Trust

Security questionnaire answers.

95 answers to the HECVAT’s questions, in the toolkit’s own order and words, with the questions that do not apply and why. Each answer describes what LFW does today, consistent with the policies on the trust page.

We fill in your institution’s own form from these answers. Send it, and it comes back completed, with anything that differs for your contract marked.

Last updated

The question set.

HECVAT Lite no longer exists as a separate file. The current toolkit, HECVAT 4.1.6, folds Full, Lite and On-Premise into one workbook, and names its questions of critical importance as the replacement for the Lite approach. These are those questions, checked against the workbook on October 6, 2026.

  • What is hereThe eight scoping questions, the organization entries and every critical question of HECVAT 4.1.6, each with LFW’s answer. The question IDs are the workbook’s, so your reviewer can match them.
  • What is notThe standard and minor questions, which the full workbook adds. LFW answers those on your form, from the same facts. If your institution still uses an older HECVAT Lite, the categories map to the sections below.
  • The scope assumedThe solution is LFW’s web operations service: running a website in the institution’s own hosting, plus the Client Portal at my.lfw.com, where the institution’s staff send requests and read reports. The portal is the only system LFW hosts.

Start here

Scoping questions.

The eight questions that decide which sections apply. The answers are why the HIPAA, payment card and AI sections below are marked not applicable.

  • REQU-01 Are you offering a cloud-based product? Yes In part. The service runs inside your own hosting account. The Client Portal (my.lfw.com) is a hosted application LFW runs, so the product questions below are answered for it.
  • REQU-02 Does your product or service have an interface? Yes The Client Portal for your staff, and the website LFW builds or maintains for your visitors and editors.
  • REQU-03 Are you providing consulting services? Yes LFW’s staff work inside your systems: your content management system, your hosting account and your Cloudflare zone, through accounts you grant.
  • REQU-04 Does your solution have AI features, or are there plans to implement AI features in the next 12 months? No The Client Portal has no AI features. The portal can be connected to an AI assistant you choose, under your own consent, through a standard connection; LFW calls no model on your behalf. LFW uses AI tools in its own work, covered under Privacy below.
  • REQU-05 Does your solution process protected health information (PHI) or any data covered by the Health Insurance Portability and Accountability Act (HIPAA)? No LFW does not take on sites or forms that collect health information covered by HIPAA.
  • REQU-06 Is the solution designed to process, store, or transmit credit card information? No Neither the Client Portal nor LFW’s own site handles card data. On a client site, payments go to the institution’s own payment processor, never through pages LFW stores data from.
  • REQU-07 Does operating your solution require the institution to operate a physical or virtual appliance in their own environment or to provide inbound firewall exceptions to allow your employees to remotely administer systems in the institution's environment? No No appliance and no inbound exceptions. LFW signs in to your hosted systems the way your own staff do.
  • REQU-08 Does your solution have access to personal or institutional data? Yes Your website’s content, editor accounts and form submissions, in your systems. In the portal: the names and email addresses of your staff, the requests they send and the files they attach.

GNRL, COMP, DOCU

Organization.

Who LFW is, and the documents it holds.

  • GNRL-01 Solution Provider Name LFW’s answer LFW.com LLC, doing business as LFW.
  • GNRL-02 Solution Name LFW’s answer LFW web operations (the Web Operations Retainer) and the Client Portal.
  • GNRL-03 Solution Description LFW’s answer Website management under a monthly retainer: updates, security, accessibility testing and fixes, content changes and a monthly written report, in hosting the institution owns. The Client Portal is where the institution’s staff send requests and read reports.
  • GNRL-04 Solution Provider Contact Name LFW’s answer Leland Fiegel, Founder & CEO.
  • GNRL-06 Solution Provider Contact Email LFW’s answer hello@lfw.com; security reports to security@lfw.com.
  • GNRL-07 Solution Provider Contact Phone Number LFW’s answer (703) 662-1617.
  • GNRL-08 Country of Company Headquarters LFW’s answer United States (Arlington, Virginia). All of LFW’s work is done in the United States, from Arlington.
  • COMP-01 Do you have a dedicated software and system development team(s) (e.g., customer support, implementation, product management, etc.)? No LFW has one person, its founder, who does the development, support and implementation (1, as of September 27, 2026).
  • COMP-02 Describe your organization’s business background and ownership structure, including all parent and subsidiary relationships. LFW’s answer LFW.com LLC is a Virginia limited liability company, formed in the District of Columbia in 2020 and domesticated to Virginia in 2022, owned entirely by Leland Fiegel. It has no parent, subsidiaries or offshore arrangements.
  • COMP-03 Have you operated without unplanned disruptions to this solution in the past 12 months? No One self-inflicted outage of about one minute on September 8, 2026, when a deployment stopped the web service before its backup finished. The deployment procedure was replaced that day, and releases now switch traffic only after the new release passes its checks.
  • COMP-04 Do you have a dedicated information security staff or office? No The founder is the security contact (security@lfw.com). There is no separate office.
  • COMP-05 Use this area to share information about your environment that will assist those who are assessing your company's data security program. LFW’s answer One server at Hetzner in Ashburn, Virginia, behind Cloudflare. The firewall accepts web traffic from Cloudflare’s addresses only; SSH is by key, with passwords off. The application, its database and the search index listen on the loopback address. Details are in the information security policy.
  • DOCU-01 Do you have a well-documented business continuity plan (BCP), with a clear owner, that is tested annually? No Not as a tested plan. What LFW has published instead is the continuity arrangement for a one-person firm: your hosting account and repository in your name from day one, a runbook in your repository updated monthly, your host’s 24/7 support, and access returned at no charge when the retainer ends.
  • DOCU-02 Do you have a well-documented disaster recovery plan (DRP), with a clear owner, that is tested annually? Partly Backups are documented and automatic: an encrypted, deduplicated snapshot every day and at every release, checked weekly, with an off-site copy. A scheduled annual restore drill is not yet part of the record; the owner is the founder.
  • DOCU-03 Have you undergone a SSAE 18/SOC 2 audit? No LFW holds no SOC 2 report. Your host’s own reports cover the infrastructure your site runs on.
  • DOCU-04 Do you conform with a specific industry standard security framework (e.g., NIST Cybersecurity Framework, CIS Controls, ISO 27001, etc.)? No LFW claims no framework conformance. Its practices are published in full on this site so you can map them to your own framework.
  • DOCU-05 Can you provide overall system and/or application architecture diagrams, including a full description of the data flow for all components of the system? Yes On request. The data flow is short: visitor, Cloudflare, nginx on the server, the Node application, a SQLite database on the same server, with encrypted backups to the server’s backup directory and to Cloudflare R2.
  • DOCU-06 Does your organization have a data privacy policy? Yes Published at lfw.com/privacy, with its date and previous versions.
  • DOCU-07 Do you have a documented, and currently implemented, employee onboarding and offboarding policy? N/A LFW has no employees. The access control policy covers how LFW’s own access to your systems is granted and removed, which doubles as the offboarding list.

THRD, CHNG, PPPR

Third parties and change.

The companies LFW relies on, and how changes and patches are handled.

  • THRD-01 Do you perform security assessments of third-party companies with which you share data (e.g., hosting providers, cloud services, PaaS, IaaS, SaaS)? Partly LFW reads each provider’s published security documentation before using it and keeps the list of providers public (the subprocessors on the trust page). It does not run its own audits of them.
  • THRD-02 Do you have contractual language in place with third parties governing access to institutional data? Yes Each provider’s standard terms and data processing terms. LFW does not negotiate custom contracts with them.
  • THRD-03 Do the contracts in place with these third parties address liability in the event of a data breach? Partly Only as each provider’s standard terms do. LFW holds no negotiated breach-liability terms with any provider.
  • THRD-04 Do you have an implemented third-party management strategy? Partly A short, published list, reviewed whenever a provider is added or removed; the privacy policy, the security page and the trust page change together.
  • CHNG-01 Will the institution be notified of major changes to your environment that could impact the institution's security posture? Yes In your monthly report, and on the dated documents on the trust page, which change in the open.
  • CHNG-02 Does the system support client customizations from one release to another? Yes Your website is a custom theme in a repository you own, so nothing of yours is overwritten by an update. The Client Portal is not customized per client.
  • CHNG-03 Do you have an implemented system configuration management process (e.g., secure "gold" images, etc.)? Yes The server’s provisioning script, service units, firewall rules and web server configuration live in version control. Each release is built in a disposable container and activated as a whole.
  • PPPR-01 Do you have a documented patch management process? Yes For your site: updates monthly, security releases ahead of the cycle, and a firewall that blocks known attacks in between. For LFW’s systems: dependencies are audited at every release and a version published fewer than seven days earlier is refused.
  • PPPR-02 Can your organization comply with institutional policies on privacy and data protection with regard to users of institutional systems, if required? Yes Under your contract. Send the policy; LFW reads it before signing.
  • PPPR-03 Is your company subject to the institution's geographic region's laws and regulations? Yes LFW is a United States company. Under a public institution’s contract it accepts the institution’s state law and venue.

CONS

Consulting access.

How LFW works inside your systems.

  • CONS-01 Will the consultant require access to the institution's network resources? No No network access, VPN or appliance. LFW uses named accounts you grant in your hosted systems.
  • CONS-02 Has the consultant received training on (sensitive, HIPAA, PCI, etc.) data handling? No There is no formal training program; one person holds the access. The written rules are the acceptable use policy and the access control policy on this site.
  • CONS-03 Is the data encrypted (at rest) while in the consultant's possession? Partly LFW keeps your data in your systems and avoids holding copies on its own equipment. Work in progress lives in the repository you own. Encrypted LFW backups cover the Client Portal’s records.
  • CONS-04 Can access be restricted based on source IP address? Yes Where your platform supports it. LFW works within an address allowlist you set.

APPL, FIDP, VULN, DCTR

Application and infrastructure.

The Client Portal and the server it runs on.

  • APPL-01 Are access controls for institutional accounts based on structured rules, such as role-based access control (RBAC), attribute-based access control (ABAC), or policy-based access control (PBAC)? Yes Portal roles are owner, member and viewer, with per-site grants for members. LFW staff cannot write as a client: a staff view of a client account is read-only and logged.
  • APPL-02 Are you using a web application firewall (WAF)? Yes Cloudflare’s web application firewall in front of LFW.com and the portal; the server accepts web traffic from Cloudflare only. Client sites run Wordfence Premium and Cloudflare’s firewall.
  • APPL-03 Are only currently supported operating system(s), software, and libraries leveraged by the system(s)/application(s) that will have access to institution's data? Yes A current Node.js release and current libraries, pinned in a lockfile and audited at every release. The build refuses a known vulnerability of high severity.
  • APPL-04 Does your application require access to location or GPS data? No No. Page-view analytics keep only a country or region computed from the address, which is not stored.
  • APPL-05 Does your application provide separation of duties between security administration, system administration, and standard user functions? Partly Between LFW and clients, yes: the staff admin and the client portal are separate sites with separate sessions. Inside LFW, no: one person holds both the security and the system administration roles.
  • APPL-06 Do you subject your code to static code analysis and/or static application security testing prior to release? Partly Linting, a dependency audit of both production trees and the test suite run in a disposable container before every release and fail the release. There is no separate SAST product.
  • APPL-07 Do you have software testing processes (dynamic or static) that are established and followed? Yes An automated test suite on every release, browser checks on changed pages, and LFW Monitor’s daily checks of the live site.
  • FIDP-01 Are you utilizing a stateful packet inspection (SPI) firewall? Yes The server’s host firewall (netfilter through ufw), with Cloudflare in front.
  • FIDP-02 Do you have a documented policy for firewall change requests? Yes Firewall rules are in the provisioning script in version control; a change is a reviewed commit and a deploy.
  • FIDP-03 Have you implemented an intrusion detection system (network-based)? No No network intrusion detection system. Cloudflare’s firewall and DDoS mitigation sit in front of the server, and only Cloudflare can reach it on the web ports.
  • FIDP-04 Do you employ host-based intrusion detection? Partly fail2ban bans addresses after repeated failed connections. There is no broader host intrusion detection product.
  • FIDP-05 Are audit logs available for all changes to the network, firewall, IDS, and IPS systems? Yes Every change to the firewall or server configuration is a commit in version control, with its author and date, and a deploy log.
  • VULN-01 Are your systems and applications scanned with an authenticated user account for vulnerabilities (that are remediated) prior to new releases? No No authenticated scanner runs before a release. What runs: the dependency audit, the test suite, and LFW Monitor’s daily unauthenticated checks of headers, TLS and content policy.
  • VULN-02 Will you provide results of application and system vulnerability scans to the institution? Yes LFW Monitor’s daily check of LFW.com is public, and dependency audit output is shared on request.
  • VULN-03 Will you allow the institution to perform its own vulnerability testing and/or scanning of your systems and/or application, provided that testing is performed at a mutually agreed upon time and date? Yes At an agreed time, within the rules of the vulnerability disclosure policy at lfw.com/security.
  • DCTR-06 Does a physical barrier fully enclose the physical space, preventing unauthorized physical contact with any of your devices? Yes LFW owns no data center. The server is in Hetzner’s Ashburn facility; its physical controls are Hetzner’s, described in Hetzner’s published documentation, not verified on site by LFW.
  • DCTR-10 Are redundant power strategies tested? Yes Per the data center operator. LFW has not verified it on site.

AAAI

Authentication and audit.

How people sign in to the Client Portal, and what is logged.

  • AAAI-01 Does your solution support single sign-on (SSO) protocols for user and administrator authentication? Yes OpenID Connect, direct to your identity provider (for example Entra ID, Okta or Google Workspace). The redirect address is registered by your IT staff.
  • AAAI-02 For customers not using SSO, does your solution support local authentication protocols for user and administrator authentication? Yes An emailed link that works once and expires after 15 minutes, or a passkey. There are no passwords.
  • AAAI-03 For customers not using SSO, can you enforce password/passphrase complexity requirements (provided by the institution)? N/A There are no passwords to set rules for.
  • AAAI-04 For customers not using SSO, does the system have password complexity or length limitations and/or restrictions? N/A No passwords.
  • AAAI-05 For customers not using SSO, do you have documented password/passphrase reset procedures that are currently implemented in the system and/or customer support? N/A Nothing to reset. A new sign-in link replaces a lost one; a passkey can be enrolled again after signing in by email.
  • AAAI-06 Does your organization participate in InCommon or another eduGAIN-affiliated trust federation? No Not a member. SSO is configured per institution with your own identity provider.
  • AAAI-07 Are there any passwords/passphrases hard-coded into your systems or solutions? No Secrets live in a file on the server readable by root and the service account only. The repository holds none; the September 2026 review checked.
  • AAAI-08 Are you storing any passwords in plaintext? No LFW stores no passwords at all.
  • AAAI-09 Are audit logs available that include AT LEAST all of the following: login, logout, actions performed, and source IP address? Partly The portal records actions on requests and documents (an append-only history), every staff view of a client account, and used sign-in tokens. Web server logs hold the source address of each request. A per-user sign-in and sign-out report is not yet exposed to clients.
  • AAAI-11 Can you provide the institution documentation regarding the retention period for those logs, how logs are protected, and whether they are accessible to the customer (and if so, how)? Yes On request, in writing, for the logs named above.

DATA

Data.

Where institutional data sits in LFW’s systems, encrypted or not, and what happens to it at the end.

  • DATA-01 Will the institution's data be stored on any devices (database servers, file servers, SAN, NAS, etc.) configured with non-RFC 1918/4193 (i.e., publicly routable) IP addresses? Yes The one server has a public address. Its firewall accepts web traffic from Cloudflare’s ranges only and SSH by key; the database is a file on that server, readable by the service account alone.
  • DATA-02 Is the transport of sensitive data encrypted using security protocols/algorithms (e.g., system-to-client)? Yes TLS 1.3 to visitors, with a one-year HSTS policy; older TLS versions refused. Traffic between Cloudflare and the server is also encrypted.
  • DATA-03 Is the storage of sensitive data encrypted using security protocols/algorithms (e.g., disk encryption, at-rest, files, and within a running database)? Partly Backups are encrypted before they leave the server. The live database is protected by file permissions and the firewall; LFW does not claim disk encryption for it.
  • DATA-04 Do all cryptographic modules in use in your solution conform to the Federal Information Processing Standards (FIPS PUB 140-2 or 140-3)? No No FIPS validation is claimed.
  • DATA-05 Will the institution's data be available within the system for a period of time at the completion of this contract? Yes For 30 days after the end, during the handoff the services agreement sets out, and on request LFW exports your portal records.
  • DATA-06 Are ownership rights to all data, inputs, outputs, and metadata retained even through a provider acquisition or bankruptcy event? Yes Your content and data stay yours under the services agreement, and the work you pay for is yours once paid. A change in LFW’s ownership does not change that.
  • DATA-07 Do backups containing the institution's data ever leave the institution's data zone either physically or via network routing? Yes The server and its backups are in Ashburn, Virginia. The encrypted off-site copy is in Cloudflare R2 in Cloudflare’s default jurisdiction, which may place it outside the United States; the copy is encrypted before it leaves the server. Your website’s backups stay with your host.
  • DATA-08 Is media used for long-term retention of business data and archival purposes stored in a secure, environmentally protected area? Yes No physical media. Retention is in the data centers of Hetzner and Cloudflare.

ITAC

IT accessibility.

For the Client Portal and LFW.com, and for the sites LFW builds.

  • ITAC-06 Has a VPAT or ACR been created or updated for the solution and version under consideration within the past 12 months? Yes An Accessibility Conformance Report for LFW.com dated October 2, 2026 is published on the trust page. For a site LFW builds, a report is delivered at launch.
  • ITAC-07 Will your company agree to meet your stated accessibility standard or WCAG 2.1 AA as part of your contractual agreement for the solution? Yes For the templates and pages LFW builds and maintains, as the standard in your contract. LFW does not promise conformance by a date for content it does not control.
  • ITAC-08 Does the solution substantially conform to WCAG 2.1 AA? Yes LFW.com, per the self-prepared report: every Level A and AA criterion supports or does not apply. The report says it is not an independent audit.
  • ITAC-09 Do you have a documented and implemented process for reporting and tracking accessibility issues? Yes Report a barrier by email, as the accessibility statement says, or in the Client Portal. Findings are tracked as requests, and LFW Monitor rechecks pages daily.

PCOM, PTHP, PDAT, PRPO, DPAI

Privacy.

Breaches, third parties, the kinds of data LFW does not collect, and AI tools.

  • PCOM-01 Have you had a personal data breach in the past three years that involved reporting to a governmental agency, notice to individuals (including voluntary notice), or notice to another organization or institution? No None.
  • PTHP-01 Do you have contractual agreements with third parties that require them to maintain standards and to comply with all regulatory requirements? Yes Each provider’s standard terms and data processing terms.
  • PDAT-01 Do you collect, process, or store demographic information? No No.
  • PDAT-02 Do you capture or create genetic, biometric, or behaviometric information (e.g., facial recognition or fingerprints)? No No. A passkey’s biometric check happens on the user’s own device; LFW receives a public key only.
  • PDAT-03 Do you combine institutional data (including "de-identified," "anonymized," or otherwise masked data) with personal data from any other sources? No No.
  • PRPO-06 Do you have a privacy awareness/training program? No No formal program; one person. The privacy policy is the written rule.
  • PRPO-12 Do you share any institutional data with law enforcement without a valid warrant or subpoena? No No.
  • DPAI-02 Is any institutional data retained in AI processing? No LFW’s systems have no AI features. In LFW’s own work, AI tools may process client information to draft and check work; it is never used to train models, a person reviews every output, and any data you name in your contract is excluded.
  • DPAI-03 Do you have agreements in place with third parties or subprocessors regarding the protection of customer data and use of AI? Yes Anthropic’s commercial terms, which bar training on customer content. The subprocessor list on the trust page names each AI provider.

HIPA, PCID, AI sections

Not applicable, and why.

Critical questions the scoping answers rule out. Each is listed so your reviewer sees the ID was not skipped.

  • HIPA-01 to HIPA-04 HIPAA training, risk areas, tested plans, and business associate agreements. N/A LFW processes no protected health information (REQU-05).
  • PCID-01 to PCID-03 PCI DSS attestation, PA-DSS listing, and third-party cardholder data handling. N/A No card data passes through LFW’s systems (REQU-06). Payments on a client site go to the institution’s own processor.
  • AIGN-01 to AIGN-03 AI risk model, disabling AI features, responsible AI training. N/A No AI features in the solution (REQU-04).
  • AIPL-01 to AIPL-04 Posted AI policies, measured AI risks, disabling and re-enabling AI features after an incident. N/A No AI features in the solution (REQU-04).
  • AISC-01 to AISC-03 Removing data from a model, user input influencing a model, logging of AI actions. N/A No AI features in the solution (REQU-04).
  • AIML-01, AIML-02, AILM-01 to AILM-04 Machine learning training data separation and feedback; large language model privileges, training data, human intervention and plugins. N/A No AI features in the solution (REQU-04).

Send us your institution’s form.

HECVAT, a state questionnaire or your own spreadsheet. It comes back completed from these answers, with the policies it cites linked.