Security & Compliance Engineering
Controls in code. Evidence on demand. No fire drill.
Compliance becomes expensive when it is treated as an annual documentation exercise performed by people who did not build the system. Treated as engineering, most controls are things you should be doing anyway (least privilege, encryption, logging, change management) and the evidence is a by-product of doing them properly rather than a scramble every audit cycle.
- Evidence collection for recurring controls
- AutomatedEvidence collection for recurring controls
- Policy checks on every change
- CI-gatedPolicy checks on every change
- Incident runbooks, not shelfware
- TestedIncident runbooks, not shelfware
Sounds like
You might recognise one of these.
A customer’s security questionnaire is holding up a seven-figure deal.
Our SOC 2 audit is in ninety days and we have no evidence.
We handle PHI and I’m not confident we’d survive a breach review.
A pen test came back and we don’t know what to fix first.
What this includes
The work, specifically.
Not every engagement needs all of it. This is the range we cover and what each part is actually for.
Readiness assessment
Gap analysis against SOC 2 Trust Services Criteria, HIPAA Security Rule, PCI DSS 4.0, CMMC Level 2 or NIST 800-171, with each gap costed and sequenced rather than merely listed.
Controls as code
Policy-as-code in the pipeline, enforced network and identity boundaries, automated configuration checks, and evidence collected continuously into an auditor-ready store.
Application security
Threat modeling, secure code review, SAST/DAST and dependency scanning wired into CI with a triage process, plus secrets management and rotation that people actually follow.
Identity and access
SSO and SCIM, role design that survives contact with an org chart, just-in-time privileged access, and access reviews that generate their own evidence.
Incident readiness
Detection and response runbooks, tested tabletop exercises, breach notification workflows mapped to jurisdiction, and blameless postmortems that produce fixes rather than blame.
What you get
Deliverables, not documents.
- Gap analysis mapped to the specific framework and control IDs
- Remediation backlog sequenced by risk and audit deadline
- Policy-as-code checks enforced in CI/CD
- Automated evidence collection for recurring controls
- Threat model and application security test results
- Incident response runbooks with a completed tabletop exercise
Shapes
How this usually runs.
Readiness assessment
2–4 weeksWhere you stand against the framework you need, what each gap costs to close, and what can be closed before your audit window.
Remediation
6–16 weeksEngineers closing the gaps, with evidence automation built alongside so the second audit costs a fraction of the first.
Sustained assurance
OngoingContinuous control monitoring, questionnaire support and audit liaison during the observation window.
Tooling
What we build it with.
No tool here was picked because it was new. Where we do reach for something novel, it is in one place, for a stated reason, and it is written down.
- Frameworks
- AppSec
- Identity
- Assurance
Questions
Security & compliance, honestly.
No, that’s the auditor’s job, and it should be an independent one. We get you ready, build the evidence machinery and sit with you through fieldwork. We’ll recommend auditors we’ve worked with and have no financial relationship with any of them.
Before the deal that forces it. SOC 2 Type II requires an observation window of three to twelve months, so the constraint is usually calendar time rather than engineering effort.
We support CUI handling under NIST 800-171 and CMMC Level 2, and deploy into GovCloud boundaries. Classified work requires cleared personnel; tell us the requirement and we’ll be direct about whether we can meet it.
Yes, and we treat it as a live obligation rather than a signature. A business associate is directly liable under HIPAA and HITECH, not merely liable to the covered entity, so the practical work is upstream of the paperwork: breach reporting inside the window you need to meet your own sixty-day deadline, minimum-necessary access design, subcontractors bound to report in time for us to report to you, and PHI encrypted to the point where an incident is not a reportable breach at all.
With an exhibit written for your data rather than a reference to our then-current policy, which is a standard that can change without telling you. It covers encryption in transit and at rest, removable media, access control and logging, media sanitization to NIST SP 800-88, incident notification to you within 24 hours, and your sole control over the content and timing of any notification to your customers or regulators. Send your own requirements early and we’ll redline against them.
Further reading
What we think about this, at length.
- Security8 min read
In vulnerability research, most of the work is ruling things out
We hunt on public disclosure programs between engagements. The part that transfers to paid work is not the findings. It is the machinery for discarding the forty candidates that looked exactly like them.
- Security5 min read
TX-RAMP § 6.2: the exemption a custom build may already have
A Texas university asks for your TX-RAMP certification and the project stops for a quarter. For software the institution commissioned, the program manual says certification does not apply — and then attaches four conditions that decide whether you actually get it.
- Engineering5 min read
Whether you can investigate a breach was decided months ago
The questions asked after an incident are answerable only if somebody made specific, unglamorous logging decisions long before it happened. Almost nobody does.
Sources
- 1.45 CFR Part 164 Subpart C: Security Standards for the Protection of Electronic Protected Health Information, Electronic Code of Federal Regulations
- 2.SP 800-171 Rev. 3: Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, NIST
- 3.32 CFR Part 170: Cybersecurity Maturity Model Certification (CMMC) Program, Electronic Code of Federal Regulations
- 4.OWASP Top 10:2025, OWASP Foundation
Next step
Tell us what’s breaking.
Forty-five minutes, no charge, no deck. We’ll tell you what we’d do, what it would likely cost, and whether you should be building this at all.