Skip to content

Security & Compliance Engineering

Controls in code. Evidence on demand. No fire drill.

Compliance becomes expensive when it is treated as an annual documentation exercise performed by people who did not build the system. Treated as engineering, most controls are things you should be doing anyway (least privilege, encryption, logging, change management) and the evidence is a by-product of doing them properly rather than a scramble every audit cycle.

Evidence collection for recurring controls
AutomatedEvidence collection for recurring controls
Policy checks on every change
CI-gatedPolicy checks on every change
Incident runbooks, not shelfware
TestedIncident runbooks, not shelfware

Sounds like

You might recognise one of these.

  • A customer’s security questionnaire is holding up a seven-figure deal.

  • Our SOC 2 audit is in ninety days and we have no evidence.

  • We handle PHI and I’m not confident we’d survive a breach review.

  • A pen test came back and we don’t know what to fix first.

What this includes

The work, specifically.

Not every engagement needs all of it. This is the range we cover and what each part is actually for.

  • Readiness assessment

    Gap analysis against SOC 2 Trust Services Criteria, HIPAA Security Rule, PCI DSS 4.0, CMMC Level 2 or NIST 800-171, with each gap costed and sequenced rather than merely listed.

  • Controls as code

    Policy-as-code in the pipeline, enforced network and identity boundaries, automated configuration checks, and evidence collected continuously into an auditor-ready store.

  • Application security

    Threat modeling, secure code review, SAST/DAST and dependency scanning wired into CI with a triage process, plus secrets management and rotation that people actually follow.

  • Identity and access

    SSO and SCIM, role design that survives contact with an org chart, just-in-time privileged access, and access reviews that generate their own evidence.

  • Incident readiness

    Detection and response runbooks, tested tabletop exercises, breach notification workflows mapped to jurisdiction, and blameless postmortems that produce fixes rather than blame.

What you get

Deliverables, not documents.

  • Gap analysis mapped to the specific framework and control IDs
  • Remediation backlog sequenced by risk and audit deadline
  • Policy-as-code checks enforced in CI/CD
  • Automated evidence collection for recurring controls
  • Threat model and application security test results
  • Incident response runbooks with a completed tabletop exercise

Shapes

How this usually runs.

  1. Readiness assessment

    2–4 weeks

    Where you stand against the framework you need, what each gap costs to close, and what can be closed before your audit window.

  2. Remediation

    6–16 weeks

    Engineers closing the gaps, with evidence automation built alongside so the second audit costs a fraction of the first.

  3. Sustained assurance

    Ongoing

    Continuous control monitoring, questionnaire support and audit liaison during the observation window.

Tooling

What we build it with.

No tool here was picked because it was new. Where we do reach for something novel, it is in one place, for a stated reason, and it is written down.

Frameworks
  • SOC 2
  • HIPAA
  • PCI DSS 4.0
  • CMMC L2
  • NIST 800-171
  • ISO 27001
AppSec
  • Semgrep
  • CodeQL
  • Trivy
  • OWASP ASVS
  • Dependency review
Identity
  • Okta
  • Entra ID
  • SCIM
  • OIDC
  • SAML
Assurance
  • Vanta
  • Drata
  • OPA/Conftest
  • AWS Config
  • Cloud audit logs

Questions

Security & compliance, honestly.

  • No, that’s the auditor’s job, and it should be an independent one. We get you ready, build the evidence machinery and sit with you through fieldwork. We’ll recommend auditors we’ve worked with and have no financial relationship with any of them.

  • Before the deal that forces it. SOC 2 Type II requires an observation window of three to twelve months, so the constraint is usually calendar time rather than engineering effort.

  • We support CUI handling under NIST 800-171 and CMMC Level 2, and deploy into GovCloud boundaries. Classified work requires cleared personnel; tell us the requirement and we’ll be direct about whether we can meet it.

  • Yes, and we treat it as a live obligation rather than a signature. A business associate is directly liable under HIPAA and HITECH, not merely liable to the covered entity, so the practical work is upstream of the paperwork: breach reporting inside the window you need to meet your own sixty-day deadline, minimum-necessary access design, subcontractors bound to report in time for us to report to you, and PHI encrypted to the point where an incident is not a reportable breach at all.

  • With an exhibit written for your data rather than a reference to our then-current policy, which is a standard that can change without telling you. It covers encryption in transit and at rest, removable media, access control and logging, media sanitization to NIST SP 800-88, incident notification to you within 24 hours, and your sole control over the content and timing of any notification to your customers or regulators. Send your own requirements early and we’ll redline against them.

Next step

Tell us what’s breaking.

Forty-five minutes, no charge, no deck. We’ll tell you what we’d do, what it would likely cost, and whether you should be building this at all.