Standards we build toward
Most companies do not buy security because they are afraid. They buy it because an auditor, a customer or an insurer requires it. These are the frameworks we work against.
HIPAA
For any organization handling protected health information. We work on the technical safeguards: access control, audit controls, integrity, transmission security and encrypted backup.
PCI DSS
For anyone who accepts card payments. Network segmentation of the cardholder data environment, firewalling, logging and vulnerability management.
SOC 2 readiness
The report your enterprise customers ask for. We prepare the technical controls behind the Security, Availability and Confidentiality criteria so your audit does not start from zero.
CMMC
For suppliers to the United States Department of Defense. We map the practices that fall on infrastructure and help close the gaps before your assessment.
NIST CSF and NIST 800-171
The framework most United States auditors speak. We use it as the backbone of every security project, whether or not it is formally required of you.
CCPA and CPRA
California privacy obligations that reach any company doing business with California residents: data inventory, retention limits, deletion capability and breach readiness.
LFPDPPP (Mexico)
For your operation south of the border: privacy notices, ARCO rights and the security measures Mexican law requires of data controllers.
GLBA Safeguards Rule
For financial institutions and anyone providing them services: written security program, access controls, encryption and incident response.
CIS Controls
The practical checklist we run first. It is not a certification, it is the fastest way to find what is actually exposed.
How we approach a compliance project
1. Gap assessment
We compare your current environment against the framework that applies to you and produce a written list of gaps, ranked by risk.
2. Remediation plan
A plan with owners, cost and timeline. You decide what we execute and what your internal team handles.
3. Implementation
We deploy and document the technical controls: segmentation, access, logging, encryption, backup and monitoring.
4. Evidence and maintenance
We keep the evidence your auditor will request and re-test the controls on the cycle you need.
An audit coming up?
Send us the framework and the deadline. We will tell you what is realistic before you commit to a date.