Honest framing — read this first
Most agency websites list compliance frameworks as if they were trophies. We will not do that. Here is the plain-English position:
We design and deliver compliance-ready architecture. The systems we build for clients are engineered to meet the technical requirements of SOC 2, HIPAA, GDPR, and PCI DSS. Encryption, access control, audit logging, breach procedures, and data minimisation are baked in by default.
We do not currently hold active SOC 2, ISO 27001, or HIPAA "certifications" of our own corporate environment. SOC 2 Type 1 is in active progress, engaged with an auditor, target completion Q4 2026. ISO 27001 is on the roadmap for 2027. HIPAA is not a certification anyone can hold — there is only the Security Rule and a signed Business Associate Agreement (BAA), both of which we operate under when handling PHI on a client's behalf.
We sign BAAs and DPAs. Where the engagement requires it, we sign a Business Associate Agreement (HIPAA), a Data Processing Agreement (GDPR / UK GDPR / DPDP / PDPL), and any client-specific addenda. Our standard DPA template is downloadable.
If your procurement team needs a clean answer to "are you certified?", the honest answer is "not yet for SOC 2, working on it for 2026, here is what we deliver in the meantime." If that is a deal-breaker, please tell us early so we do not waste your team's time.