Security is the product.
We build security software and run security assessments, so our own posture has to hold up to the same scrutiny we apply to clients. Sovereign by design, least-privilege by default, and tested by people who break things for a living.
Security principles
Sovereign by design
Collection, analysis, and reporting stay on-box or on your infrastructure. No client data, evidence, or findings are sent to a third-party cloud, SaaS, or telemetry endpoint.
Encryption everywhere
TLS in transit; AES-GCM vaults and hashed credentials (PBKDF2 / bcrypt) at rest. Local evidence stores are encrypted; secrets live in scoped stores, never in source.
Least privilege
Role-based access (admin / investigator / evaluator / read-only), tag-scoped data retrieval, and per-application isolation so no component sees more than its mission requires.
Governed data
Internal corpora are classified, access-controlled, and never reproduced in customer-facing output. Investigative work is chain-of-custody aware and admissibility-minded.
Hardened edge
Production apps sit behind a managed WAF with bot mitigation, security headers (HSTS, CSP, X-Frame-Options, X-Content-Type-Options), DNSSEC, and signature-verified webhooks.
Continuously tested
We run our own offensive, defensive, and dependency reviews on a recurring basis, mapped to MITRE ATT&CK, OWASP Top 10, and NIST CSF.
How posture maps to framework
| Control | Implementation | Framework |
|---|---|---|
| Identity & access | SSO, RBAC, MFA on privileged tiers, opaque session tokens | PR.AC · ATT&CK TA0006 |
| Data protection | TLS, AES-GCM at rest, hashed creds, on-box storage | PR.DS |
| Application security | Parameterized SQL, CORS allowlist, input validation, SQL-lint gate | OWASP A01/A03 |
| Edge & network | Managed WAF, bot mitigation, security headers, DNSSEC | PR.PT · DE.CM |
| Detection & response | Error-triage pipeline, dependency auditing, IR runbooks | DE.CM · RS.RP |
What we hold, and what we do not
| Framework | Status | Detail |
|---|---|---|
| SBA SDVOSB / VOSB | Certified | SBA VetCert, 13 CFR Part 128, effective 2026-07-29; first renewal 2029. SAM.gov Active — UEI U95HZTS97YK8, CAGE 225D1. |
| Section 889 | Compliant | Self-represented in SAM. No covered telecommunications or video-surveillance equipment or services in the supply chain. |
| SOC 2 Type II | In progress · not certified | No SOC 2 report exists. Control environment is live; the evidence-collection observation window opened 2026-07-14. Earliest Type II readiness 2026-10-14. Independent audit firm not yet engaged. |
| ISO/IEC 27001:2022 | Aligned · not certified | No certificate and no certification body engaged. ISMS documented against the standard: 15 adopted policies (four adopted 2026-08-05 — security awareness and training, physical and environmental security, asset management, and audit-log review — closing the Annex A gaps at A.6.3, A.7.1/7.2/7.3/7.6/7.7, A.5.9 and A.8.15), a Statement of Applicability covering all 93 Annex A controls, risk register and treatment plan, control-owner matrix, and an internal-audit programme (first internal audit executed 2026-07-27/28). Those four policies are adopted but not yet operating: they carry policy evidence, not operating evidence, and their SoA rows remain open until each is executing and producing records. |
| CJIS Security Policy | Architecturally aligned · no attestation | Omega Point holds no CJIS attestation and no CJIS Security Addendum with any cloud provider, and personnel-vetting (CJIS PS-3) is not in place. Products are designed against CJIS control expectations — audit logging, advanced authentication, encryption, US-only data residency — but CJIS authorization for any deployment is determined by the agency and its state CJIS Systems Agency. |
| FedRAMP | Not authorized | No FedRAMP authorization at any impact level. Sponsorship path under evaluation; required only for federal contracts handling Moderate-impact data. |
| NIST SP 800-171 / CMMC | Not in scope | Deferred until Omega Point handles DoD Controlled Unclassified Information. No SPRS score posted. |
| HIPAA | Not applicable | No protected health information is processed. A Business Associate Agreement programme is documented but unexecuted; it would be engaged only if a covered-entity engagement is taken on. |
| NIST CSF · CIS · CPG | Alignment framework | Used as the assessment methodology for our own posture and for client readiness reviews. Alignment to a framework is not certification against it. |
Measured posture, last assessed 2026-08-05. The administrative workstation is graded on a recurring automated audit against a control catalogue mapped to ISO/IEC 27001:2022, SOC 2, NIST SP 800-53 Rev.5, NIST CSF 2.0 and CJIS Security Policy v6.0: 39 of 45 technical controls passing (87%), up from 58% before the 2026-08-04/05 remediation cycle, with every applied change recorded alongside its rollback command. The six open items are each recorded with a named reason — one architectural (365-day off-host audit-log retention, the only critical-severity gap), three deferred by decision of the Security Officer pending workflow-compatibility review, and two blocked by a third-party endpoint-protection product owning real-time protection on the host. Fourteen organizational controls cannot be evidenced by any scanner; they are excluded from the score rather than auto-passed, and none has yet been attested. This grades one workstation. It is not an estate-wide statement, and it is not an audit.
Language on this site is deliberate. Certified means an external body issued a certificate we can produce. Compliant means a self-representation we stand behind on the record. Aligned means our controls are designed against the framework without an external audit. Anything not listed here, we do not hold.
Found something? Tell us first.
We welcome good-faith security research. If you discover a vulnerability in an Omega Point property, report it privately and give us a reasonable window to remediate before any public disclosure.
- Email security@omegapointsolutions.com with steps to reproduce and impact.
- Do not access, modify, or exfiltrate data that isn't yours; do not run denial-of-service or automated mass-scanning.
- Stay within scope and the law. We will not pursue good-faith researchers who follow this policy.
Need your own posture tested?
The same discipline we apply to ourselves, applied to your environment, cyber, physical, or critical infrastructure.
Request an Assessment →