Identity · Data · Operating Model
Howweoperate.
Identity verified at federal and state level. Data handled with intent. Documentation available on request.
A page for procurement, legal, IT, and enterprise reviewers. Plain language. Nothing implied beyond what we can show.
SAM · Active
NJ MBE
NJ SBE
USPTO ™
Identity & verification
Verifiable at source.
The fastest way to confirm us is to look us up directly with each issuer. The live capability statement keeps every cert number, expiration, and renewal step in one place.
P4 One LLC · New Jersey
UEISW9VDGLV8AY6
CAGE17SM1
NJ MBEA0654-63
NJ SBEA0704-18
NJ Entity0451378177
Open live capability statement
Data & privacy posture
What we collect, why, and what we won't do with it.
◐Minimum necessary
We collect only the data needed to deliver the engagement — contact information, project content, and access credentials provided for the work itself. We don't profile, sell, or rent any of it.
◑Encryption in transit & at rest
Production sites we host serve over TLS. Credential storage uses encrypted vaults. Backups are encrypted. Specifics for any given engagement are documented in the engagement agreement.
◒Access limited & logged
Production access is limited to the team members performing the work. Administrative changes are logged. We use two-factor authentication on every service that supports it.
◓Data export on engagement end
When an engagement ends, we hand over a clean export of project assets, source files, and credentials. Hosted accounts under our control are transferred or wound down on your timeline.
◔Incident response
If we become aware of a security incident touching client data, we notify the affected client within the timeline written into the engagement agreement and provide a clear summary of what happened and what we did.
◕Plain-language agreements
Our engagement agreements, data processing terms, and privacy notice are written in plain English. We'd rather have you understand and sign than impress you with legalese and not.
Operating posture
How the team works.
◐Where we operate from
Kenilworth, New Jersey. Engagements run remotely with optional on-site visits for NJ-area clients. We serve NJ, NY, PA, CT, and the broader tri-state market.
◑Intentionally small team
P4 One LLC operates with a small core team and a hand-picked roster of trusted partners. We scale by adding partners we've worked with before — not by stacking junior contractors. This is a design decision, not a constraint.
◒Maintenance-first delivery
Most engagements come with a built-in care plan after launch. We don't ship and walk. The thing we built two years ago should still be working two years from now — and we plan for that from day one.
◓Liability lane discipline
We provide informational monitoring on accessibility, SEO, and site health. We do not claim guarantees of ADA compliance, search ranking, or third-party certification we don't hold. Buyers should verify any cert directly at the issuer.
Subprocessors
The vendors behind what we deliver.
For typical client engagements we rely on the platforms below. The exact stack depends on the engagement and is written into the agreement. We update this list as the stack changes.
Hosting
Netlify
Static site hosting, edge functions, forms. Primary host for most P4 deliverables.
DNS & edge
Cloudflare
DNS management, TLS certificate management, edge caching, DDoS protection.
Email
Google Workspace
Business email and document collaboration. Used for client-facing communication and admin.
Analytics
Google Analytics 4
Aggregated, privacy-respecting usage analytics on hosted properties. IP anonymization enabled where applicable.
Payments
Stripe
Engagement invoicing and payment processing. Card data is held by Stripe — never by P4.
Source & CI
GitHub
Code versioning and automated build / deploy pipelines for the sites we maintain.
Trust & security inquiries