Skip to content
Compliance

Build it so the answer is evidenced.

Most revenue systems are built for speed and audited later. We build them the other way round: the boundary drawn first, permissions modelled per role, retention and consent written into the schema. We hold SOC 2, monitor our own controls in Vanta, and implement Vanta and Drata for the clients we build for.

HIPAA-aware architecturePermissionsRetentionEvidence
The problem

Compliance arrives as a questionnaire.

A deal reaches security review and someone is asked where the data lives, who can see it and how long it is kept. The policy says one thing. The CRM, the forms, the spreadsheets and the six connected tools say something else. The gap between them is where the deal stalls.

Evidence, not screenshots.

What we do

What we build into the system.

The PHI and PII boundary

We decide what is never allowed into the CRM at all — clinical detail, diagnoses, documents — and hold it behind a system with a BAA, referenced by an identifier instead of copied. The marketing stack then works on data it is allowed to hold.

Least privilege, modelled per role

Permissions built from what a role actually needs to do the job, rather than cloned from whoever was hired first. Every field carrying sensitive data has a named set of people who can read it, and a reason.

Retention, deletion and the audit trail

A record has a defined life: how long it is kept, what triggers deletion, and where the deletion is logged. The audit trail is a property of the system, not a report someone assembles afterwards.

Consent captured, not reconstructed

Lawful basis and consent recorded at the point of collection, on the form, with the source and the timestamp attached to the record. Reconstructing why you were allowed to email someone two years later is guesswork, and it reads as guesswork under review.

Subprocessors and integrations reviewed

Every tool wired into the stack is one more place the data goes. We map what each integration reads and writes, what agreement covers it, and cut the ones that pull sensitive fields for no operational reason.

Evidence collected continuously

Controls monitored in Vanta or Drata and wired to the systems they cover, so evidence accrues as the business runs. Screenshotting settings the week before an audit produces a snapshot, not a control.

How it runs

Follow, bound, build, evidence.

01

Follow the data

Every field, form, integration and export that touches regulated or personal data, with the person who owns it and the tool it flows into next.

02

Set the boundary

A written line between what the revenue stack may hold and what it may only point at, agreed with whoever carries the risk before anything is built.

03

Build the controls in

Permissions, retention, consent fields and logging shipped as part of the system, so a control is something the software does rather than something a person remembers.

04

Evidence it continuously

Monitoring connected, owners assigned, and the questionnaire answered from the system itself. Where an answer needs counsel, the system makes the facts unambiguous — your lawyers still make the call.

Where it usually breaks

The policy passes. The export does not.

A security questionnaire asks concrete things: where the data sits, which subprocessors touch it, who has admin, how long records live, how deletion is proved. Those answers live in configuration, not in a document — and the answer that fails review is almost always a spreadsheet someone exported to work faster.

Operators we build with
ThalesImpervaCameoMozAPMEXRaySecurBolsterHuifyRegency Health CareNiche Academy
Start a project

Tell us which question your stack cannot answer.

Tell us what you are running

What the system does today, where it breaks, and when it has to work. An engineer reads it — you get an answer inside one business day, not a sequence.

Book a call