Identity and Access
Role-based access and least-privilege practices keep system permissions tied to assigned responsibilities and approved work.
CF builds information security into the people, systems, facilities, and workflows behind every engagement. Role-based access, trained teams, documented procedures, and monitored technology create a disciplined operating environment for client work.

Independently Audited Information Security
CF Solutions Philippines Inc., the Philippine operating entity supporting CF delivery, is certified to ISO/IEC 27001:2022 under certificate PH26/00000076.
ISO/IEC 27001:2022 is the globally recognized standard for information security management systems. Certification requires independent audit of a structured, risk-based security program, with ongoing surveillance supporting continual improvement.
Role-based access and least-privilege practices keep system permissions tied to assigned responsibilities and approved work.
Confidentiality obligations, acceptable-use standards, workstation controls, and facility practices protect the delivery environment.
Documented procedures, quality review, exception handling, escalation paths, and continuity planning make security responsibilities clear.
Client-approved tools, logging, monitoring, backups, and technical controls protect the systems and workflows used for delivery.
Protected health information
For healthcare engagements involving PHI, CF establishes approved channels, access controls, and handling procedures and executes Business Associate Agreements when required by the parties, data access, and agreed scope.
CF makes its ISO certificate and scope available directly and provides security overviews and available due-diligence materials to prospective clients. Additional documents are shared through the appropriate confidential review process.
Review CF’s ISO/IEC 27001:2022 certification, delivery controls, and due-diligence materials, then align the security plan to your engagement.