Skip to content

SecurePoint USA

Trust Center

Everything a security or procurement reviewer needs, in one place.

Last reviewed: September 1, 2026

Certifications and program status

FrameworkStatusDetail
SOC 2 Type IINot certified. Target Q3 2027Controls mapped to the Trust Services Criteria. Audit engagement in progress; scope and observation period are still being set, so the target date is not a commitment.
CMMC 2.0 Level 2Controls implemented; Level 2 self-assessment postureNo C3PAO certification is claimed. Phase 1 self-assessment is in force; DoD suspended Phase 2 on July 13, 2026 pending review.
NIST SP 800-171Rev 2 under DFARS 252.204-7012A DoD class deviation keeps contracts on Rev 2; Rev 3 is tracked.
FedRAMPNot claimedNo Ready, Authorized, or certified status is claimed.
ISO/IEC 27001Control-informed; no audit plannedUsed as a rubric for our own program. We are not pursuing certification.
Third-party penetration testPlannedInternal security review is ongoing. Contact us for current timelines.

Availability and incident response

The platform runs on Vercel and Supabase in United States regions. Service-level terms are set in the customer agreement. Internal service-level objectives, error budgets, and monitoring runbooks are available for review during procurement.

Incident response follows a documented runbook with named roles: incident commander, communications, security engineering, and customer liaison. Notification commitments are set in the customer agreement and vary by contract and jurisdiction.

Documents

Security

Data and privacy

Terms

Due diligence

A downloadable security packet, control matrix, evidence map, and subprocessor list are on the Security Center. For questionnaires, an NDA for deeper review, or an architecture call with engineering, write to security@securepointusa.com.

Trust Center | SecurePoint USA