Built for the
compliance file.
Procurement, security, and audit teams are first-class citizens of every engagement. This is the documentation surface that shows up during diligence.
Standards we operate against.
SOC 2 Type II
In progressAudited annually since 2021. Continuous monitoring.
ISO 27001 / 27701
In progressInformation security and privacy management systems.
HIPAA & HITRUST
In progressBAA-ready. Production deployments since 2019.
GDPR & CCPA
In progressData-residency options across US, EU, UK.
FedRAMP-aligned
In progressReference architectures for moderate workloads.
PCI-DSS Level 1
In progressTokenization, vaulting and audit trail patterns.
How an engagement is run.
Architecture Review Board
Every engagement opens with a written architectural decision record. You keep the document.
Master Services Agreement
Standard MSA with named-team continuity, IP ownership, and exit clauses written in plain English.
Engagement insurance
$5M E&O · $5M Cyber · $2M General. Certificates on request.
Quarterly business review
SLO performance, spend vs. plan, risk register. Reviewed with your CFO and CTO.
The infrastructure of trust.
SSO via SAML/OIDC. Hardware-backed second factor required for production. Quarterly access reviews, evidenced.
Tenant isolation by default. Encryption at rest (AES-256) and in transit (TLS 1.3). Data residency options across US, EU, UK.
Continuous SCA + SAST + DAST. Annual penetration tests by an independent firm. Patch SLAs aligned to CVSS.
24/7 on-call. Defined severity matrix. Customer notification within 24 hours of confirmed material incident.
Subprocessors reviewed quarterly. Public list maintained. SCCs and DPAs available.
RTO 4 h, RPO 15 min for managed-platform engagements. Quarterly DR exercises.