LEGAL
Last updated: July 2026
PRIVACY POLICY
Harpy Industries (“Harpy,” “we,” “us,” or “our”) respects your privacy and treats business contact information with professional care. This Privacy Policy explains how we collect, use, and safeguard information when you interact with our website or engage our services.
Information We Collect
We may collect information you voluntarily provide, including name, email address, company name, phone number, facility or program context, and any details submitted through inquiry channels. We may also collect limited technical data such as browser type, device information, and IP address for security, diagnostics, and site performance.
How We Use Information
Information is used to respond to inquiries, evaluate service fit, deliver contracted support, maintain professional records, and improve our website. We do not sell personal information.
Sensitive & Controlled Information
Do not submit classified information, Controlled Unclassified Information (CUI), export-controlled data, or other restricted government information through this website, email, or any unapproved channel. Harpy will not request, and should not receive, protected information outside approved government or contractual handling methods.
Data Protection
We apply reasonable administrative, technical, and physical safeguards appropriate to the type of information we handle. No system is perfectly secure. Clients remain responsible for protecting their own networks, systems, and controlled information environments.
Contact
For privacy-related questions, contact hello@harpyindustries.com.
TERMS OF SERVICE
By accessing this website or engaging Harpy Industries for services, you agree to these Terms.
Services
Harpy Industries provides contracted Facility Security Officer (FSO) support, Personnel Security (PERSEC) support, and related security program consulting for DoD contractors and cleared industry partners. Scope, responsibilities, deliverables, and fees are defined only in a written agreement between Harpy and the client.
No Assumption of Program Ownership
Unless expressly stated in a signed agreement, Harpy does not assume ownership of a client’s security program, Facility Clearance, personnel security records, or compliance obligations. Support is provided to assist the client organization in meeting its own responsibilities.
Client Obligations
Clients are responsible for timely access to required points of contact, accurate information, internal coordination, and decisions reserved to company leadership or the appointed security authority. Clients remain accountable for compliance with applicable laws, regulations, contract clauses, and government security requirements.
Limitation of Liability
To the fullest extent permitted by law, Harpy Industries shall not be liable for indirect, incidental, special, or consequential damages arising from the use of this website or from consulting services, including but not limited to inspection findings, clearance actions, contract impacts, or third-party decisions. Aggregate liability is limited as set forth in the governing service agreement.
Governing Law
These Terms are governed by the laws of the State of Texas.
DATA & SECURITY DISCLAIMER
Harpy Industries provides Facility Security Officer and Personnel Security consulting and operational support. This work is professional, advisory, and process-oriented. It is not a substitute for a company’s legal counsel, cyber security program ownership, or government direction.
Classified Information
Classified information must never be transmitted to Harpy through email, web forms, chat, cloud links, or any unapproved channel. Handling of classified information is permitted only within authorized facilities, systems, and procedures approved for that classification level. Harpy does not accept classified material through public or commercial communication paths associated with this website.
Controlled Unclassified Information (CUI)
Controlled Unclassified Information, including CUI marked or unmarked information requiring safeguarding, must be handled according to applicable government and contractual requirements. Clients must not send CUI to Harpy unless a written agreement, approved channel, and required safeguarding measures are in place. Unauthorized transmission of CUI creates risk for the client and is outside the intended use of this website.
CMMC, NIST, and Cyber Requirements
Where clients are subject to CMMC, NIST SP 800-171, DFARS cyber clauses, or related cybersecurity requirements, Harpy may provide process guidance and coordination support related to security program operations. Harpy does not, by default, act as a Registered Provider Organization assessment body, C3PAO, or system accreditation authority. Cybersecurity architecture, system hardening, evidence packages, and formal certification outcomes remain the responsibility of the client and its designated cyber/IT providers unless expressly contracted otherwise in writing.
Facility Clearance & PERSEC Responsibility
Maintenance of a Facility Clearance, personnel security actions, reporting obligations, self-inspections, and day-to-day compliance remain the responsibility of the cleared company and its authorized officials. Harpy supports these functions under agreed scope. Final accountability for government security requirements stays with the client organization.
No Legal or Government Advice
Communications from Harpy are not legal advice, are not formal government guidance, and do not replace direction from DCSA, contracting officers, cognizant security authorities, or qualified legal counsel. Regulatory interpretation can change. Clients should validate critical compliance decisions through official channels.
Operational Reality
Security programs fail in the gaps: incomplete records, informal workarounds, delayed reporting, and unclear ownership. Harpy’s role is to help reduce those gaps through disciplined process and practical support. Results still depend on client cooperation, internal decision-making, and honest execution of required controls.