Govern
Document ownership, policies, risk decisions, asset inventories, vendor responsibilities, and periodic management review.
Security & compliance
This page describes the current public posture and intended direction of the VanFossen Holdings security program. It does not represent an independent certification or audit report.
VanFossen Holdings has not stated that it has completed a SOC 2 examination. No SOC 2 report is currently offered on this website.
Program direction
Document ownership, policies, risk decisions, asset inventories, vendor responsibilities, and periodic management review.
Establish access control, multifactor authentication, secure development, encryption, backup, change-management, and vendor requirements.
Define logging, monitoring, vulnerability management, security reporting, and repeatable evidence collection.
Maintain incident roles, escalation paths, communications procedures, containment steps, and post-incident review.
Test restoration procedures, business continuity expectations, data recovery objectives, and lessons learned.
Complete readiness assessment, remediate gaps, retain operating evidence, and engage an independent qualified CPA firm when the organization is ready.
SOC 2
SOC 2 is an examination of controls at a service organization relevant to security, availability, processing integrity, confidentiality, or privacy. A company cannot obtain a valid SOC 2 report simply by publishing policies or adding security language to a website.
A future examination would require a defined system, documented controls, evidence that the controls operated, management assertions, and work performed by an independent CPA firm. Until that work is complete, this site will not display a SOC 2 certification badge or claim.
VanFossen Holdings may use the NIST Cybersecurity Framework 2.0 as a voluntary risk-management reference while developing its program.
Responsible disclosure
If you believe you have identified a vulnerability involving this corporate site or a VanFossen Holdings product, email vanfossenace@gmail.com with the affected product, steps to reproduce, potential impact, and a safe way to contact you. Do not access, alter, download, or disclose data that does not belong to you.