Effective January 1, 2026

Phoenix Consultants Group, Inc. (“Phoenix”) maintains administrative, physical, and technical safeguards designed to protect Customer Data processed through the FireFlight Data Systems platform against unauthorized access, disclosure, alteration, loss, or destruction.

FireFlight Data Systems is hosted on infrastructure owned and operated by Phoenix at 9 Wilson Drive, Northfield, New Jersey 08225. Phoenix does not use a third-party public cloud provider to host Customer Data.

Infrastructure and Physical Security

  • Infrastructure supporting FireFlight is owned and operated by Phoenix.
  • Physical access is limited to authorized personnel.
  • Customer Data is not hosted in a third-party public cloud environment.

Encryption

  • Customer Data is encrypted in transit using TLS 1.2 or higher across public networks.
  • Customer Data at rest, including backup media, is encrypted using AES-256 or an equivalent industry-standard algorithm.

Access Controls

  • Access to Customer Data is limited according to least-privilege and role-based access principles.
  • Individuals with access are assigned unique credentials.
  • Multi-factor authentication is required for administrative access.
  • Access is revoked promptly when employment or engagement ends.

Logging and Monitoring

  • Phoenix maintains system and access logs sufficient to investigate suspected Security Incidents.
  • Relevant logs are retained for at least 60 days.

Vulnerability and Patch Management

  • Security patches are applied on a risk-prioritized basis.
  • Patches addressing critical vulnerabilities are applied within 30 days of availability.

Backups and Recovery

  • Customer Data is backed up regularly.
  • Backup copies are encrypted and stored at a geographically separate location.
  • Restoration from backup is tested at least annually.

Incident Response

  • Phoenix maintains a documented incident response plan that is reviewed at least annually.
  • Phoenix will notify an affected Customer without undue delay, and in any event within 72 hours after confirming a Security Incident affecting Customer Data.
  • Phoenix will provide known details, take reasonable mitigation and remediation steps, and cooperate with the Customer’s applicable notification obligations.

Personnel Security

  • Background screening is conducted consistent with applicable law.
  • Personnel with access to Customer Data are subject to written confidentiality obligations.
  • Periodic security and privacy training is provided.

Payment Card Information

Payment card transactions are processed by PayPal, Inc. Payment card numbers are not transmitted to, stored on, or processed by Phoenix systems.

Security Certifications

Phoenix does not represent that it currently holds SOC 2 Type II, ISO 27001, or another third-party security certification. Phoenix will complete reasonable customer security questionnaires and provide written information about the safeguards described on this page upon request.

Customer Responsibilities

Customers are responsible for maintaining the confidentiality of user credentials, managing authorized users, using appropriate access permissions, and promptly notifying Phoenix of any suspected unauthorized access.

Authoritative Terms

This overview is provided for transparency and general information. If there is a conflict between this page and a signed agreement with a Customer, the signed agreement controls.

Security Contact

Security-related questions may be sent to in**@************ts.com.

Phoenix Consultants Group, Inc.
9 Wilson Drive
Northfield, New Jersey 08225