Compliance, documented honestly

Our posture across HIPAA, PCI DSS, GDPR, SOC 2, and ISO 27001, stated plainly. Compliant builds, baked into architecture from week one.

The same posture we state in proposals and contracts. Nothing on this page claims a certificate we do not hold.

  • SOC 2 aligned
  • HIPAA-aware
  • GDPR

Control evidence

Where we stand

The five standards our clients ask about most, with the status we can actually defend.

Our compliance status across the five standards our clients ask about most.
StandardStatusWhat we ship
HIPAACompliantShipped HIPAA-architected AI healthcare apps. Compliance baked into architecture from week one. BAA available.
PCI DSSCompliantTokenization-first, no card storage. PCI Level 1 processor integrations only.
GDPR / UK GDPRCompliantData handling architected for compliance. DSAR support built in.
SOC 2 Type IINot yetPlanned. Target late 2026 / early 2027.
ISO 27001Not yetWe build to the standard today; no certificate held.

Why publish this

Why we document this publicly

  • Buyers respect agencies that document their compliance stance, not just claim it. We publish where we stand, including where we are not yet.
  • We say "compliant builds", never "certified", unless we hold a certification. HIPAA is a regulation, not a certificate; SOC 2 and ISO 27001 are certifications we are still working toward.
  • Compliance is architected from week one, not bolted on after an audit. The status above reflects how we actually ship, not aspiration.
Code on screen

Built into the architecture, not bolted on after

Building something where compliance is non-negotiable?

Schedule a meeting about how we architect for your regulatory requirements from day one.