The Long Range Discrimination Radar has an unglamorous dependency: air conditioning. The missile-defense system consumes substantial power and produces substantial heat. Its building controls manage cooling, water, power and emergency notifications. Let those systems fail, and the radar’s ability to do its job can suffer. A security problem in a building can become a problem in the defense of a country.
Sentar worked on the industrial control systems behind this radar, navigating the Defense Department’s cybersecurity requirements during construction. The assignment explains the company rather neatly. The important machine is often surrounded by smaller machines, software and permissions. Sentar’s business lives in those connections.
- The work: cyber defense, secure software, intelligence analysis and engineering for systems whose interruption matters.
- The customers: defense and intelligence agencies, military healthcare, and companies supplying government markets.
- The distinctive detail: a code scanner that handles Fortran, alongside research into protecting digital twins.
- The business twist: employees became co-owners through an ESOP in 2025.
The radar’s less glamorous dependencies
At the radar site, Sentar was subcontracted by construction prime contractors. Its team helped categorize the potential effects of losing confidentiality, integrity or availability, then developed security documentation, procedures and control assessments. The company says it also helped change the planned authorizing-official and risk-management arrangements early in construction.
That last detail is telling. Installing a control and deciding who may authorize it are connected jobs. A secure component is useful only if it fits the system and can enter service. The risk here was prospective: failure of supporting controls could impair radar operations. Sentar’s account describes prevention, rather than a recovery from an actual radar outage.
Across its customer portfolio, the same practical range appears. For the Defense Health Agency, Sentar lists medical-device security and incident response. For the Army Corps of Engineers, it lists utility controls and combined information-technology and operational-technology systems. For the Navy, it develops secure software and cloud solutions. Intelligence customers use network and signals analysis. The common thread is knowing enough about the mission to understand what a cyber event would interrupt.
A scanner with a memory for Fortran
Sentar’s origins predate the current enthusiasm for AI. In 1990, Peter and Karen Kiss bought Wake Research Group, a small systems engineering business that became Sentar. Two DARPA contracts in 1995 shifted the company toward research and development. Its technical history includes intelligent agents, distributed knowledge systems and intrusion detection for missile-defense networks.
KnoWeb, its knowledge-based framework, belongs to that lineage. It is designed to coordinate distributed knowledge and reasoning through fault-tolerant intelligent agents. The vocabulary comes from an earlier AI tradition: rules, knowledge units and inference. Sentar’s interest in AI did not begin with a chatbot.
The more tangible product story concerns legacy code. Sentar’s customer was building the Objective Simulation Framework, a missile-defense simulation with a large code base and older programming languages. According to the company’s case study, available commercial scanning options did not cover the Fortran code the project needed to inspect.
Sentar developed a Fortran scanner and folded security testing into the project’s Agile development cycles and build acceptance criteria. Its veriScan tool, renamed CodeValor in May 2020, combined scanning capabilities and mapped findings to Common Weakness Enumeration categories and defense Security Technical Implementation Guides. Sentar reports that the project’s development timeline fell by 20%. That is a result from this engagement, rather than a forecast for every buyer.

Today, CodeValor links to GitHub, GitLab and Bitbucket repositories, supports multiple languages and can join a continuous integration pipeline. Teams can collaborate on findings and export reports, including plans of action and milestones. The appeal is specific: inspection and evidence for developers working inside demanding assurance processes. A scanner still needs people to judge findings and repair code.
Four months to get medical equipment connected
During the COVID-19 response, the problem took a more immediate form. Laboratory equipment and ventilators needed cybersecurity authorization for network connectivity, including connections to the MHS Genesis electronic health record system. Sentar’s case names a Siemens Dimension EXL 200 analyzer and a Dräger Evita Infinity V500 ventilator.
The team developed a rapid authorization process, assembling network topology, data-flow diagrams and vulnerability evidence. It applied lessons across system packages and developed an Assess and Incorporate process for lower-risk systems. The company reports favorable authorization decisions for all targeted systems within four months, compared with a more typical year to eighteen months per system.
For favorable authorization decisions across the targeted systems.
Different scopes; a process comparison, not a controlled trial.The useful lesson is the process redesign. Lower-risk systems received a faster route; the evidence still had to support the decision. An organization cannot simply borrow the four-month figure. It can borrow the habit of matching the authorization pathway to the system’s risk and reusing lessons without treating every package as identical.
A $99,995 experiment in trust
A digital twin is a virtual representation of a physical machine. The model can help people understand the equipment, but the exchange of data creates another connection to protect. In September 2024, Sentar announced DLA work on that connection, following an earlier digital-twin contract involving cyberattack analysis and prediction.
The federal SBIR record makes the scale concrete: $99,995 for a Phase I project called Zero Trust for Digital Twins, starting September 10, 2024. The proposed architecture restricts permissions, divides network communications into smaller segments, and uses software-defined networking to monitor and enforce the policies. Its stated design aims to preserve ordinary IP communications without modifying the connected components.
This is a research proposition, with conditions attached. The enforcement layer must see and control the relevant communications. Devices must continue to interoperate. Adding security around an operating machine must preserve the behavior that makes the machine useful. The award establishes funding for the approach; it does not establish that every industrial environment can adopt it successfully.
MissionValor approaches the related prioritization problem. Sentar describes it as mapping mission dependencies and predicting the operational impact of cyberattacks, including a Mission Impact Prediction Score. The attraction is asking what an attack could do to the operation. As an analytical principle, that also exposes a limitation: a dependency map that misses a crucial relationship will give decision makers an incomplete picture.
What the contract headlines really buy
Sentar sells professional services, assessment work and software, and conducts funded research. Government customers can buy through its contract vehicles; CodeValor buyers can request a demonstration and a quote. Commercial customers include defense suppliers needing CMMC assessments and cloud providers pursuing FedRAMP or GovRAMP authorization. The company presents itself as an authorized third-party assessor in those markets.
Its place in the market is therefore broader than a software vendor’s. Sentar can build, assess and operate systems, while bringing its own tools to selected problems. Other government contractors, compliance specialists and software assurance vendors offer alternatives. Sentar’s public cases make a credible case for mission familiarity, but they are not independent comparisons proving universal superiority.
The large contract numbers require careful reading. Its 2024 cybersecurity risk-management recompete carried a $32 million base year and four options, with a potential value above $172.7 million. In August 2026, it announced a position on NIWC Pacific’s $278 million multiple-award IDIQ contract. That position lets Sentar compete for task orders. A two-year option could raise the vehicle’s potential value to $400 million. These figures describe purchasing capacity and conditional work, rather than money already earned by Sentar.
The people who now own the work
The founders’ people-first language acquired a financial form in 2025, when Sentar introduced an Employee Stock Ownership Plan. Its 2026 announcements describe the business as employee-owned. Bridget McCaleb leads it as Catalyst and CEO, an unusually exuberant title for a company whose work can involve security documentation.
“Sentar was founded on the premise that employees are our most important asset.”
Peter Kiss / 2020 anniversary announcement

The culture has some visible substance: an employee giving committee, investment in Huntsville’s cyber education programs and mental-wellness resources. In September 2026, Sentar announced its eleventh consecutive appearance in South Carolina’s workplace awards, placing fifth among large employers. The program combines employer information with confidential employee surveys. It offers a view of employee experience alongside the company’s own description of itself.
Borrow the dependency map
For a defense supplier, Sentar offers a route into assessment and compliance work. For a developer, CodeValor offers scanning and reporting. For an operator of consequential equipment, its engineering and risk work addresses the distance between an exposed component and an interrupted mission.
The portable idea is simple enough to use without buying anything: write down the outcome the system must deliver, trace the controls, data and utilities it depends on, and rank security work against that chain. Then test the assumptions with the people who operate it. Somewhere on the diagram there may be an ordinary cooling controller. It deserves a box of its own.