Regulated environments

Experience you can audit.

Healthcare, payments, financial services, privacy regimes: a decade of delivering to the frameworks that govern them. What follows is the evidence — case studies you can read, and practices you can inspect — not adjectives.

Hard evidence

The record, engagement by engagement.

Every line below cites the framework the engagement was delivered to or under, and links to a published case study. Where the client is anonymized, it’s because the engagement shipped under NDA — the work is real either way.

Delivering in regulated environments

When the rules are non-negotiable, that’s our comfort zone.

The frameworks we design and deliver to — not certifications we hold.

  • HIPAAHealth Insurance Portability and Accountability ActFederal safeguards for protected health information (PHI).
  • HITRUST CSFHITRUST Common Security FrameworkCertifiable framework harmonizing healthcare security and privacy controls.
  • SOC 2 Type IIService Organization Control 2Audited operating effectiveness of security controls over time.
  • ISO/IEC 27001Information Security ManagementInternational standard for an information security management system.
  • ISO/IEC 27701Privacy Information ManagementPrivacy extension to 27001 for managing personal data (PII).
  • GDPRGeneral Data Protection RegulationEU framework governing personal-data collection, processing, and transfer.
  • CCPA / CPRACalifornia Consumer Privacy ActCalifornia rights over collection, use, and sale of personal data.
  • COPPAChildren's Online Privacy Protection ActU.S. protections for the online privacy of children under 13.
  • PCI DSSPayment Card Industry Data Security StandardControls for securely handling and storing payment-card data.
  • NIST PF 2.0NIST Privacy FrameworkRisk-based model for identifying and managing privacy risk.
  • NIST CSF 2.0NIST Cybersecurity FrameworkGovern–identify–protect–detect–respond–recover risk management.
  • CIS v8CIS Critical Security Controls v8Prioritized safeguards for modern cloud and hybrid environments.

…and the rest of the alphabet soup. Tell us your regime — we’ll meet it.

Operating posture

Process that stands up to diligence.

Compliance fails in the gaps between intentions and habits. These are the habits — and this site is built under the same rules, so run Lighthouse on it.

  • Decisions on the record

    Significant architecture decisions are written down as decision records when they’re made — so a reviewer can read why the system is the way it is instead of reverse-engineering it.

  • Infrastructure as code

    The config plane lives in version-controlled Terraform: reviewable, repeatable, and diffable. No console drift, no tribal knowledge standing in for an audit trail.

  • A gated path to production

    Protected mainline; every change passes type checks, lint, unit and end-to-end tests, and performance budgets before it ships. A red build is a stop-the-line event.

  • Privacy and minimum necessary by default

    Privacy-first analytics with no cookie banner, PII collected minimally and retained deliberately, secrets kept out of source control, least-privilege access.

  • Accessibility as a floor

    WCAG 2.2 AA is a non-negotiable on everything we ship — semantics, keyboard, focus, contrast — not a remediation project after launch.

  • Your perimeter, your tools

    We work inside your cloud accounts, your repositories, your access controls, and your work OS — so nothing about the engagement weakens the boundary you answer for.

For the procurement file

Three things we’d rather say now than in the review.

We deliver to your framework. We are not your auditor.

We design and engineer to the controls and produce the artifacts an assessor asks for — architecture and data-flow diagrams, decision records, audit logging, runbooks. Certification of your organization stays with your auditor, where it belongs.

Confidentiality is the norm here.

Most regulated engagements ship under NDA — it’s why several of the case studies above are anonymized. We’ll share what we can, and tell you plainly what we can’t.

Bring the questionnaire.

Security questionnaires, vendor reviews, and procurement diligence are an expected part of working with us — answered directly by the senior people who do the work, not a proposals team.

Have a framework to meet?

Tell us the standard and the deadline. We reply within one business day.

Start a project