Service-disabled veteran-owned. Mobile on-site destruction anywhere in the lower 48.330-704-1641    contact@mansfieldtech.us

Trust and security

A company that destroys other people's data should say how it protects its own operation. This is how we vet people, control custody, protect records, and stand behind the work.

People

Every member of our team is a U.S. citizen who has passed a criminal background check. The team is veterans, National Guard and Reserve members, and former Intelligence Community members, and many hold individual security clearances through their Guard or Reserve service. Every technician is trained on the equipment and the standards before working a job alone, and two technicians handle every item, both recorded on the certificate.

Equal opportunity

Mansfield Technologies is an equal opportunity employer. Qualified applicants receive consideration for employment without regard to race, color, religion, sex, national origin, age, disability, genetic information, or protected veteran status. Veterans, National Guard and Reserve members, and people with disabilities are encouraged to apply. Every position requires U.S. citizenship and a criminal background check, and some require the ability to obtain a security clearance.

Facility clearance

Mansfield Technologies does not hold a facility clearance (FCL). We intend to obtain one and welcome a sponsoring contract. In the meantime, classified destruction works the way the NISPOM (32 CFR Part 117) contemplates for a cleared facility: the classified material stays in your custody, on your premises, under the continuous observation of your appropriately cleared personnel from the moment it leaves storage until it is destroyed. Our technicians operate the equipment; your cleared staff supervise, witness, and sign. For Top Secret material, your two authorized persons satisfy the two-person destruction rule. Because classified media never enters our custody and never leaves your site, an FCL is not required for this arrangement, and your FSO or security office confirms the conditions before we come. The individual clearances our people hold through military service are theirs, not the company's, and we do not represent them as a facility clearance.

Custody

Media is destroyed at your site, where you can see it, which is the strongest custody control there is. When media must be staged, it goes into totes closed with two numbered tamper-evident seals, and the tote and seal numbers are recorded on the log. Shred by Mail packages are photographed sealed on arrival and logged before they are opened. Nothing is stored, tested, read, or resold.

Records

Certificates, media logs, and customer records are stored encrypted, behind multi-factor authentication, on devices that are themselves encrypted, with access limited to the people who need it. Certificates are digitally signed, so any change after signing is detectable. We keep records for the audit period on the certificate and longer where your contract requires.

Equipment

Our degausser and disintegrator are on the NSA/CSS Evaluated Products Lists by model number, tested before each session as the manual requires, and maintained with critical spares on the truck. Every machine is American-made. The equipment page lists each one and its listing.

Insurance

We carry commercial general liability of $1 million per occurrence and $2 million aggregate, pollution liability of $1 million, technology professional liability (errors and omissions) of $1 million, cyber and privacy liability of $1 million including network security, privacy, and incident response, and commercial automobile liability of $1 million for our trucks and trailer plus $1 million for hired and non-owned vehicles. Three of those matter more in this business than in most: pollution coverage for the truck and the material it carries, professional coverage for the advice we give when we consult, and cyber and privacy coverage for the records we hold about your hardware. Certificates of insurance naming your organization as certificate holder, with additional-insured endorsements where your contract requires them, are available on request before a job.

Our own security program

We hold ourselves to the same frameworks we help clients meet. Mansfield Technologies has completed the CMMC Level 1 self-assessment and affirmed it in SPRS, covering the fifteen basic safeguarding requirements for federal contract information, and runs a written program aligned with CIS Controls and NIST 800-171 with the incident response plan a client would expect us to have. We destroy our own retired media the same way we destroy yours.

CJIS and other agency requirements

Law enforcement agencies may require the CJIS Security Addendum and fingerprint-based background checks for vendors. Our process does not require access to criminal justice information, because the media stays in your custody and is destroyed under your authorized personnel's supervision, but if your agency requires the Addendum and the checks, we sign and our technicians submit to them.

NAID AAA

We are not NAID AAA certified. That program was built around paper shredding and the security of off-site destruction plants; our work is electronic media, destroyed on your site while you watch, on NSA-listed equipment, with a serial-level certificate. If a vendor policy lists NAID AAA, we will answer the questionnaire behind it, and the answers are on this page.

If something goes wrong

If we ever have an incident involving your information, we notify you as Ohio law and your contract require, tell you what happened in plain language, and show you the record. Questions about any of this: contact@mansfieldtech.us.

Due diligence kit

What vendor-management and procurement programs ask every vendor for, assembled once. The public documents are downloads; the ones with your organization's name on them come by email before the job.

  • UEI, CAGE, NAICS, PSC, past performance, equipment, standards, insurance summary.
  • The signed letter with the client redacted, and the media log columns. Explained field by field.
  • Our standard HIPAA BAA, two pages, for covered entities and business associates. We will sign yours instead if you prefer.
  • A disposal log template for NIST 800-171 requirement 3.8.3, with an example row, to attach to a System Security Plan.
  • A one-page summary for public entities: who we are, what a job includes, the standards it meets, and how to buy.
  • Security summary
    This page: people, custody, records, equipment, insurance, equal opportunity, CMMC status, facility clearance status.
  • By email, before the job
    Certificate of insurance naming your organization with additional-insured endorsements as required, W-9, past-performance references, and any vendor questionnaire, returned with supporting documents, usually within a week. Ask.

Want a certificate of insurance or a security questionnaire completed?

Contact us