Privacy statement
What this site collects, what it does not, and how to report a vulnerability.
What this site collects
This is a static website. It has no accounts, no login, no sign-up, and no forms. We do not set cookies, and we do not run analytics or advertising trackers.
Two things are worth stating precisely:
- Fonts. Typefaces load from Google Fonts. Your browser makes a request to
fonts.googleapis.comandfonts.gstatic.com, which discloses your IP address to Google under their privacy policy. We do not receive that data. Self-hosting the fonts removes this entirely and is a change we intend to make. - Server logs. Our host records standard request logs, which may include IP address, user agent, and requested path. These are used for operating and securing the site.
Email you send us
If you email an address on this site, we hold that correspondence to respond to you and to maintain a record of contracting enquiries. We do not sell it, and we do not add you to a marketing list.
Information in systems we build
Systems Fed.tech delivers under contract hold data belonging to the contracting agency, governed by that contract and by the agency’s System of Records Notice where applicable. This statement covers only this website.
Vulnerability disclosure
If you believe you have found a security vulnerability in this site or in a system we operate, email [email protected].
- We acknowledge reports within two business days.
- We will not pursue legal action against good-faith research that avoids privacy violations, service degradation, and data destruction.
- Please give us reasonable time to remediate before public disclosure.
- Do not access, modify, or exfiltrate data that is not yours.
If the vulnerability is in a federal system rather than one we operate, report it to that agency’s disclosure programme.
Changes
Material changes to this statement will be reflected in the review date below.
LAST REVIEWED 2026-10