Build it so the answer is evidenced.
Most revenue systems are built for speed and audited later. We build them the other way round: the boundary drawn first, permissions modelled per role, retention and consent written into the schema. We hold SOC 2, monitor our own controls in Vanta, and implement Vanta and Drata for the clients we build for.
Compliance arrives as a questionnaire.
A deal reaches security review and someone is asked where the data lives, who can see it and how long it is kept. The policy says one thing. The CRM, the forms, the spreadsheets and the six connected tools say something else. The gap between them is where the deal stalls.
Evidence, not screenshots.
ComplianceWhat we build into the system.
The PHI and PII boundary
We decide what is never allowed into the CRM at all — clinical detail, diagnoses, documents — and hold it behind a system with a BAA, referenced by an identifier instead of copied. The marketing stack then works on data it is allowed to hold.
Least privilege, modelled per role
Permissions built from what a role actually needs to do the job, rather than cloned from whoever was hired first. Every field carrying sensitive data has a named set of people who can read it, and a reason.
Retention, deletion and the audit trail
A record has a defined life: how long it is kept, what triggers deletion, and where the deletion is logged. The audit trail is a property of the system, not a report someone assembles afterwards.
Consent captured, not reconstructed
Lawful basis and consent recorded at the point of collection, on the form, with the source and the timestamp attached to the record. Reconstructing why you were allowed to email someone two years later is guesswork, and it reads as guesswork under review.
Subprocessors and integrations reviewed
Every tool wired into the stack is one more place the data goes. We map what each integration reads and writes, what agreement covers it, and cut the ones that pull sensitive fields for no operational reason.
Evidence collected continuously
Controls monitored in Vanta or Drata and wired to the systems they cover, so evidence accrues as the business runs. Screenshotting settings the week before an audit produces a snapshot, not a control.
Follow, bound, build, evidence.
Follow the data
Every field, form, integration and export that touches regulated or personal data, with the person who owns it and the tool it flows into next.
Set the boundary
A written line between what the revenue stack may hold and what it may only point at, agreed with whoever carries the risk before anything is built.
Build the controls in
Permissions, retention, consent fields and logging shipped as part of the system, so a control is something the software does rather than something a person remembers.
Evidence it continuously
Monitoring connected, owners assigned, and the questionnaire answered from the system itself. Where an answer needs counsel, the system makes the facts unambiguous — your lawyers still make the call.
The policy passes. The export does not.
A security questionnaire asks concrete things: where the data sits, which subprocessors touch it, who has admin, how long records live, how deletion is proved. Those answers live in configuration, not in a document — and the answer that fails review is almost always a spreadsheet someone exported to work faster.










Tell us which question your stack cannot answer.
Tell us what you are running
What the system does today, where it breaks, and when it has to work. An engineer reads it — you get an answer inside one business day, not a sequence.