
Compliance, documented honestly
Our posture across HIPAA, PCI DSS, GDPR, SOC 2, and ISO 27001, stated plainly. Compliant builds, baked into architecture from week one.
The same posture we state in proposals and contracts. Nothing on this page claims a certificate we do not hold.
- SOC 2 aligned
- HIPAA-aware
- GDPR
Control evidence
Where we stand
The five standards our clients ask about most, with the status we can actually defend.
| Standard | Status | What we ship |
|---|---|---|
| HIPAA | Compliant | Shipped HIPAA-architected AI healthcare apps. Compliance baked into architecture from week one. BAA available. |
| PCI DSS | Compliant | Tokenization-first, no card storage. PCI Level 1 processor integrations only. |
| GDPR / UK GDPR | Compliant | Data handling architected for compliance. DSAR support built in. |
| SOC 2 Type II | Not yet | Planned. Target late 2026 / early 2027. |
| ISO 27001 | Not yet | We build to the standard today; no certificate held. |
Why publish this
Why we document this publicly
- Buyers respect agencies that document their compliance stance, not just claim it. We publish where we stand, including where we are not yet.
- We say "compliant builds", never "certified", unless we hold a certification. HIPAA is a regulation, not a certificate; SOC 2 and ISO 27001 are certifications we are still working toward.
- Compliance is architected from week one, not bolted on after an audit. The status above reflects how we actually ship, not aspiration.

Built into the architecture, not bolted on after
Standard by standard
Explore each standard
What each framework covers, what we ship against it, and where the boundaries of our role sit.
HIPAA
HIPAA-compliant software development for AI healthtech. Privacy Rule, Security Rule, HITECH, and a signed BAA.
Read morePCI DSS
Tokenization-first payment architecture. No card data at rest, PCI Level 1 processor integrations only.
Read moreGDPR / UK GDPR
Data-protection-by-design. Lawful basis, data minimisation, and DSAR tooling engineered in from the start.
Read moreSOC 2 Type II
Planned. We build to SOC 2 trust-service-criteria patterns today; formal Type II report targeted late 2026 / early 2027.
Read moreISO 27001
ISO 27001-aligned engineering. Annex A controls mapped into architecture, with evidence-ready audit trails from day one.
Read moreBuilding something where compliance is non-negotiable?
Schedule a meeting about how we architect for your regulatory requirements from day one.