Security is the product.
We build security software and run security assessments, so our own posture has to hold up to the same scrutiny we apply to clients. Sovereign by design, least-privilege by default, and tested by people who break things for a living.
Security principles
Sovereign by design
Collection, analysis, and reporting stay on-box or on your infrastructure. No client data, evidence, or findings are sent to a third-party cloud, SaaS, or telemetry endpoint.
Encryption everywhere
TLS in transit; AES-GCM vaults and hashed credentials (PBKDF2 / bcrypt) at rest. Local evidence stores are encrypted; secrets live in scoped stores, never in source.
Least privilege
Role-based access (admin / investigator / evaluator / read-only), tag-scoped data retrieval, and per-application isolation so no component sees more than its mission requires.
Governed data
Internal corpora are classified, access-controlled, and never reproduced in customer-facing output. Investigative work is chain-of-custody aware and admissibility-minded.
Hardened edge
Production apps sit behind a managed WAF with bot mitigation, security headers (HSTS, CSP, X-Frame-Options, X-Content-Type-Options), DNSSEC, and signature-verified webhooks.
Self-tested on a recurring cadence
We run our own offensive, defensive, and dependency reviews on a recurring basis, mapped to MITRE ATT&CK, OWASP Top 10, and NIST CSF. These are internal reviews; no independent penetration test has been performed to date.
How posture maps to framework
| Control | Implementation | Framework |
|---|---|---|
| Identity & access | SSO, RBAC, MFA on privileged tiers, opaque session tokens | PR.AC · ATT&CK TA0006 |
| Data protection | TLS, AES-GCM at rest, hashed creds, on-box storage | PR.DS |
| Application security | Parameterized SQL, CORS allowlist, input validation, SQL-lint gate | OWASP A01/A03 |
| Edge & network | Managed WAF, bot mitigation, security headers, DNSSEC | PR.PT · DE.CM |
| Detection & response | Error-triage pipeline, dependency auditing, IR runbooks | DE.CM · RS.RP |
What we can put in front of you today
We hold no third-party certificate yet. What exists instead is the underlying work, documented and dated, and available to a qualified reviewer under NDA:
- ISO/IEC 27001:2022 programme — 15 adopted policies, a Statement of Applicability covering all 93 Annex A controls, a maintained risk register with treatment plan, and a control-owner matrix.
- Internal audit executed 2026-07-27/28 — 4 major and 6 minor findings raised; all audit-remediable findings closed and evidenced. The detect-and-close loop itself is the artifact.
- SOC 2 Type II — evidence-collection observation window opened 2026-07-14; earliest Type II readiness 2026-10-14. Remaining before examination: an independent penetration test, vendor-attestation collection, and CPA engagement.
- CJIS readiness set — a control crosswalk mapping all thirteen CJIS policy areas to NIST SP 800-53 Rev 5 and to the ISO Annex A rows, a System Security Plan for the production boundary, an annual security-awareness training programme with completion records and signed acknowledgements, and a documented personnel-screening procedure.
- Operating evidence — centralized audit logging with a 365-day retention lock, individual accountability cryptographically bound into the audit trail, enforced multi-factor authentication, nightly encrypted backups with restore drills passed on every production database, and WAF posture managed as code with drift detection.
- Documented limits — we also publish what does not yet operate: no independent penetration test, no external audit of any kind, tamper-evidence on the audit store is retention-based rather than hash-chained, and there is no 24/7 monitoring operation.
A security-questionnaire pre-fill and the full artifact index are available on request.
What we hold, and what we do not
| Framework | Status | Detail |
|---|---|---|
| SBA SDVOSB / VOSB | Certified | SBA VetCert, 13 CFR Part 128, effective 2026-07-29; first renewal 2029. SAM.gov Active — UEI U95HZTS97YK8, CAGE 225D1, D-U-N-S 146814782. |
| Section 889 | Compliant | Self-represented in SAM. No covered telecommunications or video-surveillance equipment or services in the supply chain. |
| SOC 2 Type II | In progress · not certified | No SOC 2 report exists. Control environment is live; the evidence-collection observation window opened 2026-07-14. Earliest Type II readiness 2026-10-14. Independent audit firm not yet engaged. |
| ISO/IEC 27001:2022 | Aligned · not certified | No certificate and no certification body engaged. ISMS documented against the standard: 15 adopted policies (four adopted 2026-08-05 — security awareness and training, physical and environmental security, asset management, and audit-log review — closing the Annex A gaps at A.6.3, A.7.1/7.2/7.3/7.6/7.7, A.5.9 and A.8.15), a Statement of Applicability covering all 93 Annex A controls, risk register and treatment plan, control-owner matrix, and an internal-audit programme (first internal audit executed 2026-07-27/28). Those four policies are adopted but not yet operating: they carry policy evidence, not operating evidence, and their SoA rows remain open until each is executing and producing records. |
| CJIS Security Policy | Architecturally aligned · no attestation | Omega Point holds no CJIS attestation and has executed no CJIS Security Addendum with any agency or cloud provider. Products are designed against CJIS control expectations — audit logging, advanced authentication, encryption, US-only data residency — but CJIS authorization for any deployment is determined by the agency and its state CJIS Systems Agency. Readiness work completed (2026-08): a CJIS-to-NIST SP 800-53 Rev 5 control crosswalk across all thirteen policy areas; a maintained System Security Plan for the production boundary; an annual security-awareness training programme running the CJIS Level 4 (Privileged) curriculum with completion records and signed acknowledgements; and a documented personnel-screening procedure. Still outstanding: fingerprint-based personnel screening (CJIS PS-3) cannot be submitted until a Contracting Government Agency sponsors it under its ORI, and no independent penetration test has been performed. Training records are interim and self-administered; at first Addendum, personnel re-certify through the sponsoring agency's CJIS Online programme. |
| FedRAMP | Not authorized | No FedRAMP authorization at any impact level. Sponsorship path under evaluation; required only for federal contracts handling Moderate-impact data. |
| NIST SP 800-171 / CMMC | Not in scope | Deferred until Omega Point handles DoD Controlled Unclassified Information. No SPRS score posted. |
| HIPAA | Not applicable | No protected health information is processed. A Business Associate Agreement programme is documented but unexecuted; it would be engaged only if a covered-entity engagement is taken on. |
| NIST CSF · CIS · CPG | Alignment framework | Used as the assessment methodology for our own posture and for client readiness reviews. Alignment to a framework is not certification against it. |
Measured posture, last assessed 2026-08-05. The administrative workstation is graded on a recurring automated audit against a control catalogue mapped to ISO/IEC 27001:2022, SOC 2, NIST SP 800-53 Rev.5, NIST CSF 2.0 and CJIS Security Policy v6.0: 39 of 45 technical controls passing (87%), up from 58% before the 2026-08-04/05 remediation cycle, with every applied change recorded alongside its rollback command. The six open items are each recorded with a named reason — one architectural (365-day off-host audit-log retention, the only critical-severity gap), three deferred by decision of the Security Officer pending workflow-compatibility review, and two blocked by a third-party endpoint-protection product owning real-time protection on the host. Fourteen organizational controls cannot be evidenced by any scanner; they are excluded from the score rather than auto-passed, and none has yet been attested. This grades one workstation. It is not an estate-wide statement, and it is not an audit.
Language on this site is deliberate. Certified means an external body issued a certificate we can produce. Compliant means a self-representation we stand behind on the record. Aligned means our controls are designed against the framework without an external audit. Anything not listed here, we do not hold.
Found something? Tell us first.
We welcome good-faith security research. If you discover a vulnerability in an Omega Point property, report it privately and give us a reasonable window to remediate before any public disclosure.
- Email security@omegapointsolutions.com with steps to reproduce and impact.
- Do not access, modify, or exfiltrate data that isn't yours; do not run denial-of-service or automated mass-scanning.
- Stay within scope and the law. We will not pursue good-faith researchers who follow this policy.
Need your own posture tested?
The same discipline we apply to ourselves, applied to your environment, cyber, physical, or critical infrastructure.
Request an Assessment →