CityZeen®
Trust & Compliance · Public disclosure · 2026

Regulation is distribution
here is what governs us.

CityZeen® is supervised by the Luxembourg CSSF and operates under MiFID II, AIFMD and SFDR. The pages that follow set out our operational regulatory framework and our roadmap toward the enterprise security standards institutional buyers request — SOC 2, ISO 27001, ISO 42001.

In force In progress Roadmap Not applicable

Operational regulatory framework

01

These are the operational regulations that govern CityZeen® today, supervised by Luxembourg CSSF. They are publicly stated on /compliance and binding on every entity in the group.

FrameworkWhat it isStatus
CSSF · LuxembourgPrimary supervisor. Commission de Surveillance du Secteur Financier.In force
MiFID IIMarkets in Financial Instruments Directive II — professional client framework, best execution, transaction reporting.In force
AIFMDAlternative Investment Fund Directive — Luxembourg AIF structure, depository, risk management framework.In force
SFDRSustainable Finance Disclosure Regulation — Article 8 & 9 classification, PAI reporting, taxonomy alignment.In force
GDPREU 2016/679 — Art. 6 lawful basis, Art. 30 ROPA, Art. 35 DPIA, Art. 33 72-hour breach notification.In force
eIDASElectronic identification & trust services — qualified signatures on regulated documents.In force
AML5 / AML6EU Anti-Money Laundering Directives — KYC/KYB, beneficial-ownership transparency, suspicious-transaction reporting.In force
CSSF Circular 22/806Outsourcing & IT arrangements — governs the data-protection posture of identity-verification vendors.In force

Enterprise security standards

02

These are the certifications institutional procurement teams ask for in vendor security questionnaires. They are enterprise security controls, distinct from regulatory licensing. CityZeen® does not currently hold these attestations — the roadmap below is what we publish.

StandardWhat it coversTarget
SOC 2 Type II AICPA attestation against the Trust Services Criteria — Security (always), Availability, Confidentiality, Processing Integrity, Privacy. Type II covers a 6–12 month observation window. The most-asked attestation in US / UK institutional procurement. Roadmap
Type I [20XX-Qx] · Type II [20XX-Qx]
ISO/IEC 27001:2022 Information Security Management System (ISMS) certified against the 93 Annex A controls across four themes (organisational · people · physical · technological). Stage 1 + Stage 2 audit; 3-year recertification with annual surveillance. Roadmap
Stage 1 [20XX-Qx] · Stage 2 [20XX-Qx]
ISO/IEC 42001 AI Management System (AIMS) — AI risk assessment, AI impact assessment, AI-specific Annex A controls. Structural way to demonstrate EU AI Act alignment. Scope: AME asset-matching engine, ASK AI concierge, Dynamic Pricing, Taxonomy. Roadmap
Alongside ISO 27001
NIST CSF 2.0 Voluntary US framework — Govern · Identify · Protect · Detect · Respond · Recover. Not certifiable. Used as a control-mapping and board-reporting lens, paired with SOC 2 / ISO 27001 for executive reporting. Adopted internally
Annual independent pen test Black-box + grey-box network and application testing by an accredited firm. Summary report shared with institutional counterparties under NDA. Pre-requisite for credible SOC 2 / ISO 27001 readiness. Roadmap
First test [20XX-Qx]
HIPAA · PCI DSS · FedRAMP · SOX ITGC · TSA US healthcare · payment-card data · US federal cloud · listed-company IT · US transport. Not applicable to CityZeen's institutional capital-markets perimeter. Not applicable

What each standard means

03
SOC 2 — the SaaS security attestation
An independent AICPA attestation that a service organisation's controls — over Security, and optionally Availability, Confidentiality, Processing Integrity and Privacy — are designed and operating effectively. Type I examines design at a point in time; Type II examines operation across a months-long observation window.
CityZeen® · Roadmap
ISO/IEC 27001 — the ISMS standard
Certifies that an organisation operates an Information Security Management System against the 93 controls in Annex A of the 2022 revision, with a documented Statement of Applicability and a measured risk-treatment cycle. Certifiable by an accredited body, recertified every three years.
CityZeen® · Roadmap · aligned with CSSF Circular 22/806 outsourcing register
ISO/IEC 42001 — the AI management standard
The first international certifiable standard for an AI Management System — AI risk assessment, AI impact assessment, supplier governance for foundation models, continuous control of deployed AI. The structural way to demonstrate EU AI Act readiness.
CityZeen® · Roadmap · scope includes AME, ASK AI, Dynamic Pricing, Taxonomy
GDPR — the EU privacy regulation
The binding privacy regulation for organisations established in the EU or targeting EU residents. Requires a documented Article 6 lawful basis, an Article 30 ROPA, Article 35 DPIAs for high-risk processing, transfer mechanisms for non-EU flows (SCCs 2021/914 or adequacy), and 72-hour breach notification under Article 33.
CityZeen® · In force · DPAs signed with every authorised sub-processor; register disclosed under NDA
NIST CSF 2.0 — the structuring lens
A voluntary US framework structured around six Functions — Govern, Identify, Protect, Detect, Respond, Recover. Not certifiable, but widely used as a control-mapping and board-reporting lens.
CityZeen® · Adopted internally as part of SOC 2 preparation
Independent penetration test — the institutional ask
An authorised, independent simulated attack against the production application, network and (where applicable) social-engineering surfaces. A penetration-test summary report is a standard institutional ask.
CityZeen® · Roadmap · summary report will be shared under NDA

Disclosures

04
CityZeen® is regulated under Luxembourg CSSF, MiFID II, AIFMD and SFDR (Section 01). CityZeen® is not currently certified under SOC 2, ISO/IEC 27001 or ISO/IEC 42001 — these are stated as roadmap items in Section 02. Any public claim of SOC 2 / ISO 27001 / ISO 42001 readiness or certification will be dated and signed off by the CEO at the moment of the relevant attestation.

A standard Data Processing Agreement incorporating the 2021/914 Standard Contractual Clauses is available on request from the Compliance team. The complete sub-processor register (GDPR Art. 28 / Art. 30) is disclosed to verified institutional counterparties under a mutual NDA.