Security
Security & Trust
Updated August 19, 2026
This page states plainly what Viceroy NM holds today, what is in progress, and what is not held, so that customer security teams, assessors, and contracting officers do not have to reconcile marketing language against evidence. Where the rest of this site says "aligned" or "target," it means a design or operating standard, not a certification, authorization, or registration; this page is the authoritative status.
Held today
- ATF Federal Firearms License (FFL), a federal license held by Viceroy NM
- Active SAM.gov registration, UEI NZRVCN4KLUY1, CAGE 9W6T9 (current status is verifiable on SAM.gov)
In progress
- Accessibility Conformance Report (ACR / VPAT) for this website, in preparation; it will be published from the Accessibility Statement
- Claim substantiation file for published performance representations, maintained internally and available to contracting officers on request
Not held
- CMMC certification or SPRS-recorded self-assessment. Systems are engineered to CMMC Level 2 control alignment as a design standard; no certification is held.
- FedRAMP authorization. Architecture is FedRAMP-aligned as a design standard; no FedRAMP package, In Process designation, or sponsoring agency exists.
- SOC 2 report or ISO 27001 certificate. Security practices are SOC 2-aligned as an operating standard; no independent attestation has been issued.
- DDTC (ITAR) registration. Handling processes are ITAR-aware as an operating practice; export-regulated engagements are scoped and confirmed per contract.
Hosting stack and shared responsibility
This public website is a static site hosted on Render and delivered through Cloudflare's network; public forms send to a separate lead API service, also on Render, backed by managed PostgreSQL. Platform-level physical, environmental, and infrastructure controls for this website sit with those providers under their own compliance programs; application-level controls, content accuracy, transport policy, and data handling sit with Viceroy NM. This website does not run in AWS GovCloud or a FedRAMP-authorized environment, and website security measures do not establish the posture of any product deployment. Product deployments are scoped per engagement, including AWS GovCloud, on-premise, or air-gapped environments where a program requires them.
Public website scope
The marketing website is static and delivered over HTTPS. Public forms send information to a separate API designed to enforce an origin allowlist, JSON-only requests, field and body limits, throttling, and security response headers. Records are stored in managed PostgreSQL and are subject to the retention periods in our Privacy Notice.
Do not send restricted data
The website, contact form, job application, and email addresses published here are not approved channels for CUI, classified material, export-controlled technical data, procurement-sensitive or source-selection information, credentials, health data, financial account data, or other restricted information. Obtain a written authorized channel before transmission.
Product and government boundaries
Website security measures do not establish the security, accreditation, authorization, CMMC, FedRAMP, NIST, ITAR, DFARS, or classification posture of any customer, contract, product, or deployment. Those determinations require the exact scoped boundary, configuration, evidence, agreement, and applicable official approval.
Report a vulnerability
Email security@viceroynm.com with the affected URL, reproduction steps, potential impact, and safe contact details. Do not access another person's data, persist, disrupt service, exfiltrate information, or publish before coordinated review. We do not authorize testing that violates law or third-party terms.
