FAQ
Asked, answered.
What does 0pon build?
Three things. Fixed-fee platform builds (portals, CRM, workflow automation) for small operators with sensitive records. 0pon Care, an operational core for appointment-driven practices that integrates with the system of record already in place, proving out in healthcare. And verified systems: access control whose confidentiality properties are machine-checked rather than asserted.
How do engagements work?
A short paid discovery phase reviews your actual data and systems before migration and integration pricing is fixed. The build is fixed-fee against milestones you accept on a working system, not a status report. After launch, a monthly retainer with a defined hours bucket carries the system.
Do you publish pricing?
No. Numbers live in proposals, where they can be honest about your specific scope. The structure (discovery, fixed-fee build, retainer) is described on the Platform page and is the same for everyone.
Can you work with the systems we already run?
Yes, and by preference. We integrate with and enrich what you already have rather than forcing a replacement, and integrations start read-only: the system observes before it is ever allowed to write.
Do you handle patient or health data?
Only as a Business Associate under a signed BAA, inside systems built for it. No PHI through this website, and none by email.
What does this website collect?
The contact form collects what you type into it, plus your IP address for rate limiting. The marketing site sets no cookies and runs no analytics.
Are you registered for federal work?
Yes. 0pon, LLC is a District of Columbia company with an active SAM.gov registration, UEI M6S5C7XJ9J54, CAGE 21PM1. A NIST SP 800-171 self-assessment is current in SPRS (CUI-enclave scope), and a CMMC Level 2 (Self) assessment was affirmed at Conditional status in August 2026, valid through January 2027. Details for contracting officers on request.
Where are you?
Washington, DC. We work remotely with clients elsewhere, including internationally.
Do your systems use AI?
Where a client system includes AI features, they run on providers under agreements that bar training on customer data, and PHI is involved only under a BAA. The marketing site itself uses none.
Who do I contact about privacy, security, or my data?
h0wdy@0pon.com, one mailbox for all three. Security disclosures welcome at the same address.
Something else? Ask directly.