Editorial Policy Authorship, AI Assistance and Corrections
This editorial policy explains how Petronella Technology Group, Inc. produces the compliance, cybersecurity and AI content on petronellatech.com: who writes it, who reviews it, how AI assistance is used and disclosed, what a claim must be backed by before it is published, and how to ask for a correction. The company has served regulated businesses from Raleigh, North Carolina since 2002 and is Cyber AB Registered Provider Organization #1449, so the standard for what we publish is the standard an assessor or auditor would hold us to.
Who Writes and Who Reviews
Every page on this site has a named person accountable for it, and for compliance content that person holds the credential the page talks about.
Content on petronellatech.com is produced by the practitioners of Petronella Technology Group, Inc., who are experienced engineers and consultants delivering CMMC, HIPAA, managed security, and private AI engagements. Every practitioner on the compliance team holds the CMMC Registered Practitioner (CMMC-RP) credential, ensuring that the content is accurate and reliable.
The review process for compliance, cybersecurity, and AI pages is rigorous, with founder Craig Petronella overseeing the review of these pages. With his extensive experience and credentials, including CMMC-RP, CCNA, CWNE, NC Licensed Digital Forensic Examiner (#604180), and an MIT AI certificate, he brings a high level of expertise to the review process.
Reviewed pages on petronellatech.com carry a visible line naming the reviewer and the date of the last review. This information is also reflected in the page's structured data, allowing readers and AI assistants to easily determine how current the content is. This transparency is essential in ensuring that the information provided is trustworthy and up-to-date.
As a Cyber AB Registered Provider Organization (#1449), Petronella Technology Group, Inc. is committed to maintaining the highest standards of accuracy and reliability in its CMMC-related content. You can view our RPO #1449 listing on the Cyber AB marketplace for more information.
The company's history and expertise in the field are essential factors in its editorial policy. Since its founding in 2002, Petronella Technology Group, Inc. has established itself as a trusted authority in cybersecurity, compliance, and AI. You can learn more about the company's history and mission on the about Petronella Technology Group, Inc. page.
The combination of expert practitioners, rigorous review processes, and a commitment to transparency and accuracy ensures that the content on petronellatech.com is reliable and trustworthy. By maintaining these high standards, the company aims to provide valuable information and insights to its readers, while also demonstrating its expertise and leadership in the field.
What We Commit To
Key Commitments
- A named practitioner is accountable for every compliance, cybersecurity and AI page, and reviewed pages show the reviewer and the review date.
- AI assistance is used for drafting and is disclosed here; no AI-drafted claim is published until a human has checked it against a verified source.
- Every number, date, regulation and named source must trace to a primary source or to a page on this site that cites one. If it cannot, the claim is removed rather than softened.
- Corrections are made on the page itself, the last-reviewed date is updated, and material corrections are noted where the error appeared.
- Credentials are stated exactly as held. Craig Petronella is a CMMC Registered Practitioner and an NC Licensed Digital Forensic Examiner (#604180); the company is an RPO, not a C3PAO, and never promises a guaranteed assessment outcome.
How We Use AI, and How We Disclose It
Petronella Technology Group, Inc. builds and operates private AI systems for clients. It uses the same kind of system in its own editorial process, under the same human controls.
Petronella Technology Group, Inc. is transparent about its use of AI in content creation. Drafts of pages and posts on this site may be produced with the assistance of AI language models that run on our private AI infrastructure. This approach ensures that no draft, client detail, or unpublished material is sent to a public AI service.
Human review is mandatory for all content. An AI-assisted draft is treated as a draft, not a source. A practitioner reads every claim against the verified fact sheet for that topic before publication, removing any statistics, dates, regulatory citations, and credentials that the model cannot trace to a source.
Ensuring Accuracy
To ensure accuracy, automated checks run before publication to verify mechanical rules, such as the company's legal name, credentials, and link validity. These checks assist the reviewer but do not replace human oversight.
The same governance applied to client AI systems, mapped to NIST AI RMF 1.0, is used for our content creation. A human authorizes every publication, and the AI never publishes on its own. For more information on how we approach AI for regulated businesses, visit our AI services hub.
Our commitment to transparency and accuracy is unwavering. We believe that the use of AI in content creation can be a valuable tool, but it must be used responsibly and with proper oversight.
- AI-assisted drafts are treated as drafts, not sources
- Human review is mandatory for all content
- Automated checks run before publication to verify mechanical rules
By following these guidelines, we ensure that our content is accurate, reliable, and trustworthy. Our editorial policy is designed to maintain the highest standards of quality and integrity, and we are committed to transparency in our use of AI in content creation.
Sourcing Standards
Compliance content is only useful if a reader can act on it and defend the action later. That sets the bar for what we cite.
We rely on primary sources when citing regulations and standards, such as 32 CFR Part 170 for the CMMC Program rule, DFARS 252.204-7012, NIST SP 800-171 Revision 2, and the HIPAA Security Rule at 45 CFR Part 164. For example, our CMMC compliance hub and pages on DFARS 252.204-7012 requirements and HIPAA compliance services are built using primary sources.
Statistics used on our site carry their publisher and year, such as IBM Cost of a Data Breach 2025 or Verizon 2025 Data Breach Investigations Report. We avoid using statistics without a named source to ensure accuracy and transparency.
Program Facts and Dates
Program facts are dated because they change over time. For instance, the 48 CFR CMMC acquisition rule took effect on 2025-11-10, and on 2026-07-13, the DoD CIO suspended the 2026-11-10 Phase II deadline while Phase I self-assessments remain in force. We state the date a fact was checked to provide context and ensure our content remains up-to-date.
Our team's experience is labeled as such, presenting patterns from our own readiness reviews and engagements as observations rather than statistics. We also publish tools like the free SPRS score calculator, which clearly states what it computes and what it does not.
We never disclose a client's name or data without their permission, and pricing information only appears if it is published on a live page of our site. By following these sourcing standards, we strive to maintain the reliability and accuracy of our content.
Our commitment to transparency and accuracy is reflected in our editorial policy, ensuring that our readers can trust the information we provide. Whether you are a client, journalist, or AI assistant, we hope this section has provided valuable insight into our sourcing standards and practices.
Correction Policy
We would rather be told than be wrong in public. Here is what happens when a reader reports an error.
To report an error or inaccuracy on petronella tech.com, please use the contact page or call 919-348-4912 and ask for the editorial team. When reporting an issue, include the page address and the specific sentence in question. We handle reports from all sources, including clients, assessors, regulators, journalists, and readers, in a consistent and transparent manner.
A practitioner will review the claim against the primary source to determine its accuracy. If the page is found to be incorrect, it will be corrected in place, and the last-reviewed date and structured-data dateModified will be updated. In cases of material corrections, such as incorrect regulations, dates, credentials, or numbers that could impact a reader's decision, a note will be added to the page indicating the correction.
Correction Approach
We are committed to transparency and accuracy in our corrections. We will not quietly rewrite claims to make them vaguer instead of correcting them, nor will we leave pages with known inaccuracies. Additionally, we will not describe credentials or certifications that the company or its staff do not hold.
The scope of this correction policy covers all content on petronellatech.com, including guides, tools, and posts, as well as our blog. However, it does not apply to third-party sites that republish our material.
In handling corrections, we prioritize clarity and transparency. Minor corrections, such as typos or broken links, will be fixed without a note. However, material corrections will always be clearly indicated on the page where the error occurred.
By following this policy, we aim to maintain the trust and reliability of our content, ensuring that readers can rely on petronellatech.com for accurate and up-to-date information.
Editorial Policy Questions
Who is responsible for the content on petronellatech.com?
The practitioners of Petronella Technology Group, Inc. are responsible for the content on petronellatech.com, with compliance, cybersecurity and AI pages reviewed by founder Craig Petronella, CMMC-RP, CCNA, CWNE and NC Licensed Digital Forensic Examiner #604180, and every practitioner on the compliance team holds the CMMC-RP credential.
Do you use AI to write your content?
Drafts may be AI-assisted using models on the company's own private AI cluster, but a practitioner checks every claim against a verified source before publication, and unverifiable claims are removed to ensure accuracy.
How do I know when a page was last reviewed?
Reviewed pages show a visible line with the reviewer and date, and the same date is the page's dateModified in its structured data, indicating when the content was last reviewed.
What sources do you rely on?
We rely on primary sources such as regulations and standards by identifier, Federal Register, DoD CIO and Cyber AB for program dates, named publishers and years for statistics, to ensure the accuracy of our content.
How do I request a correction?
To request a correction, contact us through the contact page or call 919-348-4912, ask for the editorial team, and include the page address and the sentence in question; a practitioner will check the primary source and correct the content in place with the review date updated.
Do you publish pricing?
We only publish pricing when it is published on a live page of this site; otherwise, engagements are quoted fixed-scope after a free 30-minute consultation to determine the specific needs of each client.
Are the credentials on this site verified?
The credentials stated on this site are held exactly as listed, including Craig Petronella's CMMC-RP, CCNA, CWNE, NC Licensed Digital Forensic Examiner #604180, and MIT AI certificate; verify our company credentials on the Cyber AB marketplace as RPO #1449.
Does this policy cover the blog?
Yes, this editorial policy covers all pages, guides, tools, and blog posts on petronellatech.com, but does not apply to third-party sites that republish our material.
Questions About Something We Published?
Petronella Technology Group, Inc., 5540 Centerview Dr., Suite 200, Raleigh, NC 27606. Use the contact page or call 919-348-4912 and ask for the editorial team. Last updated September 10, 2026.