Verified SDVOSBCertified MBE · CRMSDC / NMSDCUEI LBGKMB1WCBU3CAGE 1RJW3

Enterprise & Public Sector

Capabilities, credentials & past performance

Norbeck Technologies delivers full-lifecycle software systems, automated cloud architecture, and cybersecurity compliance for government agencies, prime partners, and enterprise clients.

Core Disciplines

Four engineering disciplines, one delivery team

Applied AI Architecture

Speech, language, and vision pipelines embedded into production workflows — dispatch automation, document structuring, opportunity scoring, and decision support.

LLM orchestration • Speech-to-text • Retrieval

NIST SP 800-53 Security Engineering

Cloud architectures engineered to implement NIST SP 800-53 Rev. 5 moderate control baselines and FISMA reporting standards: control selection, continuous monitoring, POA&M discipline, and automated vulnerability management.

RA-5 • FISMA reporting • NIST CSF • Zero Trust

Secure Edge Computing

Distributed edge runtimes, hardened cloud desktops, network design, and resilient delivery across apex and subdomain environments.

Edge runtime • VDI • Network design

Custom Software Engineering

Full-lifecycle product delivery on PostgreSQL, TypeScript, and React — from discovery and architecture through CI/CD, operations, and sustainment.

PostgreSQL • React / TypeScript • CI/CD

Vehicles & Credentials

How agencies buy from NTI

Credentials as held by Norbeck Technologies, Inc. SAM.gov registration is active and renewal is tracked.

Veteran-Owned & SDVOSB

Active SBA VetCert status for Veteran-Owned and Service-Disabled Veteran-Owned Small Business. Renewal 10/12/2029.

Verify in SBA VetCert

Certified MBE

Certified Minority Business Enterprise through the Capital Region Minority Supplier Development Council (CRMSDC), an NMSDC affiliate regional council. Satisfies corporate and state supplier diversity mandates. Certificate number on request.

Verify with CRMSDC

CompTIA / GTIA member

Corporate membership in the Global Technology Industry Association (formerly CompTIA) covering technical standards of practice, workforce credentialing, and vendor due diligence.

GTIA

SeaPort-NxG

Navy SeaPort-NxG participation. Prime delivery history was performed under the predecessor SeaPort-e vehicle, which the Navy has sunset.

USPTO

Registered trademark protections

Maryland

Registered corporate entity since 2000

Primary NAICS codes

  • 541511Custom Computer Programming Services
  • 541512Computer Systems Design Services
  • 541519Other Computer Related Services
  • 541611Administrative & General Management Consulting

Contracting quick facts

Supplier diversity & corporate designations

Norbeck Technologies Inc. is an officially certified Minority Business Enterprise (MBE) through the Capital Region Minority Supplier Development Council (CRMSDC), an affiliate regional council of the National Minority Supplier Development Council (NMSDC). We partner with prime contractors, enterprise procurement teams, and commercial organizations to fulfill corporate supplier diversity mandates while delivering hardened, federal-grade information technology and automated software solutions.

Corporate certifications & affiliations

Certification verification checklist

Every NTI credential can be confirmed at its issuing authority. Each row links directly to the official source of record.

  • Veteran-Owned certification

    U.S. Small Business Administration — VetCert

    Active Veteran-Owned status for Norbeck Technologies, Inc. Entrance 04/12/2021; renewal 10/12/2029.

    UEI LBGKMB1WCBU3

    Verify in SBA VetCert
  • SDVOSB certification

    U.S. Small Business Administration — VetCert

    Active Service-Disabled Veteran-Owned Small Business status for Norbeck Technologies, Inc. Entrance 04/12/2021; renewal 10/12/2029.

    UEI LBGKMB1WCBU3

    Verify in SBA VetCert
  • Minority Business Enterprise (MBE) certification

    Capital Region Minority Supplier Development Council (CRMSDC) / National Minority Supplier Development Council (NMSDC)

    Certified MBE held at the parent entity, recognized by NMSDC corporate members, state agencies, and regional buyers in DC, Maryland, and Northern Virginia. Certificate number released on request.

    CRMSDC / NMSDC certified supplier

    Verify with CRMSDC
  • UEI / entity registration

    SAM.gov

    Active federal entity registration; renewal tracked.

    UEI LBGKMB1WCBU3

    Verify on SAM.gov
  • CAGE code

    DLA CAGE / SAM.gov

    Commercial and Government Entity code assigned to NTI.

    CAGE 1RJW3

    Verify CAGE code
  • Past performance

    USAspending.gov

    Federal award history including Department of Defense and VA work.

    Recipient UEI LBGKMB1WCBU3

    View award history

Data Assurance

How NTI handles customer data and AI

Every platform in the ecosystem operates under the same published data-handling commitments, so security reviewers can assess the portfolio once.

No customer data in model training

Audio, transcripts, grant narratives, and proprietary bid material are excluded from foundation model training and fine-tuning. Vendor model endpoints are used with training and retention disabled.

Voice and PII handling

RunToWork announces call recording before capture, and NTI Writing records only with explicit author consent. No voice biometric templates are created. Audio is encrypted at rest, retained only for the life of the ticket or project, and deleted on request.

Tenant and perimeter isolation

Each platform runs against its own database perimeter and credentials. NTI Manager reads scoped, aggregated metrics only — a compromise in a commercial venture cannot reach GovCon capture, grant, or accounting data.

Encryption and documentation

Data is encrypted in transit and at rest. Retention schedules, data flow diagrams, and control implementation summaries are available to agency and enterprise reviewers on request.

Compliance disclosure

NTI systems are engineered to satisfy NIST SP 800-53 security control baselines and are monitored using FedRAMP-informed practices. NTI does not claim FedRAMP authorization, a 3PAO assessment, or an agency Authority to Operate for these commercial platforms. System Security Plan artifacts, data flow diagrams, and control implementation summaries are available to agency reviewers on request.

Compliance notes — scope of NIST SP 800-53 / FISMA claims

Boundary
NTI commercial platforms run on a managed PostgreSQL platform (database, auth, storage) with application and API workloads on a global edge runtime and CDN. NTI's responsibility covers application code, data model, access control policies, and configuration; the underlying cloud providers retain responsibility for physical, host, and hypervisor controls.
Inherited vs. implemented controls
Physical and environmental (PE), media protection (MP), and much of the system and communications protection (SC) family are inherited from the cloud providers. NTI implements access control (AC), identification and authentication (IA), audit and accountability (AU), configuration management (CM), and risk assessment / vulnerability scanning (RA-5) at the application tier.
SSP status
A System Security Plan is maintained internally in NIST SP 800-53 Rev. 5 moderate baseline format, together with data flow diagrams and a POA&M. It is a self-attested document; it has not been assessed by a 3PAO and is not an agency-accepted SSP.
ATO context
No agency Authority to Operate, ATO reciprocity, or FedRAMP authorization (including FedRAMP Ready or In Process) applies to these commercial platforms. FISMA reporting language describes engineering practice, not an agency FISMA system of record. Deployment into an agency boundary would require a sponsoring agency's assessment and authorization process, which NTI supports with control implementation summaries on request.

Technology Stack

What we build on

A deliberately small, modern stack that keeps security review, delivery velocity, and long-term sustainment aligned.

Development & runtimes

PostgreSQLTypeScriptReactNodeTailwind CSSPlaywright CI/CD

Cloud & infrastructure

Managed PostgresEdge runtimeCloudflareMicrosoft 365Virtual desktops

Compliance & security frameworks

NIST SP 800-53 Rev. 5NIST CSFFISMA reportingRA-5Zero Trust