This Security Statement describes the administrative, technical, and physical
practices EverRise Performance LLC applies to the design, deployment, and
management of ACE. It is intended to give prime contractors, government buyers,
and procurement teams a clear picture of how we approach security, and where
responsibility sits between EverRise and the client under our deployment model.
01 / Approach
Our Approach to Security
EverRise builds ACE around the principle that security is a property of the
whole system, not a feature added at the end. We apply reasonable
administrative, technical, and physical safeguards throughout the design,
deployment, and management of the platform, and we structure our engagements
so that clients retain visibility and control over their own environment.
EverRise Performance does not currently hold formal third-party security
certifications (such as SOC 2 or ISO 27001). We are transparent about this,
and we're glad to walk prospective clients through our current practices,
architecture, and roadmap as part of a platform assessment or security review.
02 / Shared Responsibility
Deployment and Shared Responsibility
ACE is deployed using a Bring Your Own Cloud (BYOC) model. The client
provisions and controls the underlying infrastructure; EverRise licenses and
manages the proprietary software layer that runs within it. Security is
consequently a shared responsibility.
Client Responsibility
Provisioning, securing, and maintaining the underlying cloud
infrastructure, network boundary, and identity environment in which ACE
is deployed, consistent with the client's own security and compliance
obligations.
EverRise Responsibility
Secure design, configuration, and management of the ACE software layer
itself, including access to the platform for support, updates, and
agreed operational tasks.
Data Residency
Because the client controls the environment, client data processed by
ACE generally remains within infrastructure the client owns, rather than
being transferred into infrastructure operated by EverRise.
03 / Data Protection
Data Protection
We apply commercially reasonable measures intended to protect data in
transit and at rest, including the use of encrypted connections between
components of the platform and the systems it interacts with.
Encryption in Transit
Communication between ACE components and connected services is designed to occur over encrypted channels.
Data Minimization
ACE is configured to process the data relevant to a client's defined workflows, rather than broad, undifferentiated data collection.
Retention
Retention of business-contact and platform-administration data is limited to what is necessary for service delivery and legal compliance, as described in our Privacy Policy.
04 / Access
Access Controls
Access to client environments and platform administration functions is
restricted to authorized EverRise personnel who require it to deliver the
agreed services, and is scoped according to the engagement.
Least Privilege
Internal access to client-related systems is limited to personnel with an operational need, for the purposes agreed in the services contract.
Authentication
Administrative access to platform tooling is protected by authentication practices intended to reduce the risk of unauthorized use.
Client-Side Controls
Because the client controls the underlying infrastructure under the BYOC model, the client also retains the ability to configure, restrict, or revoke EverRise's access at any time.
05 / Subprocessors
Third-Party and Subprocessor Security
To provide certain platform capabilities, ACE relies on third-party AI and
automation providers (for example, OpenAI, Anthropic, Make.com, and Zapier).
These providers maintain their own independent security programs. EverRise
selects subprocessors with attention to their published security and privacy
practices, and discloses their use as described in our Privacy Policy.
06 / Vulnerability Management
Vulnerability and Patch Management
EverRise monitors the components of ACE for known vulnerabilities and applies
updates and patches to the software layer under our control on a reasonable
timeline based on severity. Where a vulnerability lies in infrastructure
controlled by the client under the BYOC model, remediation is coordinated with
the client.
07 / Incident Response
Incident Response
EverRise maintains an internal process for responding to suspected security
incidents affecting the ACE software layer, including triage, containment,
and client notification. Because client data generally resides in
client-controlled infrastructure under the BYOC model, clients should also
maintain their own incident response procedures for their environment, and we
coordinate with clients on shared incidents as part of the services agreement.
08 / Federal Considerations
Government and Federal Considerations
For prime contractors and government buyers, security expectations are often
formalized through procurement documentation rather than a public statement
alone. The following reflects how our model interacts with that process.
No Public Intake of Sensitive Data
We do not accept classified national security information or Controlled
Unclassified Information (CUI) through this website or during a standard
platform assessment.
Security Questionnaires
We can complete client-provided security questionnaires, discuss our
practices in more detail, and negotiate applicable safeguards as part of
a signed services agreement or procurement process.
Regulatory Responsibility
Government and prime contractor clients remain responsible for ensuring
their own use of ACE, and their own infrastructure under the BYOC model,
complies with applicable federal requirements. This statement describes
our current practices and is not a certification of compliance with any
specific federal security framework.
Requesting a platform assessment is the fastest way to get a detailed,
engagement-specific answer to a security questionnaire, rather than relying
on this page alone.
09 / Disclosure
Responsible Disclosure
If you believe you've found a security vulnerability affecting ACE or the
EverRise Performance website, we want to hear from it. Please report it to
[email protected]
with enough detail to reproduce the issue.
We ask that you avoid accessing, modifying, or exfiltrating data beyond what
is necessary to demonstrate the issue, and that you give us a reasonable
opportunity to investigate and address a report before disclosing it publicly.
We do not currently operate a paid bug bounty program.
10 / Contact
Contact
Security-related questions, reports, and procurement security questionnaires can be directed to: