Compliance & Regulatory Support
Compliance isn't security. Security is being protected. Compliance is proving it — to an auditor, a regulator, an insurer, or a customer who just sent you a questionnaire with a deadline on it. Most businesses that fail an audit weren't insecure. They just couldn't produce the paperwork showing what they'd been doing all along.
We do both, and we'll take the accountability that comes with it.
FTC Safeguards Rule
You may be covered and not know it. The Safeguards Rule applies to “financial institutions,” and that phrase is far broader than it sounds. It isn't just banks and lenders. If you prepare tax returns, you're covered. Accountants, CPAs, mortgage brokers, auto dealers arranging financing, collection agencies, investment advisers, payday lenders, and businesses that finance their own customers all fall inside it.
It requires a person, not just a policy. The Rule requires you to designate a Qualified Individual responsible for your information security program. That's a real position with real accountability. We'll take the QI role formally, or work alongside whoever holds it internally.
What it actually requires. A written risk assessment, reviewed on an ongoing basis. Multi-factor authentication. Encryption of customer information at rest and in transit. Access controls with periodic review. Written incident response. Oversight of your own service providers. Employee security training. And an annual written report to your board or governing body — which we produce, because as QI it's our obligation to.
When the regulator arrives. A breach affecting 500 or more consumers has to be reported to the FTC within 30 days. Long before that, someone will ask you to prove what your program looked like on a given date. We can hand them every policy, the evidence it was followed, the full risk assessment, and every remediation that came out of it. Not a description of your program — the documented record of it.
HIPAA
A Security Officer is required. We'll be yours. HIPAA requires a designated Security Officer accountable for safeguarding protected health information. We take that role for you if you need it, or support the person who holds it internally.
We're a Business Associate, and we sign the agreement. Any vendor touching PHI is directly liable under HIPAA — including us. We execute a BAA, and we hold our own subcontractors to the same standard.
The parts people miss. Encryption at rest and in transit is the easy part. What gets missed is offboarding — the account that still exists after someone leaves. Mobile devices, because phones reaching your email means PHI on phones. Physical safeguards and proper disposal of media and paper. Backups that have actually been test-restored, not just confirmed as running. A written sanctions policy, so violations have consequences you can point to. Six years of documentation retention. And the sixty-day clock on notifying affected individuals after a breach.
AI is the newest gap. Your staff are already using it. If PHI can reach a consumer AI account, you have an unmanaged disclosure and no BAA covering it. We block AI services at the network and endpoint level by default, and permit only approved enterprise tooling under a signed BAA with zero data retention.
SOC 2
Usually, someone else's deadline. SOC 2 rarely starts as your idea. It starts when a large customer informs you it's now a condition of doing business, with a date attached. That letter arrives more often every year as major brands push security requirements down to their suppliers.
We've done exactly this. A national brand required its processing partner to achieve SOC 2. We took them through it — built the control environment, produced the evidence, and got them through the audit. We continue to maintain it, because SOC 2 isn't a certificate you frame. It's an ongoing attestation that has to be re-earned, and the controls have to hold up in between.
What we do and don't do. The audit itself is performed by an independent CPA firm — that's required, and it's not us. What we do is everything on either side of it: designing controls that map to the Trust Services Criteria, implementing them in your actual infrastructure, generating the evidence continuously rather than scrambling in the weeks before fieldwork, and answering the auditor's requests when they come.
If the letter just arrived, the timeline is usually tighter than you'd like and the gap is usually smaller than you fear. Start with a real assessment of where you actually stand.
How we build it
It starts with a risk assessment, and it never really stops. Every framework begins the same way: what data do you have, where does it live, what could happen to it. Ours is documented, ongoing, and it drives everything downstream. Every control we implement traces back to a specific risk. Every remediation is recorded against the finding that prompted it.
We can tell you what your exposure is worth. Not as a metaphor. We scan for sensitive data across your environment, find it in the places nobody remembered, and put a dollar figure on it — the actual liability if it walked out the door. That number usually ends the debate about whether this is worth doing.
Encryption that survives exfiltration. Devices are encrypted at rest. On top of that, files carrying sensitive data are individually encrypted, so if something is copied out of your environment, what leaves is unreadable.
Access is proven, not assumed. Multi-factor everywhere it can be enforced — your email tenant, desktop logins for anyone touching sensitive data, remote access, and the line-of-business applications themselves. For cloud systems, we go further and restrict access to your office network and our zero-trust gateway only. An attacker with valid stolen credentials still can't get in from anywhere else.
Monitored continuously, not annually. Endpoint detection and response with real people watching it. Your email tenant monitored for the login patterns that precede a breach. Dark web monitoring for your credentials appearing where they shouldn't. Phishing simulation and training, because your staff remain the most likely entry point. Continuous monitoring is also what satisfies the testing obligation in the Safeguards Rule — documented as such.
Your vendors are your problem too. Both frameworks make you responsible for the security of everyone you hand data to. We help put those agreements in place and keep track of who's holding what.
And all of it produces paper. Every one of those systems feeds a compliance platform that writes your policies from the frameworks that apply to you, then continuously collects the evidence that you're following them. That's the part that matters when someone asks. Not that you were secure — that you can prove it, on a specific date, with documentation.