Information Security Commitment

VCPG

Veterans Covert Protection Group (“VCPG”) recognizes that security services frequently involve sensitive personal, operational, and corporate information. We are committed to maintaining appropriate administrative, technical, and physical safeguards to protect the confidentiality, integrity, and availability of the information entrusted to us.

This statement outlines our general security practices. Detailed security documentation may be provided under appropriate confidentiality agreements.

Legal

Legal

Legal

Effective Date:

January 01, 2026

1 — Governance & Oversight

VCPG maintains internal policies and procedures designed to safeguard sensitive information in compliance with applicable federal, state, and contractual requirements.

Security responsibilities are assigned to designated personnel to ensure:

  • Oversight of data protection practices

  • Ongoing risk assessment

  • Review of security controls

  • Incident response coordination

2 — Administrative Safeguards

We implement administrative controls designed to reduce risk and prevent unauthorized access, including:

  • Role-based access controls

  • Background screening of personnel as required by law

  • Confidentiality agreements

  • Secure handling procedures for client information

  • Data minimization practices

  • Periodic review of data access permissions

Access to sensitive information is restricted to authorized personnel with a legitimate business need.

3 — Technical Safeguards

VCPG utilizes commercially reasonable technical safeguards, which may include:

  • Secure communication platforms

  • Encrypted data transmission where appropriate

  • Secure storage systems

  • Access authentication mechanisms

  • Device protection controls

We take reasonable steps to protect against unauthorized access, disclosure, alteration, or destruction of information.

4 — Physical Safeguards

Given the nature of our services, we implement physical security controls appropriate to the operational environment, which may include:

  • Secure document handling procedures

  • Controlled access to sensitive materials

  • Secure disposal of physical records

  • Secure storage of operational information

5 — Confidentiality & Sensitive Operations

Executive protection and corporate security engagements may involve sensitive personal and operational information, including travel details, risk assessments, and security planning.

VCPG maintains strict confidentiality protocols and does not disclose client information except:

  • As required by law

  • As necessary to perform contracted services

  • With written client authorization

6 — Data Retention

Information is retained only for as long as necessary to:

  • Fulfill contractual obligations

  • Comply with legal requirements

  • Maintain appropriate business records

Retention periods vary based on the nature of the engagement and applicable regulations.

7 — Incident Response

VCPG maintains procedures to respond to suspected security incidents. In the event of a confirmed data breach involving personal information, notifications will be made in accordance with applicable law and contractual obligations.

8 — Regulatory & Contractual Compliance

VCPG operates in accordance with:

  • Applicable California data protection requirements

  • Federal privacy and security obligations where applicable

  • Contractual security requirements imposed by corporate and government clients

Additional security documentation may be made available upon request and subject to non-disclosure agreements.

9 — Continuous Improvement

Security threats evolve. VCPG reviews and updates its safeguards as necessary to address emerging risks and maintain alignment with industry standards.