STIG Craft Data Handling Statement

Pre-release edition, for information systems security managers and authorizing officials. The in-app edition adds the running build's privacy test results and this device's state.

Data flow

  1. The browser downloads the STIG Craft application from stigcraft.com (read-only HTTPS GET).
  2. The application downloads public DISA STIG reference data from stigcraft.com (read-only HTTPS GET, no request body, no cookies).
  3. Files the user opens are read locally by the browser. They are never uploaded.
  4. Checklists, hosts, results, settings and original files are stored in the browser's IndexedDB and Origin Private File System on the user's device.
  5. Backups are STIG Craft Archive Packs that the user saves and moves themselves. Nothing is synchronized to any server.

Hosting and logging

Technical enforcement

Limits