Security
Last updated: August 7, 2026
1. Our Approach
This Site is a public marketing and informational website. It does not process payments, store classified information, or accept Controlled Unclassified Information (CUI) or export-controlled technical data. We intentionally keep the Site’s footprint small — collecting only what is described in our Privacy Policy — to limit exposure and reduce risk to visitors.
2. Website Protections
- All traffic to the Site is served over an encrypted HTTPS connection.
- The contact form is the Site’s only data-collecting feature; submissions are transmitted server-side and are not stored in a public-facing database.
- The Site does not request or store passwords, payment card data, or government identifiers.
- Dependencies and hosting infrastructure are kept current to reduce exposure to known vulnerabilities.
Our internal engineering and cybersecurity practice — the same discipline behind our defense and systems integration work — is applied to how we build and maintain this Site.
3. Reporting a Vulnerability
If you believe you’ve identified a security vulnerability affecting this Site, we want to hear from you. Please email info@keystoneshieldllc.com with the subject line “Security Disclosure” and include:
- A description of the vulnerability and its potential impact;
- Steps to reproduce it, including the affected URL(s), request/ response details, or a proof of concept; and
- Any tools used, so we can accurately reproduce your findings.
We aim to acknowledge reports within 3 business days and will follow up as we investigate. Please allow us reasonable time to remediate before any public disclosure.
Scope
This policy covers keystoneshieldllc.com and its subdomains only. It does not cover Department of Defense systems, customer or partner environments, or third-party services we link to or rely on (e.g., email providers, analytics, or hosting platform infrastructure) — please report those directly to the relevant provider.
Good-Faith Research (Safe Harbor)
We will not pursue legal action against researchers who make a good-faith effort to comply with this policy, provided you:
- Avoid privacy violations, data destruction, or interruption of service (no denial-of-service testing);
- Do not access, modify, or exfiltrate more data than necessary to demonstrate the vulnerability, and never access data belonging to another user;
- Do not use social engineering, phishing, or physical attacks against Keystone Shield personnel or facilities; and
- Give us a reasonable opportunity to investigate and remediate an issue before disclosing it publicly.
Testing that falls outside this scope, or that violates the above, may be treated as unauthorized activity rather than good-faith security research. See our Terms of Service for Site usage rules more generally.
4. Reporting Suspected Fraud or Impersonation
If you encounter a website, email, or communication impersonating Keystone Shield LLC, please report it to info@keystoneshieldllc.com so we can investigate.
5. Questions
For any other security-related questions, contact:
Keystone Shield LLC
429 Fourth Ave, STE 300, Pittsburgh, PA 15219
info@keystoneshieldllc.com · 412-492-3398
