§ IV — TRUSTAUDIT · READY

Built for the
compliance file.

Procurement, security, and audit teams are first-class citizens of every engagement. This is the documentation surface that shows up during diligence.

FRAMEWORKS
06
§ I — COMPLIANCE

Standards we operate against.

SOC 2 Type II

In progress

Audited annually since 2021. Continuous monitoring.

ISO 27001 / 27701

In progress

Information security and privacy management systems.

HIPAA & HITRUST

In progress

BAA-ready. Production deployments since 2019.

GDPR & CCPA

In progress

Data-residency options across US, EU, UK.

FedRAMP-aligned

In progress

Reference architectures for moderate workloads.

PCI-DSS Level 1

In progress

Tokenization, vaulting and audit trail patterns.

§ II — GOVERNANCE

How an engagement is run.

Architecture Review Board

Every engagement opens with a written architectural decision record. You keep the document.

Master Services Agreement

Standard MSA with named-team continuity, IP ownership, and exit clauses written in plain English.

Engagement insurance

$5M E&O · $5M Cyber · $2M General. Certificates on request.

Quarterly business review

SLO performance, spend vs. plan, risk register. Reviewed with your CFO and CTO.

§ III — SECURITY POSTURE

The infrastructure of trust.

Identity & access

SSO via SAML/OIDC. Hardware-backed second factor required for production. Quarterly access reviews, evidenced.

Data handling

Tenant isolation by default. Encryption at rest (AES-256) and in transit (TLS 1.3). Data residency options across US, EU, UK.

Vulnerability mgmt

Continuous SCA + SAST + DAST. Annual penetration tests by an independent firm. Patch SLAs aligned to CVSS.

Incident response

24/7 on-call. Defined severity matrix. Customer notification within 24 hours of confirmed material incident.

Vendor management

Subprocessors reviewed quarterly. Public list maintained. SCCs and DPAs available.

Business continuity

RTO 4 h, RPO 15 min for managed-platform engagements. Quarterly DR exercises.

§ IV — DOCUMENTATION

The diligence packet.

DOC 01
SOC 2 Type II report
↓ REQUEST ACCESS
DOC 02
ISO 27001 certificate
↓ REQUEST ACCESS
DOC 03
Pen-test executive summary
↓ REQUEST ACCESS
DOC 04
Subprocessor list
↓ REQUEST ACCESS
DOC 05
DPA template
↓ REQUEST ACCESS
DOC 06
Insurance certificates
↓ REQUEST ACCESS
DOC 07
MSA template
↓ REQUEST ACCESS
DOC 08
Architecture sample letter
↓ REQUEST ACCESS
Season