Trust Center - Slingshot Aerospace
Slingshot Aerospace
Slingshot Aerospace is the leader in Space Operations Intelligence & Autonomy (SOIA), delivering AI-powered solutions that help government and commercial partners track, interpret, and act on activity in space. By combining real sensor data, advanced analytics, and simulation, we enable faster, more confident decisions in an increasingly complex space environment.
Controls
Updated 27 minutes ago
Infrastructure security
| Control | Status |
|---|---|
| Remote access encrypted enforced The company's production systems can only be remotely accessed by authorized employees via an approved encrypted connection. |
|
| 03.13.13.a Use of mobile code is controlled. |
|
| 03.04.01.f The inventory is maintained (reviewed and updated) throughout the system development life cycle. |
|
| 03.04.06.a Essential system capabilities are defined based on the principle of least functionality. |
|
| 03.04.07.f The use of nonessential functions is restricted, disabled, or prevented as defined. |
|
| 03.04.03.a Changes to the system are tracked. |
|
| 03.13.11.a FIPS-validated cryptography is employed to protect the confidentiality of CUI. |
|
| 03.01.20.c Connections to external systems are verified. |
|
| 03.01.07.c Non-privileged users are prevented from executing privileged functions. |
|
| 03.05.02.a The identity of each user is authenticated or verified as a prerequisite to system access. |
Organizational security
| Control | Status |
|---|---|
| Employee background checks performed The company performs background checks on new employees. |
|
| 03.09.01.a Individuals are screened prior to authorizing access to organizational systems containing CUI. |
|
| 03.12.04.a A system security plan is developed. |
|
| 03.06.03.a The incident response capability is tested. |
|
| 03.10.03.a Visitors are escorted. |
|
| 03.13.03.c User functionality is separated from system management functionality. |
Product security
| Control | Status |
|---|---|
| Control self-assessments conducted The company performs control self-assessments at least annually to gain assurance that controls are in place and operating effectively. Corrective actions are taken based on relevant findings. If the company has committed to an SLA for a finding, the corrective action is completed within that SLA. |
|
| Penetration testing performed The company's penetration testing is performed at least annually. A remediation plan is developed and changes are implemented to remediate vulnerabilities in accordance with SLAs. |
|
| Vulnerability and system monitoring procedures established The company's formal policies outline the requirements for the following functions related to IT / Engineering: - vulnerability management; - system monitoring. |
|
| 03.04.01.a A baseline configuration is established. |
|
| 03.04.07.o The use of nonessential services is restricted, disabled, or prevented as defined. |
|
| 03.05.10.b Passwords are cryptographically protected in transit. |
|
| 03.13.15.a The authenticity of communications sessions is protected. |
Internal security procedures
| Control | Status |
|---|---|
| Configuration management system established The company has a configuration management procedure in place to ensure that system configurations are deployed consistently throughout the environment. |
|
| Development lifecycle established The company has a formal systems development life cycle (SDLC) methodology in place that governs the development, acquisition, implementation, changes (including emergency changes), and maintenance of information systems and related technology requirements. |
|
| Organization structure documented The company maintains an organizational chart that describes the organizational structure and reporting lines. |
|
| Access requests required The company ensures that user access to in-scope system components is based on job role and function or requires a documented access request form and manager approval prior to access being provisioned. |
|
| Incident response plan tested The company tests their incident response plan at least annually. |
|
| Risk assessment objectives specified The company specifies its objectives to enable the identification and assessment of risk related to the objectives. |
|
| Risks assessments performed The company's risk assessments are performed at least annually. As part of this process, threats and changes (environmental, regulatory, and technological) to service commitments are identified and the risks are formally assessed. The risk assessment includes a consideration of the potential for fraud and how fraud may impact the achievement of objectives. |
|
| 03.04.06.b The system is configured to provide only the defined essential capabilities. |
|
| 03.04.09.b Installation of software by users is controlled based on the established policy. |
|
| 03.12.01.b Security controls are assessed with the defined frequency to determine if the controls are effective in their application. |
Vanta connects to a company's core systems to continuously monitor these controls.