Trust Center

Cybersecurity and privacy overview.

Trust in a cybersecurity partner must be earned from something concrete. This page details the credentials our crew holds, the frameworks we implement, and how we handle your data. Every credential here was independently issued and is actively maintained.

Overview

Company credentials

Cyber-AB Registered Provider Organization

CMMC Registered Provider Organization (RPO)

RPO status is issued by Cyber-AB, the body authorized by the United States Department of Defense to oversee CMMC accreditation. OrbitalFire has met Cyber-AB’s requirements to guide organizations through CMMC preparation and certification. This credential is earned and maintained under ongoing oversight.

Company recognition

OrbitalFire has been recognized repeatedly for our growth as a small business and for providing superior managed security services to our customers, measured against providers across North America.

  • MSSP Alert Top 250 MSSPs, 2025
  • MSSP Alert Top 250 MSSPs, 2024
  • MSSP Alert Top 250 MSSPs, 2023
  • MSSP Alert Top 250 MSSPs, 2022
  • MSSP Alert Top 250 MSSPs, 2021
  • MSSP Alert Top 250 MSSPs

Individual credentials

Our crew holds more than 40 credentials across governance, risk assessment, operations, and AI security. Full certificates are available on request. The marks below are the ones customers and auditors ask about most.

  • Cyber-AB Registered Provider Organization
  • Cyber-AB Registered Practitioner Advanced
  • Cyber-AB Registered Practitioner
  • CMMC Certified Professional
  • CompTIA SecAI+
  • CISSP
  • CISM
  • CISA
  • CompTIA Security+
  • CompTIA CySA+
  • GIAC Security Expert
  • GIAC Certified Incident Handler
  • ITIL 4 Foundation
  • GIAC Certified Forensic Examiner
  • GIAC Web Application Penetration Tester
  • GIAC Certified Intrusion Analyst
  • GIAC Certified Detection Analyst
  • GIAC Cloud Security Essentials
  • GIAC Security Essentials
  • GIAC Critical Controls Certification
  • SANS Security Awareness Professional
Our own practices

Cybersecurity

OrbitalFire has adopted numerous cybersecurity practices to manage risk to our own business, including several of the frameworks our customers are subject to.

Frameworks

NIST AI Risk Management Framework

The framework our Robot Acceptable Use Policy aligns to. It governs how we use automation and AI on your work: what those tools may do, what stays with people, and who answers for the outcome.

NIST SP 800-171

The control set we use as our foundational assessment framework, and the basis of CMMC for the defense supply chain. We measure our own business against it, not only our customers.

PCI Data Security Standard (DSS)

Payment Card Industry Data Security Standard for organizations handling cardholder data. OrbitalFire assesses and declares full compliance annually.

Critical controls

  • Risk management
  • Policy management
  • Access controls
  • Least privilege
  • Intrusion and threat detection
  • Multi-factor authentication (MFA)
  • Encryption
  • Configuration management
  • Vulnerability management
  • Background checks
  • Security awareness training
  • Phishing testing
  • Penetration testing
  • Backup
  • Cyber insurance
Your data

Customer data handling

We collect only what is necessary to deliver our services, retain it only as long as required, and give you clear visibility into how it is handled.

Zero Knowledge

OrbitalFire has no access to your systems. We never log in to your environment, and we never hold your credentials. Where a service needs information from inside your network, Vulnerability Management and Configuration Management among them, it comes from an agent your own IT deploys. The agent runs locally in your environment and reports back to us. We never take custody of, or maintain, credentials, passwords, or other authentication data.

Minimum Necessary

Delivering managed security services may require us to collect data about networks, assets, and users, along with dark web monitoring results, vulnerability scan findings, and evidence gathered during assessments or incidents. We collect only what the specific services you have engaged require.

Privacy

When you fill in a form or contact us, we collect what you provide. When you visit the site, our tools collect technical and behavioral information. We use it to answer you, to manage our customer and prospect relationships, to improve the site, and to meet our legal obligations.

We do not sell personal information under any circumstances, and we do not share it with third parties for marketing purposes.

The full detail — what we collect, how long we keep it, and your rights over it — is in our privacy policy.

Inquiries

For security questionnaires, certification documentation and compliance inquiries, write tohello@orbitalfire.com or call (844) ORB-FIRE (672-3473).

OrbitalFire makes no warranties, express or implied, on this page.

  • Will you have access to our systems?

    No. We never log in to your environment, and we never hold your credentials. Where a service needs information from inside your network, Vulnerability Management and Configuration Management among them, it comes from an agent your own IT deploys. The agent runs locally and reports back to us. We call this Zero Knowledge, and it is also why we do not make changes in your environment ourselves.

  • Do you hold our passwords or credentials?

    No. We never take custody of, or maintain, credentials, passwords, or other authentication data. Where a service needs to reach inside your network, it does so through an agent your own IT deploys rather than through an account belonging to us.

  • What information do you collect about us?

    Only what the services you have engaged require. That can include data about networks, assets, and users, along with dark web monitoring results, vulnerability scan findings, and evidence gathered during assessments or incidents. We keep it only as long as required. What we collect, how long we keep it, and your rights over it are set out in our privacy policy.

  • Do you sell or share our data?

    No. We do not sell personal information under any circumstances, and we do not share it with third parties for marketing purposes. What we collect when you contact us or visit the site is used to answer you, to manage our relationship with you, to improve the site, and to meet our legal obligations.

  • We need you to complete our security questionnaire. Who do we send it to?

    Write to hello@orbitalfire.com or call (844) ORB-FIRE (672-3473). Security questionnaires, certification documentation, and compliance inquiries all reach the same place. Much of what a questionnaire asks about is on this page already, and every credential listed here was independently issued and is actively maintained.

Tell us about your business.

A half-hour conversation about what you're being asked for and where you actually stand. If we can help, you'll have a proposal usually within a day.

Not ready to talk? Check your readiness in five minutes and see where to start.