Control framework
The platform’s controls are mapped against CCSS, SOC 2 and ISO 27001; no certification is held yet. The mapping is a working document maintained by engineering: each control is tied to the standard’s requirement, its implementation in the platform, and its current status. It is reviewed as controls are added. The mapping is organised in five areas:
How each area is implemented is described in How the platform is secured, Who holds the keys and Access control.
What we do not claim
- No SOC 2 report, ISO 27001 certificate, CCSS attestation or third-party audit report exists today. Do not represent the platform as certified in your own compliance filings.
- The platform does not perform AML or sanctions screening, KYT, or Travel Rule messaging. Institutions that need those controls apply them in their own systems before a withdrawal is requested, or hold withdrawals for approval and screen them there.
- Regulatory status depends on how you deploy and operate the platform and on your own licences; Blockops does not provide legal or regulatory advice.

