Trust and procurement
What we hold, what we do not, and what to do about the gap
Everything on this page is current as of the date below, including the parts that are a no. A vendor page in this category is read by somebody whose job is to find the overclaim, and the fastest way through that review is to have made it already.

Attestations
Certifications a diligence checklist asks about
All of these are currently a no. Each row says who asks for it and what to do instead, because a page that only says no is honest and useless.
SOC 2 Type II
Not heldWho asks: District and enterprise IT, usually as a hard gate before a security review will even begin.
No audit has been completed and no report exists. The controls such a report would describe are written into the data processing agreement instead, which is contractual rather than independently audited, and the difference is worth knowing rather than glossing.
DHS SAFETY Act designation
Not heldWho asks: A school district's general counsel. It limits a buyer's liability exposure after an incident, which is the question counsel is actually asking when they ask about certifications.
Not held and not yet applied for. It is the strongest single asset a vendor in this category can carry, and you should ask everyone on your shortlist about it, including us. What we offer against it is a different thing: an evidence chain for every alert that can be recomputed by hand from published constants.
ISO/IEC 27001
Not heldWho asks: Buyers outside the United States, and some private schools and health systems.
No certification. Raised here because it is on many diligence templates, not because it is commonly required of this category in US K-12.
SDPC National Data Privacy Agreement
Not heldWho asks: Districts in states where the Student Data Privacy Consortium agreement is the standard route to approving a vendor.
No signed NDPA is on file with the consortium. We will sign a district's own data privacy agreement on request, and the published student privacy terms are the starting point for that conversation.
Third-party penetration test
Not heldWho asks: Security reviewers, usually as an alternative to a SOC 2 report.
No external test has been commissioned. There is also no published vulnerability disclosure policy yet; reports are read at the security address below and answered by a person.
How to buy
Purchasing routes
Cooperative contracts let a public buyer skip a competitive solicitation. We hold none of them yet, and one entry on this list is a programme you should not spend a week applying to.
Sourcewell
Not availableNo awarded contract. A district that needs a cooperative vehicle today buys through a reseller who holds one, or runs its own solicitation.
TIPS
Not availableNo awarded contract.
BuyBoard
Not availableNo awarded contract. Relevant mainly to Texas districts working to a state panic mandate.
OMNIA Partners
Not availableNo awarded contract.
E-Rate
Not availableNot an oversight and not worth an application. E-Rate funds connectivity and internal network equipment. Surveillance, cameras, and detection are not eligible categories under either funding category, so no vendor in this category can be bought with it.
Direct purchase
AvailableHow every deployment is bought today, most of them on grant money. The funding page lists the programmes that pay for this work and what an application needs from a vendor.
Most deployments are bought with grant money. The funding page lists the programmes that pay for this work, what each publishes, and what an application needs from a vendor.
Security
Properties you can verify rather than take on trust
Each of these is enforced by something in the build rather than by a policy document, which is the only kind of security claim worth printing on a page like this.
The appliance connects outward only
It opens no inbound port and accepts no inbound connection. There is nothing in the cloud that can reach into the building and no route by which a compromise of this platform reaches a camera.
We hold no credential that can open a stream
A camera password is sealed when you enter it, delivered once to your appliance, and erased. Only a fingerprint survives. Replacing an appliance costs you re-entered passwords, and the console says so before you do it.
The audit log cannot be edited
It is append-only and hash-chained per organization. Nothing in the codebase issues an update or a delete against it, and the viewer verifies the chain rather than trusting it.
No biometrics, anywhere
Following a person between cameras during one incident computes no identity. There is no face data, no embedding, and no field in the data model in which one could be recorded.
Doors cannot be unlocked
Lockdown secures doors and there is no release action to ask for. The absence is enforced three separate ways, and a build fails if one of them is removed.
Video does not leave the building
Streams are analysed on site. Only the cropped frame attached to a detection is uploaded, and the retention period for those is yours to set.
Terms
What is already published
The contractual answers live in the legal directory and are not repeated here.
Reporting a vulnerability
Write to security@optiarms.com and a person will answer. There is no published disclosure policy and no bounty programme yet, so there is nothing here promising you a timeline that nobody has committed to.
Statuses on this page were last reviewed on 2026-08-18.