Resources
Compliance guides without the fog.
Written for technical founders and operators who are smart but not compliance specialists. Sourced, dated, and reviewed.
Lead resource
The HIPAA + SOC 2 startup checklist
The full combined readiness checklist — every workstream, in order, with owner suggestions — plus the phase-by-phase sample project plan.
HIPAA + SOC 2
HIPAA vs SOC 2: what each one is, and why healthcare vendors usually need both
HIPAA is a law; SOC 2 is an attestation framework. This guide explains what each covers, who asks for them, and how the work overlaps.
Last reviewed 2026-09-01
HIPAA + SOC 2
HIPAA and SOC 2 for healthcare SaaS: what you actually need
A practical map for healthcare SaaS founders: your obligations as a business associate, what enterprise buyers will demand, and the shortest honest path through both.
Last reviewed 2026-09-01
SOC 2
SOC 2 Type 1 vs Type 2: cost, evidence, and timeline
Design versus operation, point-in-time versus period — and how to choose a path that unblocks deals now without painting yourself into a corner.
Last reviewed 2026-09-01
HIPAA
How to perform and document a HIPAA security risk analysis
The risk analysis is the foundation of the Security Rule — and the most common gap in enforcement. Here's a defensible method, step by step.
Last reviewed 2026-09-01
HIPAA
What a healthcare AI vendor should ask every subprocessor
Your compliance story is only as strong as the model providers, GPU clouds, and tools underneath it. The questions to ask — and the answers that should worry you.
Last reviewed 2026-09-01
Reading only gets you so far.
Contact us and get a scope, timeline, and budget range specific to your company.