Legal
Security & Data-Retention Policy
Last updated · July 13, 2026
This policy explains how Applied America secures the Applied America OS, what business and security activity we monitor, who may access it, and how long we keep it. It complements our Privacy Policy, Terms of Use, and Cookie Notice, and reflects our principle that oversight exists to protect the platform and its users — not to surveil them.
Security Program
We apply administrative, technical, and organizational safeguards designed to protect the platform and the confidential project, capital, and organizational information it holds. These include access controls, transport encryption, security headers and a content-security policy, least-privilege administration, and audit logging of sensitive actions. No system is perfectly secure, and we do not guarantee absolute security.
What We Monitor
For authenticated platform accounts we record business and security activity for security, compliance, auditability, and support:
- Authentication & sessions — sign-in / sign-out, session duration, IP address, approximate IP-based location, network provider, device, browser, and operating system.
- In-app activity — pages and modules opened, projects and capital rooms viewed, documents viewed or downloaded, forms submitted, searches, and access requests made or decided.
- Security events — failed sign-ins, permission-denied events, unusual download volume, new-device or new-location logins, and related risk indicators.
IP-based location is approximate and is not a verified physical address. We do not conduct covert screen recording; where activity reconstruction is needed, it is assembled from the event log described above. We do not sell activity data.
Administrative Access (Tiered)
Access to monitoring and analytics is restricted by role, on a need-to-know basis, and every administrative access is itself logged:
- Analytics Viewer — aggregate analytics only.
- Security Admin — login, IP, security, and risk records.
- Compliance Admin — audit logs, legal flags, and public-records review.
- Platform Admin — operational and usage analytics.
- Super Admin — full visibility, with all access logged.
Data-Retention Schedule
The following are baseline targets; exact periods are reviewed by counsel and may vary by jurisdiction and legal hold:
- Security event logs — 1–7 years
- Audit logs — 3–7 years
- Login / session records — 1–3 years
- Document access logs — 3–7 years
- Page & interaction analytics — 12–24 months
- Aggregated / de-identified analytics — retained longer
- Export logs — 3–7 years
- Support records — 2–5 years
- Deleted-account records — only as legally necessary
- Sensitive Tribal Affairs records — special retention and deletion rules approved by governance, with data-sovereignty protections and strict access controls.
Safeguards & Governance
- Role-based access to all monitoring and analytics.
- Data minimization — we collect what oversight and security require, and no more.
- Sensitive-field masking and export controls, with approval required for sensitive exports.
- Legal review for any surveillance-sensitive feature before release.
- No sale of user-activity data; no hidden tracking beyond what we disclose.
Prototype Notice
During the platform’s prototype phase, activity is captured only within the current browser for demonstration, and server-only signals (such as IP address and geolocation) are not collected. Authoritative, server-side capture, append-only audit logging, and enforced retention activate when the secure backend is deployed. This notice will be updated accordingly.
Reporting a Concern
To report a security vulnerability or a concern about how activity is monitored or retained, contact applied@thecefa.org.
Questions about this policy? Write to applied@thecefa.org.