Procurement readiness

Status — can you sub-PO us today?

Honest registration status up front so you don't waste time. UEI is active (QDL3BAL1NLY3); CAGE and SAM are pending. We can support pre-activation teaming conversations and proposal capture now.

UEIActive QDL3BAL1NLY3
CAGE CodePending
SAM.gov RegistrationActive by June 15, 2026
Capability StatementAvailable for download PDF
Primary contactTeam@OlenArc.com · Book a 25-min call
LocationsUtqiaġvik, AK (HQ) · Scottsdale, AZ

For the full picture — insurance posture, set-aside eligibility, NIST 800-171 / FedRAMP detail, and the certifications we deliberately do not pursue — see Certifications & Compliance Posture →

Vehicles we're sub-ready under

We sub-perform under our prime's existing vehicle, on our prime's invoice. We do not hold our own GWAC seats — that's the point. We don't compete for your agency relationship. We fit cleanly inside FAR 52.219-14 subcontracting limitations on services contracts.

GSA OASIS+

Unrestricted, Small Business, and 8(a) pools. Sub-ready on services task orders — including 8(a) sole-source TOs up to the $4.5M services threshold.

8(a) STARS III

GWAC for 8(a) primes. We slot under primes' STARS III seats inside the FAR 52.219-14 sub-ceiling.

GSA MAS IT — SIN 54151S

Lowest-friction lane for civilian software task orders. Many ANC primes hold multiple subsidiary MAS IT positions.

NITAAC CIO-SP3 SB / CIO-SP4

Health-and-civilian heavy — aligned with IHS, HHS, and BIA / BIE software task orders.

GSA Polaris (SB / HUBZone / WOSB)

Newer SB GWAC tracks. We sub-perform under the prime's Polaris seat where the SOW fits our module shapes.

Agency IDIQs — IHS / BIA / BIE / DOI

Direct civilian-agency IDIQs for grants management, case management, public-facing portals, and program reporting.

We do not claim to hold OASIS+, STARS III, CIO-SP, or MAS IT as a prime. We sub under primes who do. If your vehicle isn’t listed here, ask — we can usually sub under it.

Why pick us — when 100 small subs are on your bench list

The first sub-PO is the hardest. You carry the CPARS risk; we don’t have history with you yet. This page is the short answer to why us, not them — compared to the other shapes you could put on your task order.

Option A Offshore dev team Cheap rate Time-zone gap on weekly demos CUI / 800-171 awkward to staff Cultural-context gaps on Native programs Bench depth opaque to your PM Your CPARS, their schedule
Option B US solo contractor Bus-factor = 1 One person; vacation = stop Hard to scale past one workstream Compliance posture self-attested only Capacity unclear during proposal Founder-as-developer, not founder-on-call
Option C Generic small US firm May go prime Pursuing prime work — potential channel conflict No specific Native-serving credibility Likely splitting attention across larger sales pipeline Sub-PO is opportunistic, not strategic Mid-engagement scope creep risk
OlenArc Civilian software studio · sub-only Strategic sub We sub-perform — we don’t compete for the prime’s agency relationship Rooted in Utqiaġvik · Native-serving credibility primes can’t buy Named senior leads · founder on every engagement Fixed-scope 4–12 wk sprints · weekly demos · no end-of-engagement surprise Civilian / unclassified · 508 / NIST 800-171 self-assessment in flight

What primes ask us first — and our specific answer

The six real questions that surface in the first capture call. Short, direct answers; no hand-waving on the things your contracts team will actually check.

Will you compete with us for the prime?

No— we sub-perform under primes — we don’t compete for your agency relationship, and don’t hold a federal prime vehicle. Your task order is safe; there’s no path on our side to recompete you next cycle.

What’s your bench depth if Lorenzo gets hit by a bus?

Senior teamwith a vetted specialist network across engineering, AI, UX, and operations. Founders on every engagement. Specialist subcontractors brought in by name when scope requires — backup ownership is structural, not improvised.

Have you actually shipped at federal scale?

Productionacross all 8 North Slope Iñupiat villages for the Arctic Slope Community Foundation — applicant portal, admin/review dashboard, AI navigator chatbot, impact reporting layer. Multi-year operating agreement, not a pilot.

How do you handle scope creep on a fixed-price sub-PO?

Fixed shapeper module with an explicit decline list in writing. Weekly scope check on each demo. New asks go to a change-order conversation, not a silent overrun.

Will you blow our CPARS at delivery time?

Weekly demosprevent the end-of-engagement surprise. Your PM sees real software every week of a 4–12 week sprint. If something’s sliding, you know in week 2, not week 11.

What about clearance, CMMC, FedRAMP?

Civilian / unclassified only— we don’t pursue DoD or cleared work, which keeps the engagement clear of DFARS surprises. NIST SP 800-171 self-assessment in flight; FedRAMP-Moderate inherited via AWS GovCloud or Azure Gov when the task order requires it. See compliance posture.

From first call to first sub-PO — a five-step de-risking path

Designed so each step costs you something small and produces something your capture team can show. The first deal is the hardest; this is how we make it cheap to start.

1
Intro call
15 minutes · what task order, what gap, what shape
NDA optional
2
Capability brief
5 business days · tuned to your specific task order, not a generic one-pager
2-page brief
3
Scoped pilot
3–6 weeks · fixed-price · small enough to fit under $10K micro-purchase if needed
Pilot SOW
4
Sub-PO ready
Teaming agreement signed · module-shape priced · bench named
Signed TA + SOW
5
Kickoff & weekly demos
Production engagement · CPARS-safe cadence · founder on call
Production sub-PO

What we sign for — and what we decline

Named up front so your contracts team can rule us in or out before the first call.

What we sign for

  • Discrete software modules — portal, intake, AI doc review, dashboard, integration glue.
  • Fixed-scope sprints — 4–12 week increments with named acceptance criteria.
  • Civilian / unclassified work — HIPAA-aware and CUI-aware where required.
  • Sub-PO under your existing vehicle — OASIS+, STARS III, MAS IT, CIO-SP, Polaris.
  • Commercial project experience — deployed, named, references under mutual NDA.
  • Civilian agencies — IHS, BIA, HHS, GSA, DOI, state HHS, Tribal programs.

What we decline

  • Strategy decks & advisory hours. Not our shape.
  • Standalone staff augmentation. Bodies-on-keyboards is not what we sell.
  • Cleared / DoD / ITAR / classified scopes. Civilian only.
  • Fabricated past performance. No CPARS-rated federal PP claims.
  • Work a community we serve hasn’t consented to. Tribal & Native-serving: non-negotiable.
  • Competing for your agency relationship. The prime stays the prime.
Risk, Security & Data Practices

How we handle access, security, and sensitive data

Primes are accountable to the agency for risk posture. Here’s ours at a glance — without overclaiming certifications we don’t hold.

ItemPostureStatus
NIST SP 800-171Self-assessment against the 110 controls; SPRS-ready summary on requestIn progress Q4 2026 · SPRS Q1 2027
FedRAMP-ModerateVia inheritance — AWS GovCloud or Azure Government deployments when the engagement requires itPosture-ready · not pursued as a CSP
Clearance postureCivilian / unclassified lane. No DFARS-7012, no CMMC L2 work today.By design
Personnel staffingMatched to each task order’s compliance requirements — Public Trust eligibility or US-person staffing on requestPer engagement
CUI handlingRole-based access, separation of public / internal / sensitive data, audit-ready permission model on forms, dashboards, documents, reportsBuilt-in by default
HIPAA-aware developmentFor healthcare-adjacent scopes — practices defined before implementation, not claimed as HIPAA compliancePer engagement
Third-party pen testingScopable add-on when the task order or prime requires independent assessmentOn request

Data sovereignty-aware design

Client data stays under client ownership and control. We align with existing Tribal, agency, or funder data policies, and can work with preferred hosting partners when required. For ANC and Tribally-owned primes this means we slot into your data governance rather than imposing our own. We do not claim sovereign-AI guarantees or legal data-sovereignty consulting.

We do not claim FedRAMP authorization, CMMC certification, automatic HIPAA compliance, or any certification we have not received. Compliance scope is defined at the start of each engagement.

Considering a sub engagement?

Tell us the agency, the vehicle, and the module gap. We respond within two business days with a fit / no-fit read. More questions? Federal teaming FAQ →