Security & compliance

Trust begins with accurate claims.

This page describes the current public posture and intended direction of the VanFossen Holdings security program. It does not represent an independent certification or audit report.

Current status

VanFossen Holdings has not stated that it has completed a SOC 2 examination. No SOC 2 report is currently offered on this website.

Program direction

A practical path toward stronger assurance.

01

Govern

Document ownership, policies, risk decisions, asset inventories, vendor responsibilities, and periodic management review.

02

Protect

Establish access control, multifactor authentication, secure development, encryption, backup, change-management, and vendor requirements.

03

Detect

Define logging, monitoring, vulnerability management, security reporting, and repeatable evidence collection.

04

Respond

Maintain incident roles, escalation paths, communications procedures, containment steps, and post-incident review.

05

Recover

Test restoration procedures, business continuity expectations, data recovery objectives, and lessons learned.

06

Verify

Complete readiness assessment, remediate gaps, retain operating evidence, and engage an independent qualified CPA firm when the organization is ready.

SOC 2

What a real examination involves.

SOC 2 is an examination of controls at a service organization relevant to security, availability, processing integrity, confidentiality, or privacy. A company cannot obtain a valid SOC 2 report simply by publishing policies or adding security language to a website.

A future examination would require a defined system, documented controls, evidence that the controls operated, management assertions, and work performed by an independent CPA firm. Until that work is complete, this site will not display a SOC 2 certification badge or claim.

VanFossen Holdings may use the NIST Cybersecurity Framework 2.0 as a voluntary risk-management reference while developing its program.

Responsible disclosure

Report a security concern.

If you believe you have identified a vulnerability involving this corporate site or a VanFossen Holdings product, email vanfossenace@gmail.com with the affected product, steps to reproduce, potential impact, and a safe way to contact you. Do not access, alter, download, or disclose data that does not belong to you.