Security & Compliance

SVT Security & Compliance Posture

SVT (Stolen Vehicle Tracking) is built for law enforcement use on a hardened, US-operated cloud stack. This page is an honest statement of how the platform is secured and where the boundaries of that posture sit, written for agency security reviewers and procurement officers.

Operated by Omega Point Solutions LLC · Last reviewed: 2026

01 Section 889-Clean Infrastructure

SVT runs entirely on Cloudflare's United States cloud platform (Workers compute, D1 datastore, R2 object storage, Vectorize, and Workers AI). No covered telecommunications or video-surveillance equipment or services are present anywhere in the SVT supply chain.

The platform uses no equipment, components, or services from the following prohibited vendors:

HuaweiZTEHikvisionDahuaHytera

02 Encryption

Data is protected both at rest and in transit.

  • At rest: AES-256 encryption for stored records, object storage, and backups.
  • In transit: TLS 1.2 or higher for every connection; HTTP Strict Transport Security (HSTS) is enforced with preload.
  • Plaintext credentials are never stored; only salted password hashes are persisted.

03 Authentication

Access is controlled by per-account credentials and server-side sessions.

  • Opaque session tokens stored server-side as SHA-256 hashes; the raw token never persists in the database.
  • Passwords hashed with PBKDF2 using a per-account salt and a high iteration count.
  • Multi-factor authentication (MFA) is available, including time-based one-time passwords (TOTP).
  • Role-based access control scopes records to the entering agency; cross-agency reads are denied by default.
  • Rate limiting and lockout protect the login endpoint against credential-stuffing.

04 CJIS Posture

SVT is designed with CJIS principles in mind (least-privilege access, full audit logging, encryption in transit and at rest, and MFA availability).

Honest disclosure

SVT does not operate inside a CJIS environment. Agencies subject to CJIS Security Policy obligations should treat SVT as an external system and confirm that their intended use is consistent with their CSA's requirements before entering Criminal Justice Information.

05 Data Handling

SVT stores only the case data agencies enter and the audit records needed to demonstrate proper use. Data is owned by the contributing agency.

Honest disclosure

SVT runs on the global Cloudflare edge with no region-pinning. We do not claim United States-only data residency: data may be processed at Cloudflare points of presence outside a single fixed region. Agencies with strict data-residency requirements should account for this in their assessment.

06 Tamper-Evident Audit Logging

Every security-relevant action is recorded to an append-only activity log.

  • Logins, logouts, password changes, and lockouts are recorded with timestamp, account, and source IP.
  • Record creates, views, updates, deletes, exports, and sensitive location queries are logged with the acting account and what changed.
  • Audit entries are insert-only; the application exposes no path to edit or delete a prior log entry.
  • Administrators can review recent login and activity history from within the platform.

07 Company Certification & Compliance Status

Updated August 2026. We publish where we actually are — held certifications, work in progress, and what remains.

  • Held: SBA VetCert SDVOSB certification (July 2026); Section 889 compliance self-represented in SAM.gov; an adopted ISMS of 11 governing security policies with a full ISO/IEC 27001:2022 Statement of Applicability (all 93 Annex A controls), a maintained risk register, and a quarterly internal-audit and management-review programme.
  • Operating with evidence: centralized immutable audit logging under a 365-day retention lock; individual user accountability cryptographically bound into the analysis engine's audit trail; MFA enforced for administrators and paid tiers; nightly encrypted backups with verified restore drills passed on every production database, including SVT's.
  • SOC 2 Type II — in progress, not certified: the evidence observation window opened July 2026; the first internal audit ran 2026-07-27/28 and all remediable findings are closed. Remaining before examination: an external penetration test, completion of vendor-attestation collection, and CPA engagement at window maturity.
  • ISO/IEC 27001:2022 — aligned, not certified: certification-body engagement follows the SOC 2 examination.
CJIS, stated plainly

We do not claim CJIS certification — no cloud vendor can. CJIS authorization is determined per deployment by the agency and its CJIS Systems Agency. No CJIS Security Addendum has been executed to date; if your agency requires one, we will sign it and support your state CSA's authorization process. Officer users are verified at signup (law-enforcement email plus supervisor attestation); personnel screening remains the employing agency's authority.

Section 889 Attestation

Omega Point Solutions LLC attests that SVT does not provide, use, or contain any covered telecommunications equipment or services as defined in Section 889 of the John S. McCain National Defense Authorization Act for Fiscal Year 2019 (Public Law 115-232), including any equipment or services produced or provided by Huawei, ZTE, Hikvision, Dahua, or Hytera, or by any subsidiary or affiliate of those entities.

Procurement and security questions: procurement@fraudtrax.net