Faction + OSec: Delivering Continuous Cyber Assurance for Owner-Controlled Zero Trust Networks
You shouldn't have to take our word that your protection is working. You should be able to verify it independently and continuously.

Today we announced our strategic partnership with OSec, which we believe is a key piece of the innovation and trust ownership model that Faction is bringing to the market. Our joint solution will provide organizations with ongoing monitoring and verification that their Zero Trust protections remain effective while supporting more informed cyber insurance underwriting.
Faction is built on a simple principle: the customer, not the vendor, should own and control trust. Your keys are yours. Your network's control plane never sits on the public internet where it can be attacked. We hold nothing we could be compelled or breached to give up. We're extending that principle one logical step further: if trust belongs to you, so should the proof. You shouldn't have to take our word that your protection is working. You should be able to verify it independently and continuously. OSec is how.
Why we're building this in, not bolting it on
Most security is verified once and then assumed. A penetration test in the spring. An annual certification. A compliance audit that produces a PDF and a sense of relief. As OSec's CEO, Mark Stamford, puts it, most organizations verify their security once and assume it stays effective. But the threat environment doesn't pause between audits: new vulnerabilities surface across firmware and hardware, configurations drift, and adversaries keep working. A point-in-time snapshot tells you nothing about your exposure NOW. That needs to change, and at Faction we are committed to being a driver of the change we seek in the industry.
What OSec brings
OSec has been dedicated since 2010 to providing world class continuous offensive security — exposure management and penetration testing that never really stops. Their Incenter platform, launched in 2023, continuously tests more than two million systems, applications, and API endpoints, and reports validated, exploitable vulnerabilities. Not a scanner's wall of theoretical findings, but the things that can actually be used against you. That signal-over-noise discipline is what makes continuous testing usable rather than exhausting, and it's why they're the right partner to build verification into our product.
What it will mean for our customers
Two things, concretely, from launch.
First, OSec will test and red team the Faction platform, stack and its components on an ongoing basis, delivering validated findings with remediation guidance so we close real gaps, wherever possible before they ever become public. We would rather be attacked by someone on our side, every day, than wait to be attacked by someone who isn't.
Second, and more importantly for you, OSec independently tests your protected environment. It probes your Faction Virtual Private Circuits from the outside to confirm that your protected users, devices, and networks remain invisible and unreachable from the public internet: the core promise of the architecture, verified by a third party rather than asserted by us. The results land in secure dashboards you control, and, if you choose, that you can share with authorized cyber insurers.
Why this is a business advantage, not just a security one
Here is the part I care about most, and it is why my job title is "product," not "engineering." Continuous, independent, timestamped evidence that your protections are actually holding is not just reassuring — it is an asset.
Cyber insurance is where that shows up first. Underwriters are tightening requirements and asking harder questions, and "we ran a pen test last year" is a weak answer. A live, independent record that your protected environment has stayed unreachable from the internet, updated continuously, not annually, is a strong one. It can help you qualify for coverage, support better terms, and provide real evidence if you ever need to make a claim. Security that you can prove changes the economics, not just the risk posture. That is why our initial focus with OSec is squarely on the small and mid-sized businesses and the cyber-insurance ecosystem that serve them, the organizations with the most to gain and the least room for a six-figure surprise.
Faction's new paradigm for Cyber Assurance
Step back and this fits the whole design of what we're shipping. We apply Zero Trust principles to our hardware, with independent forensic inspection and testing through the ORION program and other independent cyber lab partners before a Faction Pod or Portal ever carries a packet. With OSec, we will verify continuously in the field, for as long as the system operates. Zero Trust applies to every layer of our stack, and cyber integrity is verified in the field. Together they extend and enhance Zero Trust to meet the threat environment we face today.
My co-founder and CTO, Dave Rand, framed it simply when we announced the partnership: trust should belong to the customer, not the vendor. Owner-controlled keys were the first half of that; owner-controlled verification is the second. Initial capabilities will be included in v1 at launch, with roll out of the full suite of auditing dashboards for cyber insurers during Q4 2026.
When you deploy Faction Networks, you won't have to trust it. You'll be able to verify it. And if you're evaluating security you cannot independently verify, from us or anyone else, it's time to ask why.
Own your trust. Keep your peace of mind.
The new threat environment calls for a new Zero Trust model. We'd welcome the chance to show you how Faction puts you in control and secures your critical systems and assets rapidly with low cost and IT overhead.


