Trust · Security & Compliance
Security & Compliance
Last updated: September 7, 2026
IronCAD is dispatch and operations software for emergency response teams, operated as a hosted service by Ironclad Thor Industries LLC. This page describes the controls actually in place today and — just as important for an agency doing procurement — the ones that are not. Where a control belongs to one of our infrastructure providers rather than to us, we name the provider so you can review their documentation directly instead of taking our word for it.
If you need something on this page in writing for a procurement file, email contact@ironcladthor.com and say what your agency requires.
1. How the service is delivered
IronCAD is fully hosted. Agencies do not install or maintain servers. The service runs as three separate components, each on managed cloud infrastructure in the United States:
- The dispatch console your team signs in to, at your agency workspace URL.
- The application API, which every client talks to and which enforces authentication and per-agency access rules.
- This marketing site and checkout, which is separate from the application and holds no operational agency data.
Each agency is provisioned its own workspace. Access to agency records is scoped to that agency by the API; a user's account is bound to exactly one agency.
2. Authentication and access control
- Role-based access across the whole agency — roles determine what a user can see and change.
- Email two-factor authentication is available on every plan, including Starter.
- Single sign-on (SSO) is available on Enterprise & Tactical.
- Account provisioning is administrative. The subscriber becomes the first admin for the agency and invites the rest of the team; there is no open self-registration into an existing agency workspace.
- Password setting and invitation acceptance happen over a one-time link sent to the user's email address, not over a shared credential.
3. Data protection
- In transit: all traffic to IronCAD is encrypted with TLS. The application and this site send HTTP Strict Transport Security, so browsers refuse to downgrade to plaintext.
- At rest: agency data is held in a managed PostgreSQL database and managed object storage operated by our infrastructure providers (named in section 5), which encrypt data at rest as a platform default. We do not currently offer customer-managed or bring-your-own encryption keys. If your agency requires CMEK/BYOK, tell us before you buy.
- Payment data: card payments are processed by Stripe. Full card numbers are provided directly to Stripe and are not stored on IronCAD systems. We receive only limited billing metadata — card brand, last four digits, expiration status, and transaction outcome.
- Data minimisation: we collect only what is needed to operate the service, and we do not sell personal data, process it for targeted advertising, or use your operational records for anything other than running, securing, backing up and improving the service for you. This is stated bindingly in our Privacy Policy.
4. Web application hardening
Every response from IronCAD's web tier carries the following headers. These are verifiable from outside — inspect them yourself:
| Header | Value and effect |
|---|---|
| Strict-Transport-Security | max-age=15552000; includeSubDomains — forces HTTPS for 180 days, including subdomains. |
| Content-Security-Policy | Restricts which origins may supply scripts, styles and other resources, limiting the impact of injected content. |
| X-Frame-Options | DENY — the site cannot be framed, defeating clickjacking. |
| X-Content-Type-Options | nosniff — browsers must honour declared content types. |
| Referrer-Policy | no-referrer — URLs are not leaked to third parties in the referrer header. |
Unknown URLs return a real HTTP 404. The application does not serve a 200 for arbitrary paths.
5. Subprocessors
We use a small, named set of service providers. Each is contractually limited to using data only to provide services to us. This list is the same one published in our Privacy Policy, and it is the complete list.
| Provider | Purpose |
|---|---|
| Stripe | Payment processing and subscription billing |
| Render | Application and API hosting |
| Supabase | Database and authentication |
| Cloudflare | Content delivery and network security |
| Google Workspace | Email delivery |
We will notify subscribing agencies before adding a subprocessor that processes agency operational data.
6. Backups, retention and getting your data out
- Automatic backups run as part of the hosted service; agencies do not manage them.
- Retention: we keep agency data for as long as the account is active and as needed to provide the service.
- Exit: after termination your data is available for export for thirty (30) days, after which it is deleted in the ordinary course of our backup cycles. Billing and transaction records are retained where tax, accounting and legal obligations require it.
- You own your records. Incident records, unit and apparatus data, personnel rosters, location and map data and documents created in IronCAD remain your agency's property. This is stated in section 8 of our Terms of Service.
7. Availability and monitoring
Uptime monitoring is part of the hosted service, and the marketing site exposes a machine-readable health endpoint used by our own monitoring. A formal, contractual service level agreement (SLA) is offered on the Enterprise & Tactical plan; Starter and Professional are provided without a contractual uptime commitment. If your agency needs an SLA, that is an Enterprise conversation and we would rather have it before you subscribe than after.
8. Vulnerability management
Dependencies are monitored for published advisories and patched on an ongoing basis as part of routine maintenance. Security-relevant changes are tracked in version control and deployed through the same reviewed pipeline as all other changes.
Reporting a vulnerability. If you believe you have found a security issue in IronCAD, email contact@ironcladthor.com with the subject line "Security Report". Please include enough detail to reproduce the issue. We will acknowledge your report and will not pursue action against good-faith research that avoids privacy violations, service degradation, and access to data that is not yours.
9. Incident response and breach notification
If we learn of a breach of security affecting personal information, we will notify affected users as required by the Maryland Personal Information Protection Act, Md. Code Ann., Com. Law § 14-3501 et seq., and other applicable law. Agency administrators are notified through the contact addresses on the account.
10. Certifications — what we have, and what we do not
This section is deliberately blunt, because a procurement officer is going to ask and a vague answer wastes everyone's time.
- SOC 2: IronCAD has not completed a SOC 2 Type I or Type II audit. We cannot provide a SOC 2 report.
- CJIS: IronCAD has not been audited against the FBI CJIS Security Policy, and we do not currently execute the CJIS Security Addendum. Do not enter Criminal Justice Information into IronCAD without first contacting us and confirming, in writing, that your intended use is appropriate. If CJIS coverage is a requirement for your agency, tell us — we would rather lose the sale than have you place CJI in a system that has not been assessed for it.
- FedRAMP / StateRAMP: no authorization.
- HIPAA: IronCAD is not offered as a HIPAA business associate and we do not sign Business Associate Agreements. The service is not intended for protected health information.
- Data residency: the service is operated from the United States. We do not currently offer a choice of region or a data-residency commitment beyond that.
Where a control above is provided by a subprocessor, that provider may hold its own attestations — Stripe, Render, Supabase, Cloudflare and Google each publish their own compliance documentation. Their certifications are theirs, not ours, and we will not represent them as IronCAD's.
11. What remains your agency's responsibility
IronCAD supports — and does not replace — your agency's dispatch policies, procedures, training, and the requirements of your authority having jurisdiction. Your agency remains responsible for its own call-handling and response decisions; for compliance with the 911/E911/NG911, FCC and state emergency-number requirements that apply to it; and for maintaining backup and continuity-of-operations procedures, including an independent means of dispatch and communications, for use if the service is degraded or unavailable. Like any networked software, IronCAD depends on connectivity and infrastructure outside our control, and operational data may be delayed, incomplete or unavailable. Critical information should be verified through your established procedures before operational decisions are made. This is set out in full in section 11 of our Terms of Service.
IronCAD is not for public emergency reporting. If you are a member of the public experiencing an emergency, call 911 or your local emergency number.
12. Contact
Ironclad Thor Industries LLC d/b/a IronCAD — PO Box 307, Linthicum Heights, MD 21090 — contact@ironcladthor.com.
This page describes the state of the service as of the date above and is provided for information. It does not amend the Terms of Service, the Privacy Policy, or any signed agreement, and where it differs from those documents, they govern.