> ## Documentation Index
> Fetch the complete documentation index at: https://docs.blockops.network/llms.txt
> Use this file to discover all available pages before exploring further.

# Compliance & assurance

> The control framework behind the platform, what is mapped to which standard, and what is and is not certified.

Institutions that adopt the platform need to know what controls exist, which standards they are measured against, and what evidence is available. This page states that plainly.

## Control framework

The platform's controls are mapped against **CCSS**, **SOC 2** and **ISO 27001**; **no certification is held yet**. The mapping is a working document maintained by engineering: each control is tied to the standard's requirement, its implementation in the platform, and its current status. It is reviewed as controls are added.

The mapping is organised in five areas:

| Area                          | What it covers                                                                                                       |
| :---------------------------- | :------------------------------------------------------------------------------------------------------------------- |
| **Keys**                      | Key generation, share storage and encryption, node identity, resharing, and backup and recovery of shares.           |
| **Transaction integrity**     | Request validation, balance holds, transaction planning, signing authorisation, broadcast and confirmation tracking. |
| **Ledger integrity**          | Deposit detection, balance reconciliation against chain state, and the withdrawal record.                            |
| **Policy and governance**     | Roles, scoped API keys, spend limits, destination controls, approval groups, dual control and the withdrawal freeze. |
| **Operations and monitoring** | Audit events, webhook delivery, node health, backups, and operational access to production.                          |

How each area is implemented is described in [How the platform is secured](/security/how-the-platform-is-secured), [Who holds the keys](/security/who-holds-the-keys) and [Access control](/security/access-control).

## What we do not claim

* No SOC 2 report, ISO 27001 certificate, CCSS attestation or third-party audit report exists today. Do not represent the platform as certified in your own compliance filings.
* The platform does not perform AML or sanctions screening, KYT, or Travel Rule messaging. Institutions that need those controls apply them in their own systems before a withdrawal is requested, or hold withdrawals for approval and screen them there.
* Regulatory status depends on how you deploy and operate the platform and on your own licences; Blockops does not provide legal or regulatory advice.

## Evidence for your review

Compliance and security reviewers can request the current control mapping and the architecture material behind it from [hello@blockops.network](mailto:hello@blockops.network). For self-hosted deployments, the [security checklist](/self-hosted/security-checklist) lists the controls that fall to your operators.

This page is updated when a certification is obtained or a standard is added to the mapping.
