Honest framing: read this first
We design and deliver compliance-ready architecture. Systems we build are engineered to the technical requirements of SOC 2, HIPAA, GDPR, and PCI DSS: encryption, access control, audit logging, breach procedures, and data minimisation by default.
We do not currently hold active SOC 2, ISO 27001, or HIPAA "certifications" of our own corporate environment. SOC 2 Type 1 is in progress with an auditor, target Q4 2026; ISO 27001 is on the roadmap for 2027. HIPAA is not a certification anyone can hold: there is only the Security Rule and a signed Business Associate Agreement (BAA), both of which we operate under when handling PHI.
We sign BAAs and DPAs. Where required: a Business Associate Agreement (HIPAA), a Data Processing Agreement (GDPR / UK GDPR / DPDP / PDPL), and client-specific addenda. Our standard DPA template is downloadable.
If procurement asks "are you certified?", the honest answer is: not yet for SOC 2, targeting 2026. If that is a deal-breaker, tell us early.