Framework Guides

The frameworks.

Decoded, not recited.

GDPR

When GDPR applies to US companies, what compliance actually requires — lawful bases, DPAs, data subject rights, transfers — and how it fits a security program.

HIPAA

What HIPAA actually requires — the Security Rule, risk analysis, BAAs, breach notification — and why no certification exists. A guide for teams handling PHI.

ISO 27001

What ISO 27001 certification requires — the ISMS, Statement of Applicability, Stage 1 and Stage 2 audits, timelines, costs, and how it relates to SOC 2.

MAS TRM

What the MAS Technology Risk Management guidelines require of licensed financial institutions in Singapore — governance, resilience, and audit expectations.

PCI DSS

How PCI DSS works — merchant levels, SAQ types, the cardholder data environment, and what version 4.0 changed. A guide for payment-handling companies.

SOC 2

What SOC 2 is, Type I vs Type II, what auditors actually check, realistic timelines and costs, and how to get audit-ready — with platform or with help.