Legal
Security & compliance
How we protect data across the software and services we build.
Last updated August 4, 2026
Our posture
0pon builds software for businesses, including healthcare clients, and treats security as a design constraint, not an afterthought. We run on SOC 2 / HIPAA-aligned infrastructure and keep our own footprint deliberately small and auditable.
Data protection
- Encryption: In transit (TLS) and at rest (provider-managed).
- Least-privilege access: Per-tenant data isolation enforced at the database layer with row-level security.
- Audit logging: Data access and changes are logged.
- Secrets: Held in managed stores, never in source code.
HIPAA and protected health information
For healthcare engagements, 0pon acts as a Business Associate. We process protected health information (PHI) only under a signed Business Associate Agreement (BAA) and applicable law. The BAA chain (client, plus our infrastructure subprocessors) is a hard gate: no production PHI moves until it is in place. Demonstrations and prototypes use synthetic data only.
Subprocessors
- Supabase: Database / system of record. SOC 2 Type 2; HIPAA BAA in place before any PHI.
- Anthropic: AI features. BAA before any PHI; no training on customer data.
- Vercel: Hosting. TLS; managed secrets.
- Stripe: Payments. PCI-DSS Level 1.
The providers behind this website itself are listed in our privacy notice.
Federal compliance
- NIST SP 800-171: a self-assessment is current in the Supplier Performance Risk System (SPRS), scoped to our CUI enclave. This satisfies DFARS 252.204-7019. The DoD Unique Identifier and score are available to contracting officers on request.
- CMMC Level 2 (Self): Conditional status affirmed August 2026, valid through January 2027. Two remaining requirements sit on a documented plan of action, which is what Conditional means.
- CUI handling: controlled unclassified information stays inside a dedicated encrypted enclave running in FIPS mode, with multifactor authentication, continuous monitoring, and no CUI in commercial email or cloud storage.
A note on certifications
0pon is a small firm and does not hold its own SOC 2 attestation, and we don't claim one. Our assurance comes from the inherited controls of our SOC 2 Type 2 infrastructure above, our documented Information Security Policy, the BAA chain, and the least-privilege and audit practices described here. We're glad to complete a customer's security questionnaire as the formal step.
Contact
Security questions or responsible-disclosure reports: h0wdy@0pon.com. We aim to respond within two business days.