Skip to content
Client Focus

Trust and compliance

Client Focus operates under a certified information security management system and documents its controls so that clients, auditors and supervisors can rely on them.

Effective date:
August 22, 2026
Last reviewed:
August 22, 2026
Version
1.0

1. Information security management

Client Focus is certified to ISO/IEC 27001. The certified management system covers the engineering and operations activities delivered from the Ashburn, Virginia and Hyderabad, India centers. The certificate is available on request; the statement of applicability is available under non-disclosure agreement.

2. Service organization controls

A SOC 2 Type II examination covering the security, availability and confidentiality trust services criteria is underway; the expected completion date is published on this page when confirmed.

3. Control frameworks

Controls are mapped to ISO/IEC 27001, NIST Cybersecurity Framework 2.0, PCI DSS for payment-adjacent systems, FFIEC guidance for banking clients, and GDPR for personal data.

4. Operational resilience

Two operations centers with overlapping shifts, documented handover, tested continuity plans and incident records retained with hop-by-hop timestamps. Evidence is prepared to the formats supervisors request under DORA (incident reporting and ICT third-party oversight), MiCA and the GENIUS Act implementing rules.

5. Data handling

Client data is processed only for the purposes set out in the service agreement, segregated by client, encrypted in transit and at rest, and retained under the client's retention schedule. Access is granted on a least-privilege basis and reviewed periodically.

6. Third-party risk

Suppliers that touch client systems or data are assessed before engagement and monitored during it. Exit plans are documented for critical suppliers.

7. Responsible disclosure

Security researchers who identify a vulnerability in Client Focus systems are asked to report it to security@clientfocusllc.com. Reports are acknowledged and handled under the incident process.

8. Requests for documentation

Clients and prospective clients may request the ISO 27001 certificate, control descriptions, the latest penetration test summary and the business continuity overview through their Client Focus contact or from procurement@clientfocusllc.com.

9. Custody position

Client Focus does not take custody of client assets and does not hold client signing keys. Key generation, storage and signing remain within the client's or its qualified custodian's environment. Client Focus operates with monitoring and alerting rights and, where contracted, proposes actions that the client's authorized approvers execute.

10. Separation of duties between engineering and security operations

Where a client or its supervisor requires separation of duties, the Client Focus engineering teams that build a system and the security operations teams that monitor it operate under independent reporting lines, with separate access, separate change authority and audit-ready attestation of the separation. The arrangement is documented in the service agreement.

Talk with Client Focus about your digital asset program.

Whether you are designing a new system, running one in production, or defending one, Client Focus brings engineering, network operations and security operations under one accountable model. Every request is reviewed by a principal of the firm.