Pre-release edition, for information systems security managers and authorizing officials. The in-app edition adds the running build's privacy test results and this device's state.
Data flow
The browser downloads the STIG Craft application from stigcraft.com (read-only HTTPS GET).
The application downloads public DISA STIG reference data from stigcraft.com (read-only HTTPS GET, no request body, no cookies).
Files the user opens are read locally by the browser. They are never uploaded.
Checklists, hosts, results, settings and original files are stored in the browser's IndexedDB and Origin Private File System on the user's device.
Backups are STIG Craft Archive Packs that the user saves and moves themselves. Nothing is synchronized to any server.
Hosting and logging
Static files in a private Amazon S3 bucket, served by Amazon CloudFront. There is no application server, database, account system, analytics, telemetry or error-reporting service.
Every path accepts only GET and HEAD. Requests carrying data are refused at the edge.
CloudFront access logging and S3 server access logging are disabled. CloudFront still processes the IP address of each request in order to deliver it.
Technical enforcement
Content-Security-Policy with connect-src 'self', form-action 'none', script-src 'self' and Trusted Types.
A single GET-only network module; lint rules ban every other network API in the source.
A service-worker egress guard and an in-app Network Ledger of every request.
A continuous-integration privacy canary that fails any build in which planted markers appear in a request.
Limits
STIG Craft cannot protect data from a compromised device, operating system or browser extension.
Browser storage can be cleared by the user, by browser policy or, for Safari tabs, after seven days without use. Users must keep Archive Pack backups.
Exported files are ordinary files: operating-system indexing, download history and download-protection services may record their names.
Optional encryption (Vault Lock, encrypted packs) uses FIPS-approved algorithms through the browser's Web Crypto API. STIG Craft makes no claim of FIPS 140 module validation (SC-13); the authorizing official determines sufficiency.