What a CISO checks first

On-premise is a closing argument, not a footnote.

Most governance platforms are cloud-only. In a sovereign account that is a hard blocker — and you are not blocked. Which is why the deployment choice is the first thing on this page rather than the last.

Same product, same guarantees, your choice of perimeter.

On-premise, or cloud on AWS or Azure. For entities where data cannot leave the perimeter, on-premise is available and proven — not a roadmap item, and not a professional-services special case.

  • · On-premise, inside your own perimeter
  • · Cloud on AWS or Azure
  • · In-country data residency where required

UAE policy alignment

Named, or not published.

01

Deployed to UAE data and information-security policy

With in-country residency where the entity requires it. The specific policies and frameworks are named on this page, by name, or this line does not ship.

TBC · The specific UAE frameworks, by name

A CISO reading a generic sentence assumes the policies have not been read. Naming them is the whole value of the claim.

02

Certifications held

A penetration test is not ISO 27001 and not SOC 2. A government procurement questionnaire asks for those by name. Where they are held they will be listed here; nothing is claimed that cannot be produced on request.

TBC · ISO 27001 and SOC 2 — held, or not

Internal material describes a "pre-validated security suite". That is sales positioning, not evidence, and it is not published here until there is a certificate to point at.

Independently penetration tested

A certificate says a process was followed.

A penetration test says someone was paid to break in, and reported what they found.

CyberGate performs independent penetration testing against Focus. That is the stronger claim of the two, and worth stating precisely rather than softening into "security certified".

TBC · Test date and scope tested — application, infrastructure, or both

A penetration test is point-in-time and scope-bound. Published without a date and a scope, a CISO assumes the test was narrow and old. If it is re-tested on a cycle, the cycle is worth more than the test.

Immutable chain of custody

Person, authority, data, timestamp — on every action.

Forensic-grade, and the basis of both audit immunity and contractual defensibility. In a capital project, ambiguity about who approved what is what disputes are made of.

The same decision record the homepage shows, exported as an evidence set for an audit or a dispute.

Core integrity

The risk everyone has been burned by, carried contractually.

03

Integration that cannot destabilise the core

Focus reads and writes through certified connectors and never takes ownership of the core's data model. Integration with a heavily customised ERP is the risk everyone has been burned by, so it is the one we carry contractually.

04

The Core Integrity Guarantee

Zero ERP data corruption, zero core disruption. If our integration causes an issue we fix it at our cost until it is restored. It is one of the 3 guarantees, not a support policy.

The evidence pack

The review starts from evidence, not from a questionnaire.

What Rationale hands a CISO on day one: one versioned PDF, suitable for a procurement pack, covering deployment topology, data flows, the audit model, the penetration test report scope, and the connector inventory.

Where the work happens, stated plainly.

Focus is built and operated from Abu Dhabi, with an in-house engineering and R&D centre in Novi Sad, Serbia. A procurement questionnaire will ask where data is processed and where staff sit, so both are stated here rather than discovered later: data residency follows your deployment choice, and the delivery model is an Abu Dhabi headquarters with a European engineering centre.

Security review

Start the review from evidence, not from a questionnaire.

Bring your security team to the call. The questions a CISO asks are the ones this page was written to answer — and the two it cannot answer yet are marked as such.

20 days, or it's free. 15 minutes to scope it.