OrenGen Worldwide Hear the AI Voice demo at 682-399-8443 Book a Mission Brief (opens in a new tab)

Trust Center · Compliance

Compliance status, framework by framework

For procurement, security and compliance reviewers: the frameworks buyers ask us about, and where OrenGen Worldwide stands on each: certified, not held, or not claimed. If this page doesn't say we hold something, assume we don't.

How to read this page

Five status words, each with one meaning

Compliance language stretches easily. On this page these five words are used exactly, and nothing else stands in for them. Registrations and identifiers on Credentials & Registrations carry record statuses of their own.

Certified

A named certificate from a third party, with a certificate number and validity dates you can check.

Not held

We don't hold the certification, authorization or validation, or maintain the clearance. If your requirements name it as a hard gate, raise it in the first conversation.

Not claimed

We make no statement about it, not even “aligned with”. Treat it as not held.

Aligned with

Controls designed around a framework's objectives. It implies no audit, attestation or certificate. We also say “designed to support”.

Targeting

A goal we work toward, like this website's accessibility target. It's never listed alongside what we hold.

Certified

The certificate we hold

We hold one third-party certificate. It confirms supplier-diversity categories for procurement. It isn't a security, privacy or quality-management certification, and we don't present it as one.

Our identifiers, registrations and accreditations, each with its status, the record it comes from and its evidence, are listed on Credentials & Registrations.

Credentials & Registrations →

SupplierGateway

Supplier Impact Certification (US)

SupplierGateway Supplier Impact Certification (US), Certificate No. SG06265178661562, valid June 1, 2026 – June 1, 2027. Verify at suppliergateway.com/verifycert.

SupplierGateway Supplier Impact categories: Digital Identity Verified, Minority Owned, Small Business and Small Disadvantaged Business.

suppliergateway.com/verifycert ↗

Not held

Authorizations we don't hold

OrenGen does not currently hold CMMC, FedRAMP, DoD Impact Level, CJIS or HITRUST authorizations, is not a 21 CFR Part 11-validated system, and does not maintain corporate personnel security clearances.

CMMC

Not held

The Department of Defense's Cybersecurity Maturity Model Certification for contractors that handle federal contract information or controlled unclassified information.

FedRAMP

Not held

The U.S. government's authorization program for cloud services used by federal agencies.

DoD Impact Levels

Not held

Defense Department cloud security levels for data of increasing sensitivity.

CJIS

Not held

The FBI's Criminal Justice Information Services security policy for systems that handle criminal justice information.

HITRUST

Not held

A certifiable security and privacy framework widely used in healthcare.

21 CFR Part 11

Not held

FDA requirements for electronic records and signatures in regulated life-sciences work. OrenGen is not a Part 11-validated system.

Personnel security clearances

Not held

Security clearances maintained at the corporate level. OrenGen does not maintain corporate personnel security clearances.

If one is a hard requirement

Say so at the start. We'll tell you early whether the work can run inside an environment that already holds the authorization, such as your agency's or your prime contractor's, or whether we're not the right fit.

Not claimed

Frameworks we make no claim about

Buyers ask about these often. This page makes no claim about any of them, not even “aligned with”.

SOC 2

Not claimed

An attestation report on a service organization's controls, issued by an independent CPA firm.

ISO/IEC 27001

Not claimed

The international standard for an information security management system, certified by an accredited certification body.

Platform attestations

Not claimed

If a platform we build on has its own audit report, that report covers the platform only, not OrenGen or systems deployed on your infrastructure.

NIST SP 800‑53, SP 800‑171 and the AI RMF

Not claimed

U.S. federal control catalogues and a risk management framework commonly used to structure security and AI governance.

HIPAA

Not claimed

U.S. rules for protected health information, including Business Associate Agreements with vendors that handle it.

EU-U.S. and Swiss-U.S. Data Privacy Framework

Not claimed

Frameworks for transferring personal data from Europe, joined by self-certification on a public list.

Privacy laws such as GDPR and CCPA/CPRA

Not claimed

Laws that apply depending on whose personal data is processed and where.

Calling and texting rules (TCPA, A2P 10DLC)

Not claimed

Consent rules and carrier registrations for calls and texts. Registrations are operational steps, not certifications.

How we handle consent for calls and texts is covered on Responsible AI.

Responsible AI →

Scope by sector

Limits that apply before any framework does

What we do and don't do in regulated sectors, stated up front.

Public sector

For federal, state and local buyers, the Not held list above is our current position. Identifiers and NAICS codes are on Credentials & Registrations.

Public Sector →

Healthcare

Our healthcare work focuses on healthcare administration. We do not provide clinical decision support, diagnosis or treatment guidance, we are not a contract research organization, and we do not replace validated clinical systems of record.

Healthcare →

Legal operations

Non-attorney disclosure. OrenGen Worldwide LLC provides legal operations support: contract review support, clause extraction and document workflow automation. OrenGen is not a law firm, does not provide legal advice or legal opinions, and does not represent clients. All legal-support outputs require review by a licensed attorney or by the client.

Legal Operations →

This website

Targeting WCAG 2.2 Level AA for orengen.io. That's a target, not a claim of conformance.

Accessibility →

Where the detail lives

Related Trust Center pages

Credentials & Registrations

Identifiers, certificates and accreditations, each with its status, source record and evidence.

Credentials & Registrations →

Security

The security facts reviewers ask for first, how responsibility splits by deployment model, and how to report a vulnerability.

Security →

Privacy & Data Handling

Where data lives in cloud, self-hosted and hybrid deployments.

Privacy & Data Handling →

Subprocessors

The service providers that process data on our behalf, grouped by function.

Subprocessors →

Trust Center

Every Trust Center page, including responsible AI and accessibility, in one place.

Trust Center →

Governance & Security

The governance systems we build for your organization: policy controls, approvals and audit trails.

Governance & Security →

Mission Brief

Bring the questionnaire your reviewers sent.

Share the frameworks and controls your procurement or security team has named, and we'll go through them against what's on this page.