Trust Center · Compliance
For procurement, security and compliance reviewers: the frameworks buyers ask us about, and where OrenGen Worldwide stands on each: certified, not held, or not claimed. If this page doesn't say we hold something, assume we don't.
How to read this page
Compliance language stretches easily. On this page these five words are used exactly, and nothing else stands in for them. Registrations and identifiers on Credentials & Registrations carry record statuses of their own.
A named certificate from a third party, with a certificate number and validity dates you can check.
We don't hold the certification, authorization or validation, or maintain the clearance. If your requirements name it as a hard gate, raise it in the first conversation.
We make no statement about it, not even “aligned with”. Treat it as not held.
Controls designed around a framework's objectives. It implies no audit, attestation or certificate. We also say “designed to support”.
A goal we work toward, like this website's accessibility target. It's never listed alongside what we hold.
Certified
We hold one third-party certificate. It confirms supplier-diversity categories for procurement. It isn't a security, privacy or quality-management certification, and we don't present it as one.
Our identifiers, registrations and accreditations, each with its status, the record it comes from and its evidence, are listed on Credentials & Registrations.
Credentials & Registrations →SupplierGateway
SupplierGateway Supplier Impact Certification (US), Certificate No. SG06265178661562, valid June 1, 2026 – June 1, 2027. Verify at suppliergateway.com/verifycert.
SupplierGateway Supplier Impact categories: Digital Identity Verified, Minority Owned, Small Business and Small Disadvantaged Business.
suppliergateway.com/verifycert ↗Not held
OrenGen does not currently hold CMMC, FedRAMP, DoD Impact Level, CJIS or HITRUST authorizations, is not a 21 CFR Part 11-validated system, and does not maintain corporate personnel security clearances.
Not held
The Department of Defense's Cybersecurity Maturity Model Certification for contractors that handle federal contract information or controlled unclassified information.
Not held
The U.S. government's authorization program for cloud services used by federal agencies.
Not held
Defense Department cloud security levels for data of increasing sensitivity.
Not held
The FBI's Criminal Justice Information Services security policy for systems that handle criminal justice information.
Not held
A certifiable security and privacy framework widely used in healthcare.
Not held
FDA requirements for electronic records and signatures in regulated life-sciences work. OrenGen is not a Part 11-validated system.
Not held
Security clearances maintained at the corporate level. OrenGen does not maintain corporate personnel security clearances.
Say so at the start. We'll tell you early whether the work can run inside an environment that already holds the authorization, such as your agency's or your prime contractor's, or whether we're not the right fit.
Not claimed
Buyers ask about these often. This page makes no claim about any of them, not even “aligned with”.
Not claimed
An attestation report on a service organization's controls, issued by an independent CPA firm.
Not claimed
The international standard for an information security management system, certified by an accredited certification body.
Not claimed
If a platform we build on has its own audit report, that report covers the platform only, not OrenGen or systems deployed on your infrastructure.
Not claimed
U.S. federal control catalogues and a risk management framework commonly used to structure security and AI governance.
Not claimed
U.S. rules for protected health information, including Business Associate Agreements with vendors that handle it.
Not claimed
Frameworks for transferring personal data from Europe, joined by self-certification on a public list.
Not claimed
Laws that apply depending on whose personal data is processed and where.
Not claimed
Consent rules and carrier registrations for calls and texts. Registrations are operational steps, not certifications.
How we handle consent for calls and texts is covered on Responsible AI.
Responsible AI →Scope by sector
What we do and don't do in regulated sectors, stated up front.
For federal, state and local buyers, the Not held list above is our current position. Identifiers and NAICS codes are on Credentials & Registrations.
Public Sector →Our healthcare work focuses on healthcare administration. We do not provide clinical decision support, diagnosis or treatment guidance, we are not a contract research organization, and we do not replace validated clinical systems of record.
Healthcare →Non-attorney disclosure. OrenGen Worldwide LLC provides legal operations support: contract review support, clause extraction and document workflow automation. OrenGen is not a law firm, does not provide legal advice or legal opinions, and does not represent clients. All legal-support outputs require review by a licensed attorney or by the client.
Targeting WCAG 2.2 Level AA for orengen.io. That's a target, not a claim of conformance.
Accessibility →Where the detail lives
Identifiers, certificates and accreditations, each with its status, source record and evidence.
Credentials & Registrations →The security facts reviewers ask for first, how responsibility splits by deployment model, and how to report a vulnerability.
Security →Where data lives in cloud, self-hosted and hybrid deployments.
Privacy & Data Handling →The service providers that process data on our behalf, grouped by function.
Subprocessors →Every Trust Center page, including responsible AI and accessibility, in one place.
Trust Center →The governance systems we build for your organization: policy controls, approvals and audit trails.
Governance & Security →Mission Brief
Share the frameworks and controls your procurement or security team has named, and we'll go through them against what's on this page.