version 1.0, October 6, 2026 The rules LFW follows with client data, client systems, credentials, AI tools and its own equipment. Read
How we handle client data.
The short version. The information security policy and the privacy policy carry the detail.
- What we holdYour website’s content, editor accounts and form submissions stay in your systems. In the Client Portal we hold the names and email addresses of your staff, the requests they send, the files they attach and the reports we write.
- Where it isYour site runs on your hosting account, in your organization’s name. The Client Portal and LFW.com run on LFW’s own server at Hetzner in Ashburn, Virginia, behind Cloudflare, with an encrypted backup copy in Cloudflare R2.
- How long we keep itFor the life of the engagement and the 30-day handoff after it. Backup snapshots expire on a fixed schedule: daily copies after 30 days, weekly after 26 weeks, monthly after 24 months, with one yearly copy kept longer.
- Deleted on requestAsk, and we return or destroy your confidential information within 15 days, as the services agreement says. Encrypted backup copies expire on the schedule above and are never restored except to recover from a failure.
- In your nameHosting, domain, code repository and the administrator accounts on your site are in your organization’s name from the first day. When the retainer ends, access comes back to you at no charge.
- What we never collectNo passwords (sign-in is by one-time link or passkey), no card data, no health information covered by HIPAA. Visitor analytics on LFW.com store no IP address and set no tracking cookie.
Subprocessors.
The companies that process data for LFW, and what each one sees. The privacy policy names the same companies.
- Kinsta, or the host you chooseRuns your website: its files, database, backups and server logs, on an account in your organization’s name. LFW approves the plan; the host bills you at its published rates.
- HetznerLFW’s own server in Ashburn, Virginia: the Client Portal, LFW.com’s forms, the free audit and LFW Monitor, and their database.
- CloudflareIn front of LFW.com and of client sites: DNS, TLS, the web application firewall and DDoS mitigation. It sees request data and IP addresses, and holds LFW’s encrypted off-site backup copy.
- Google WorkspaceLFW’s email and calendar. Contact messages, booking requests and correspondence with you land there; replies go out through it.
- ResendApplication email from LFW’s systems: sign-in links, audit reports and receipts. It receives the address and the contents of each message it sends.
- Anthropic and OpenAIAI assistance with research, drafting, software development and administrative work, as assistants to LFW. Client data is never used to train models, and a person reviews every output. The Claude API account runs under Anthropic’s commercial terms, which bar training on customer content.
Commitments, with numbers.
From the retainer schedule and the services agreement. Response times are good-faith targets in business hours, not guarantees.
- Updates every monthWordPress core, themes and plugins on a monthly cycle, from version control, with checks after each release. A security release is applied ahead of the cycle, and the firewalls block known attacks in between.
- Incident notice within 24 hoursIf we confirm a security incident that touches your data or your site, we tell you within 24 hours of confirming it, in writing, with what we know and what we are doing.
- Business hours, statedMonday to Friday, 9 a.m. to 5 p.m. Eastern (6 a.m. to 2 p.m. Pacific), excluding federal holidays. We do not offer after-hours or on-call coverage. Your host’s support covers the servers around the clock.
- Acknowledgment targetsNew requests acknowledged within 1 business day, or 4 business hours on the Priority tier. Targets from the retainer schedule, not guarantees.
- Restores by the next business dayIf your site is compromised, tell us in the Client Portal at any hour. We begin restoring from your host’s backup by the next business day. Deeper investigation and cleanup are quoted first.
- Access returned at no chargeOn 30 days’ written notice the retainer ends. Credentials, account access and repository access come back to you at no charge; there is no termination fee.
Accessibility conformance report.
LFW.com’s own report, dated October 2, 2026, on the VPAT 2.5 structure: WCAG 2.1 A and AA, functional performance criteria and support documentation, prepared from the test record. It is self-prepared and says so.
Security questionnaires.
LFW’s answers to the HECVAT’s critical questions are published, in the toolkit’s own order, with the questions that do not apply and why. We fill in your institution’s own form from these answers.
Vendor documents.
Registrations for your vendor file, and the documents that travel with a bid. The full facts are on How to buy.
- Registered in
- Virginia, SCC ID 11400695
- eVA vendor
- SUP364899Active
- SAM.gov
- CAGE 25DX4Active
- UEI
- VBCGH1QLKSB1
- W-9 Sent within one business day on request. It is not published here because it carries a taxpayer number and a signature. Request the W-9 by email
- Certificates of insurance General liability, professional liability, and cyber coverage at the limits your contract names, bound at award and certified before work begins.
- Capability statement Company data, codes, core competencies and key personnel, as a one-page PDF for your vendor file. Download the PDF
What we do not have.
Said plainly, so your review does not have to ask.
- No SOC 2 or ISO 27001 report of LFW’s ownYour host’s reports cover the infrastructure your site runs on. LFW holds no attestation for its own operations and does not claim one.
- No annual third-party penetration test yetLFW’s own review of LFW.com is in the information security policy. Where your contract calls for an independent test of your site, LFW arranges one and reports the result.
- No employeesLFW is its founder, Leland Fiegel. Every policy on this page describes one person’s practice, and says so where it matters.
For your procurement file.
How to buy has the company facts, the terms we accept under your contract and what happens if LFW is unavailable. The capability statement is the one-page summary.