SOC 2 Type II Target FY26
Security, availability, and confidentiality criteria audited against the AICPA Trust Services framework.
Our dedicated hardware model is the foundation of everything else we offer. Every workstation is dedicated, every network path is independently routed, and every client operates within a verified B2B security sandbox with full audit accountability.
We build security through verified physical separation — not through relying on hidden or unverifiable infrastructure. Every client gets a dedicated enterprise workstation and independently routed network path, so there is no shared surface area. All infrastructure is independently attested, auditable, and contractually guaranteed.
Single-tenant — Geo-attested — AES-256 — TLS 1.3 — Independent audit trails
Enterprise-grade controls live alongside every workspace — from the workstation firmware up to the API call that secures data in transit. Certifications marked target are tracked in our public roadmap.
Security, availability, and confidentiality criteria audited against the AICPA Trust Services framework.
Information security management system aligned with ISO/IEC 27001; scope covers infrastructure and operations.
Data subject request workflow, lawful basis tracking, and regional data residency for EU and California partners.
All data in transit protected with TLS 1.3 and all data at rest encrypted with AES-256 across the dedicated infrastructure stack.
Per-partner dedicated enterprise workstation, geographically verified broadband routing, and audited session attestation.
24/7 hardware health telemetry, anomaly alerting, and three-region failover with documented runbooks.
Compliance status and audit reports are available under signed NDA. Contact support@consumerhorizon.com.
The following disclosures are provided to facilitate institutional due diligence, bank onboarding, vendor risk reviews, and enterprise procurement processes. They represent Horizon Consumer Intel LLC's formal position as a Wyoming-registered limited liability company operating in full compliance with U.S. federal, Wyoming state, and applicable international regulatory frameworks. The binding Master Services Agreement (MSA), Data Processing Addendum (DPA), and applicable Statements of Work (SOW) govern all client engagements; request executed copies at support@consumerhorizon.com.
Horizon Consumer Intel LLC ("Horizon," "we," or "the Company") is a Wyoming-registered limited liability company providing B2B enterprise hardware infrastructure, managed compliance, and zero-trust routing services to independent commercial operators and enterprise brand partners. Use of the Horizon platform is exclusively for legitimate business and commercial purposes. Consumer use is not offered and is contractually prohibited.
By executing a service agreement or accessing the platform, the client ("Partner") confirms that (i) all commercial activities conducted through Horizon's infrastructure comply fully with applicable laws, regulations, and the published terms of service of any upstream platforms, marketplaces, or programs being utilized; (ii) all commercial operations conducted through Horizon's infrastructure are owned or formally authorized for commercial operation by the Partner; (iii) all settlement amounts due are paid according to the agreed billing schedule; and (iv) the Partner will cooperate with reasonable compliance, security, and financial audits upon request.
Any activity constituting fraud, misrepresentation, violation of applicable commerce law, or any breach of this B2B service agreement may result in immediate suspension. All suspension decisions are reviewed by a human compliance officer within one business day, with a documented appeals process available under the MSA.
Governing law & jurisdiction: The MSA is governed by the laws of the State of Wyoming, without regard to conflict-of-law principles. Venue for any dispute rests exclusively in the state and federal courts located in Sheridan County, Wyoming, unless the parties agree in writing to binding arbitration administered by the American Arbitration Association (AAA) under its Commercial Arbitration Rules. The UN Convention on Contracts for the International Sale of Goods is expressly disclaimed.
Assignment & successors: Neither party may assign the MSA without prior written consent, except that Horizon may assign to a successor-in-interest in connection with a merger, reorganization, or sale of substantially all assets, provided the successor assumes all obligations in writing. The MSA is binding upon and inures to the benefit of permitted successors and assigns.
Severability & entire agreement: If any provision of the MSA is held unenforceable, the remaining provisions remain in full force and effect. The MSA, together with all SOWs, the DPA, and any executed amendments, constitutes the entire agreement between the parties and supersedes all prior negotiations, representations, or agreements relating to its subject matter.
The full executed Master Services Agreement is available on request under countersignature and NDA. Contact support@consumerhorizon.com.
Horizon Consumer Intel LLC is a Wyoming limited liability company formed and in good standing under the Wyoming Limited Liability Company Act (Wyo. Stat. 搂搂 17-29-101 et seq.). The Company's statutory registered office and registered agent are located at 75 E 3rd St, Sheridan, WY 82801, United States, in full compliance with Wyo. Stat. 搂 17-28-101. A current Certificate of Good Standing issued by the Wyoming Secretary of State is available to qualified institutional counterparties upon written request.
Registered agent & statutory presence. The Company's statutory presence in Wyoming is maintained exclusively through a licensed commercial Registered Agent in good standing with the Wyoming Secretary of State. The Registered Agent is authorized to receive service of process, official correspondence from the Wyoming Secretary of State, the Wyoming Department of Audit, the Wyoming Division of Banking, and any lawful subpoena, summons, or regulatory inquiry directed to the Company. All material state filings — including annual reports, amendments to the Articles of Organization, and changes to management or membership — are made in a timely manner as required by Wyoming law.
Distributed engineering & operations model. Horizon operates a globally distributed team of engineers, infrastructure specialists, compliance officers, and client-success personnel. Engineering, infrastructure management, and client support teams operate from secure, distributed cloud-node environments across multiple jurisdictions to ensure business continuity, time-zone coverage, and resilience. No single physical site constitutes a single point of failure for client operations. All distributed team members are subject to background checks, confidentiality obligations, and role-based access controls consistent with the controls described in Section 04 (Security & Compliance Infrastructure).
Data-center & upstream infrastructure partners. Physical data-center hosting, network transit, edge routing, and dedicated-hardware procurement are provided under strict bilateral Master Service Agreements and enterprise-level Service Level Agreements with tier-1 infrastructure providers. Upstream partners are bound by confidentiality and security commitments at least equivalent to Horizon's own obligations to clients. Specific vendor identities and facility locations are released to qualified prospects and existing clients under countersigned NDA.
Banking & depository relationships. Corporate banking services are maintained through FDIC-insured U.S. depository institutions used solely to receive service fees billed under executed Master Service Agreements and to disburse operating expenses. Horizon does not hold, transfer, or remit client or partner funds, and does not operate any money-transmission, payment-rail, or funds-disbursement business. Banking partners conduct their own independent BSA/AML and sanctions due diligence prior to onboarding and on an ongoing basis.
Institutional counterparties may request further detail on corporate governance, capitalization, and beneficial-ownership disclosure under the procedures described in Section 08 (Due Diligence & Verification for Enterprise Clients).
Horizon Consumer Intel LLC processes personal and commercial data exclusively to deliver contracted B2B services. Categories of data include: business contact identifiers, operational telemetry, settlement records, compliance audit logs, and support correspondence. We do not sell, rent, or disclose partner data to unauthorized third parties.
Encryption standards: TLS 1.3 in transit; AES-256 at rest; hardware-backed key management. Data residency: U.S. and EU regions selected at provisioning. Retention: Active partner data is retained for the duration of the engagement plus 30 days, then purged from production systems and all backups within 90 days, except where longer retention is required by applicable tax, financial, or anti-fraud law.
GDPR (EU/EEA): Horizon acts as a data processor under Article 28 DPA. Lawful basis for processing is contractual necessity. Standard Contractual Clauses (SCCs) are available on request. CCPA (California): We do not sell personal information. Authorized service providers are contractually bound to equivalent protections.
Data subject requests — access, correction, deletion, portability, and objection — may be submitted to support@consumerhorizon.com and processed within 30 calendar days at no charge. Our sub-processor list and DPA are available under NDA on request.
The Horizon platform is a B2B enterprise operational infrastructure service. Partners represent and warrant that all use of the platform constitutes legitimate commercial activity conducted in full compliance with applicable laws, including but not limited to applicable consumer protection, advertising, commercial speech, and platform-to-platform program regulations.
Partners expressly agree not to use the platform to (i) engage in fraud, misrepresentation, or deceptive commercial practices; (ii) conduct any transaction involving proceeds derived from unlawful activity; (iii) operate commercial programs the Partner does not own or lack documented written authorization to manage; (iv) transmit malicious code, unsolicited commercial communications, or illegal content; or (v) violate any applicable anti-money laundering (AML) or sanctions laws.
AML / KYC commitment: Horizon maintains a written AML compliance program aligned with FinCEN guidance for money services businesses. All partners are subject to identity verification and beneficial ownership disclosure at onboarding. Partners agree to provide updated KYC documentation upon request. Horizon will file a Suspicious Activity Report (SAR) with FinCEN if any transaction is suspected to involve money laundering or terrorism financing.
Horizon reserves the right to suspend any partner account whose activity pattern is inconsistent with the representations made at onboarding or suggests a violation of this AUP. Suspensions are reviewed by a human compliance officer within one business day.
Horizon's security architecture is built on a zero-trust, single-tenant enterprise hardware model. Every partner is provisioned a dedicated enterprise workstation with independently routed, geographically verified network paths. There is no shared virtual machine infrastructure, shared credential environment, or co-mingled network routing between partners.
Controls: AES-256 encryption at rest, TLS 1.3 in transit, hardware-backed key storage, mandatory hardware MFA for production access, role-based access control (RBAC) with least-privilege enforcement. Monitoring: 24/7 hardware health telemetry, anomaly detection, three-region failover with documented runbooks. Incident response: Documented SLA of 4-hour initial response for critical severity incidents.
SOC 2 Type II & ISO 27001 control framework. The platform is operated under a written control framework aligned with the AICPA Trust Services Criteria (Security, Availability, Processing Integrity, Confidentiality, Privacy) and ISO/IEC 27001:2022. Internal control readiness assessments — including design reviews, walkthroughs, and operating-effectiveness testing on sampled evidence — are conducted continuously by Horizon's internal compliance and risk team, with results reviewed quarterly by executive management. Formal independent attestation reports are issued by a licensed CPA firm following completion of the SOC 2 Type II observation window, and ISO 27001 certification is pursued through an accredited certification body. Independent attestation reports and certificates are released to qualified prospects and existing enterprise partners under countersigned NDA; requests are processed through the workflow described in Section 08.
Continuous monitoring. Vulnerability scanning, configuration-drift detection, and centralized log retention are maintained across all production environments. Penetration testing by an independent third-party firm is conducted at least annually, and material findings are tracked through remediation to closure under a documented corrective-action plan.
All client engagements are governed by a countersigned Master Services Agreement (MSA), a per-engagement Statement of Work (SOW), the Data Processing Addendum (DPA), and applicable Order Forms. These documents collectively establish the contractual scope, fees, deliverables, service-level commitments, confidentiality terms, liability allocations, indemnification provisions, and termination procedures for each engagement.
Bilateral contracts & engagement valuations. Each commercial engagement is documented in a standalone SOW that establishes a custom engagement valuation, defined deliverables, acceptance criteria, and a pre-approved accounting reconciliation schedule. Engagement valuations are fixed per SOW and may only be modified by a fully executed amendment signed by an authorized officer of each party. No off-statement adjustment, retroactive concession, or unwritten concession is permitted.
Banking & KYB onboarding. Horizon partners with FDIC-insured U.S. depository institutions to facilitate commercial payment processing. All partners must complete a structured KYB/AML onboarding process 鈥?including beneficial-ownership disclosure under FinCEN’s Corporate Transparency Act, OFAC sanctions screening, and entity verification 鈥?prior to infrastructure provisioning. Banking partners conduct their own independent BSA/AML due diligence prior to onboarding and on an ongoing basis.
Service Level Commitments. Horizon commits to commercially reasonable efforts to maintain platform availability of at least 99.9% measured monthly on a rolling 30-day basis, excluding scheduled maintenance windows announced with at least 72 hours' notice and force-majeure events. Critical-severity incidents are acknowledged within 4 hours of receipt of a confirmed incident notification through the documented support channels. Service-credit remedies for failure to meet committed availability are set forth in the applicable SOW and represent the Partner's sole and exclusive remedy for service-level failures, subject to the liability cap in the MSA.
Zero-tolerance AML / KYC onboarding. No engagement is activated until the partner has completed Horizon's onboarding process, including (1) identity verification of the contracting entity and its beneficial owners under the Corporate Transparency Act; (2) sanctions screening against OFAC SDN, EU Consolidated, and HMT consolidated lists; (3) review of the partner's commercial activities for consistency with the MSA, AUP, and applicable law; and (4) execution of the MSA and applicable SOWs by an authorized signatory. Onboarding is refused or terminated without liability where a partner fails to meet Horizon's compliance thresholds.
Dispute resolution. The parties will attempt in good faith to resolve any dispute through senior-executive escalation for a period of thirty (30) calendar days before initiating formal proceedings. Unresolved disputes are subject to the governing-law and venue provisions of the MSA (Section 01) unless the parties agree in writing to binding arbitration administered by the AAA under its Commercial Arbitration Rules, seated in Sheridan County, Wyoming. Notwithstanding the foregoing, either party may seek immediate injunctive or equitable relief in a court of competent jurisdiction to protect its confidential information, intellectual property, or compliance obligations.
Force majeure. Neither party is liable for delay or failure in performance (other than payment obligations) caused by events beyond reasonable control, including acts of God, government action, war, terrorism, civil unrest, internet or telecommunications failure, large-scale cyberattack, pandemic, or labor disturbance, provided the affected party gives prompt notice and uses commercially reasonable efforts to resume performance.
Requests for the MSA template, SOW template, DPA template, and standard SLA exhibits may be directed to support@consumerhorizon.com. Template documents are released under mutual NDA.
Horizon Consumer Intel LLC, a Wyoming limited liability company (Entity ID: available upon request from support@consumerhorizon.com, registered at 75 E 3rd St, Sheridan, WY 82801), maintains a formal Anti-Money Laundering (AML) compliance program aligned with FinCEN's Bank Secrecy Act Advisory for Money Services Businesses and related guidance.
AML program elements: (1) Written AML policies and procedures reviewed annually. (2) Customer Due Diligence (CDD) and Enhanced Due Diligence (EDD) for all partners, including beneficial ownership verification under the Corporate Transparency Act (CTA). (3) Transaction monitoring with automated alerting for anomalous settlement patterns. (4) Mandatory SAR filing with FinCEN within the required timeframe for any suspicious activity. (5) Sanctions screening against OFAC SDN, EU Consolidated, and HMT lists prior to onboarding and on an ongoing basis.
Source of funds. All funds received by Horizon represent service fees billed to B2B clients under executed Master Service Agreements and applicable Statements of Work for the provision of dedicated enterprise hardware infrastructure and managed compliance services. Horizon does not receive, hold, or disburse funds on behalf of any third party, and does not distribute rewards, payouts, or compensation of any kind to end users. Banking records, invoices, and contractual documentation are retained for a minimum of five years and are available to law enforcement, financial regulators, or banking partners upon lawful request.
This disclosure is provided to facilitate bank account opening, correspondent banking relationships, and institutional due diligence reviews. For the full AML program documentation or to request a copy of our AML/BSA Compliance Manual, contact support@consumerhorizon.com.
Horizon welcomes institutional due diligence reviews from prospective and current enterprise partners, banking institutions, regulated financial counterparties, government procurement officers, and authorized third-party risk platforms. All verification requests are processed through a single institutional channel to ensure documentation integrity, controlled disclosure, and full audit traceability.
Verification channel. Submit institutional verification requests to support@consumerhorizon.com with the subject line "DD Request — [Institution Name]". A compliance officer will acknowledge receipt within two (2) U.S. business days and provide a written estimate of the verification timeline and applicable NDA requirements.
Standard documentation available under NDA. Subject to execution of Horizon's mutual non-disclosure agreement, the following documentation may be released to qualified institutional counterparties:
(1) Certificate of Good Standing issued by the Wyoming Secretary of State, dated within ninety (90) days of issuance. (2) Wyoming Entity Identification and Articles of Organization, certified by the Wyoming Secretary of State. (3) Master Services Agreement (MSA) template, including liability, indemnification, confidentiality, and termination exhibits. (4) Statement of Work (SOW) template and service-level exhibit. (5) Data Processing Addendum (DPA) template and Standard Contractual Clauses (SCCs) for transfers from the EEA, Switzerland, and the United Kingdom. (6) SOC 2 Type II readiness summary and, when issued, the formal independent attestation report. (7) ISO 27001 statement of applicability and, when issued, the formal certification. (8) AML / BSA Compliance Manual summary and FinCEN-aligned program overview. (9) Sub-processor list, including data-residency region and the nature of processing performed by each sub-processor.
Beneficial-ownership disclosure. For partners and counterparties subject to the Corporate Transparency Act or comparable beneficial-ownership regimes, Horizon provides a Beneficial Ownership Information disclosure packet identifying the natural persons who, directly or indirectly, exercise substantial control over the Company or own or control not less than 25 percent of the ownership interests, as those terms are defined in 31 CFR 搂 1010.380(d)(1). The packet is released only under executed NDA and a recorded identity-verification handshake.
Banking & financial-counterparty onboarding. Banking institutions, correspondent banks, payment-service providers, and licensed money transmitters may request Horizon's compliance packet tailored to financial-counterparty onboarding, including KYB documentation, banking references, settlement-rail information, and the AML/BSA program summary. Requests should be addressed to support@consumerhorizon.com with the subject line "Banking Onboarding — [Institution Name]".
Response standards. Standard documentation is released within five (5) U.S. business days of NDA execution. Custom audit responses — including completed vendor-questionnaire packets (e.g., SIG, CAIQ, VSAQ), SOC 2 crosswalk responses, and on-site or video walkthroughs — are scheduled on a case-by-case basis and quoted in advance.
All documentation releases are logged, time-stamped, and retained for a minimum of five (5) years in accordance with Horizon's AML record-retention policy.