Skip to content
Client Focus

Trust and compliance

Client Focus documents its controls for clients, auditors and supervisors. ISO 27001 certification and a SOC 2 Type II examination are planned.

Effective date:
August 22, 2026
Last reviewed:
August 22, 2026
Version
1.0

1. Information security management

ISO/IEC 27001 certification is planned. A certificate number and certified scope will be published only after the certification is issued. Current control documentation is available on request under non-disclosure agreement.

2. Service organization controls

A SOC 2 Type II examination covering the security, availability and confidentiality trust services criteria is planned; the expected timing is published on this page when confirmed.

3. Control frameworks

Controls are mapped to ISO/IEC 27001, NIST Cybersecurity Framework 2.0, PCI DSS for payment-adjacent systems, FFIEC guidance for banking clients, and GDPR for personal data.

4. Operational resilience

Documented business continuity, disaster recovery and incident response plans are planned under the Client Focus ISO/IEC 27001 program. Corporate systems run on Google Workspace and Amazon Web Services, whose data center resilience is attested in their own SOC 2 and ISO/IEC 27001 reports. Evidence is prepared in the formats supervisors request, including DORA incident reporting and ICT third-party oversight.

5. Data handling

Client data is processed only for the purposes set out in the service agreement and only where the engagement requires it. Advisory engagements are delivered without receiving or storing client confidential data. Where client data is processed, it is encrypted in transit and at rest and access is limited to named personnel. Formal periodic access review is planned under the ISO/IEC 27001 program.

6. Third-party risk

Client Focus does not use subcontractors to deliver client services unless disclosed to and approved by the client.

Current sub-processors are listed on the Sub-processors page. A formal supplier risk assessment process is planned under the ISO/IEC 27001 program.

7. Responsible disclosure

Security researchers may report vulnerabilities under the Responsible Disclosure policy.

8. Requests for documentation

Clients and prospective clients may request current certification and examination status, available control descriptions and a completed security questionnaire through their Client Focus contact or from procurement@clientfocusllc.com.

9. Custody position

Client Focus does not take custody of client assets and does not hold client signing keys. Key generation, storage and signing remain within the client's or its qualified custodian's environment. Client Focus operates with monitoring and alerting rights and, where contracted, proposes actions that the client's authorized approvers execute.

10. Separation of duties between engineering and security operations

Where a client or its supervisor requires separation of duties, the Client Focus engineering teams that build a system and the security operations teams that monitor it operate under independent reporting lines, with separate access, separate change authority and audit-ready attestation of the separation. The arrangement is documented in the service agreement.

Talk with Client Focus about your digital asset program.

Whether you are designing a new system, running one in production, or defending one, Client Focus brings engineering, network operations and security operations under one accountable model. Every request is reviewed by a principal of the firm.