Skip to main content
Institutions that adopt the platform need to know what controls exist, which standards they are measured against, and what evidence is available. This page states that plainly.

Control framework

The platform’s controls are mapped against CCSS, SOC 2 and ISO 27001; no certification is held yet. The mapping is a working document maintained by engineering: each control is tied to the standard’s requirement, its implementation in the platform, and its current status. It is reviewed as controls are added. The mapping is organised in five areas: How each area is implemented is described in How the platform is secured, Who holds the keys and Access control.

What we do not claim

  • No SOC 2 report, ISO 27001 certificate, CCSS attestation or third-party audit report exists today. Do not represent the platform as certified in your own compliance filings.
  • The platform does not perform AML or sanctions screening, KYT, or Travel Rule messaging. Institutions that need those controls apply them in their own systems before a withdrawal is requested, or hold withdrawals for approval and screen them there.
  • Regulatory status depends on how you deploy and operate the platform and on your own licences; Blockops does not provide legal or regulatory advice.

Evidence for your review

Compliance and security reviewers can request the current control mapping and the architecture material behind it from hello@blockops.network. For self-hosted deployments, the security checklist lists the controls that fall to your operators. This page is updated when a certification is obtained or a standard is added to the mapping.