Security & Compliance
Infab Softworks' commitment to security is integral to delivering high-quality software for the defense and aerospace sectors. We prioritize the protection of our customers' sensitive information and operate within a robust cybersecurity framework built on the standards of integrity, confidentiality, and availability.
Our posture aligns with the DoD's CMMC program final rule. Read the Federal Register notice
Our security posture
ITAR / DDTC
In placeDDTC registered and ITAR compliant. All employees are U.S. persons, and all stored ITAR data is encrypted on AWS GovCloud.
CMMC Level 2
Self-assessed (SPRS)CMMC Level 1 and Level 2 self-assessment is complete, and our CMMC Level 2 score is posted in SPRS (the Supplier Performance Risk System). Third-party (C3PAO) certification is pending, and we will pursue it once it becomes available and is required.
SSP & ISMS
EstablishedOur System Security Plan (SSP) and Information Security Management System (ISMS) are established and maintained, aligning our policies, procedures, and controls with international standards.
Third-party penetration testing
AnnualInfab engages an independent third party to perform penetration testing every year. Findings drive remediation and continuous hardening of our systems.
Secure cloud infrastructure
In placeOur systems run on AWS GovCloud using FedRAMP-compliant cloud services, keeping customer data within a controlled, government-grade environment.
ISO 27001 certification
We are preparing for an ISO 27001 audit to formally certify our information security management system.
FedRAMP Moderate equivalency
Not required, as our systems are not in direct use by the Federal Government. For customers bound to FedRAMP Moderate controls, we will provide documentation demonstrating equivalency.
CMMC Level 2 C3PAO certification
Once C3PAO assessment is available to us and contractually required, we will engage a C3PAO to certify our CMMC Level 2 compliance.
Our posture in detail
The frameworks that shape how we protect customer data, and where Infab stands against each one today.
CMMC & DFARS 252.204-7012
DFARS 252.204-7012 and the DoD's CMMC program govern how defense contractors safeguard Controlled Unclassified Information (CUI) and Federal Contract Information (FCI). For our customers in the defense and aerospace sectors, that obligation flows down to every partner that stores or processes their data, and Infab is one of those partners. Meeting these requirements is a precondition for handling the work our customers trust us with, not an optional add-on.
Infab has completed its CMMC Level 1 and Level 2 self-assessment against the NIST SP 800-171 security requirements that DFARS 252.204-7012 mandates, and our resulting CMMC Level 2 score is posted in the Supplier Performance Risk System (SPRS). That means a contracting officer or prime can verify our standing through the same government system they use for every other supplier, rather than taking our word for it.
We treat the assessment as a living program rather than a one-time exercise. Our System Security Plan and supporting policies are maintained on an ongoing basis as controls and threats evolve. Third-party (C3PAO) certification is the natural next step, and we will pursue it as soon as an assessment slot is available to us and our contracts require it.
FedRAMP Moderate controls
For customers who work with federal agencies, the security of the cloud beneath their supply chain matters as much as the security of their own environment. Infab runs entirely on AWS GovCloud, using FedRAMP-authorized cloud services that keep customer data inside a controlled, government-grade boundary staffed and operated under U.S. jurisdiction.
Under FedRAMP, Infab is considered a Cloud Service Provider (CSP). Because our systems are not in direct use by the Federal Government, a full FedRAMP authorization is not required of us today. That distinction is deliberate in how we describe our posture: we speak in terms of equivalency to the Moderate baseline rather than claiming an authorization to operate that would not accurately reflect our position.
We are committed to FedRAMP Moderate equivalency so that customers who are contractually bound to those controls can rely on documented evidence of ours. When a security reviewer needs to map our environment to the Moderate baseline, we can provide the artifacts to support that review rather than leaving a gap in their own compliance package.
Independent testing
A self-assessment tells you whether your controls exist; a determined adversary tells you whether they hold. Every year, Infab commissions an independent third party to attempt to compromise our systems the way a real attacker would, probing for the weaknesses that internal reviews are prone to overlook.
Findings from each engagement are triaged by severity, remediated, and folded back into our security program so that the same class of issue does not resurface. We treat the report as a roadmap for hardening rather than a grade to be filed away, and the remediation work becomes part of how the platform evolves.
This annual cadence keeps our defenses measured against current threats rather than the assumptions we held when a system was first built. Just as importantly, it gives our customers independent, outside evidence that the posture described on this page reflects how our systems actually behave under pressure.