Guides

The details.

What the frameworks pages skip.

HIPAA

How HIPAA programs fail — The six HIPAA failure patterns in startups — stale risk analyses, missing sub-BAAs, PHI sprawl — and how each one surfaces in deals and incidents.

HIPAA for startups — A startup-sized HIPAA program — business associate reality, the minimum defensible posture, and the mistakes that surface in health-system procurement.

HIPAA vs SOC 2 — HIPAA is a law; SOC 2 is an attestation. Health-tech needs both — here's what overlaps, what doesn't, and how to build one program that satisfies each.

What HIPAA costs — What HIPAA compliance costs a health-tech startup — risk analysis, safeguards, BAAs, and training — and why 'no certificate' doesn't mean 'no budget.'

General

The pricing teardown — What Vanta, Drata, Sprinto, Secureframe, and Scrut actually cost — entry bands, the multipliers that inflate quotes, and the questions that keep pricing honest.

Drata pricing, decoded — Drata pricing decoded — reported bands, how frameworks and seats move the quote, and the configuration labor the subscription price doesn't show.

Scrut pricing, decoded — Scrut Automation pricing decoded — the aggressive value bands, what the discount trades away, and why the smallest subscription makes labor the whole story.

Secureframe pricing, decoded — Secureframe pricing decoded — mid-market bands, how bundled support changes the effective cost, and the coaching-vs-implementation line to price carefully.

Sprinto pricing, decoded — Sprinto pricing decoded — the value-tier bands, what the lower price includes and omits, and when the savings are real versus rearranged.

Vanta pricing, decoded — Vanta pricing decoded — reported entry bands, the multipliers that inflate quotes, renewal behavior, and the questions that keep your quote honest.

MAS TRM

The fintech compliance stack — Which compliance frameworks a fintech needs at each stage — SOC 2 for deals, ISO for global sales, PCI for cards, MAS TRM for the license — in one map.

MAS outsourcing guidelines — What MAS expects when a licensee outsources — due diligence, audit rights, exit plans, and cloud specifics — translated from guideline to operating checklist.

MAS TRM vs ISO 27001 — How MAS TRM differs from ISO 27001 — regulator vs certifier, recovery expectations, outsourcing oversight, and incident clocks — for Singapore fintechs.

SOC 2

Choosing a SOC 2 auditor — What actually matters in a SOC 2 auditor: firm recognition, sampling style, timeline reliability, and price — plus the questions to ask before engaging.

What SOC 2 actually costs — SOC 2 cost breakdown: audit fees, platform subscriptions, pen tests, and the labor nobody budgets for — with realistic ranges and where teams overspend.

SOC 2 for startups — A startup-sized SOC 2 strategy — when to start, what to skip, what not to skip, and how to get a first Type II without hiring a compliance team.

The SOC 2 evidence list — The evidence a SOC 2 Type II auditor requests — by control area, with what 'good' looks like and which items automation can and can't produce.

How SOC 2 programs fail — The seven failure modes that stall SOC 2 programs — from unowned platforms to aspirational policies — and what the rescue looks like for each.

The SOC 2 policy set — The complete SOC 2 policy list — what each policy must cover, who approves it, and why template packs fail audits when nobody tailors them.

The SOC 2 timeline — A realistic SOC 2 timeline from kickoff to report in hand — readiness, observation window, fieldwork, and the three places programs lose whole quarters.

SOC 2 vs ISO 27001 — SOC 2 vs ISO 27001 compared on buyer expectations, cost, timeline, and structure — with the decision rule by market, and when to run both on one control set.

ISO 27001

What ISO 27001 costs — What ISO 27001 really costs — certification body fees, platform, internal audit, and the ISMS labor — with the surveillance-year costs quotes leave out.

Choosing a certification body — What matters in a certification body: accreditation, auditor fit, scheduling, and three-year cost — plus the accreditation check that takes two minutes.

ISO 27001 for startups — How a startup gets ISO 27001 certified without enterprise bureaucracy — scope discipline, a lean ISMS, and the clauses you can't shortcut.

The ISO 27001 timeline — How long ISO 27001 really takes — ISMS build, operating evidence, internal audit, Stage 1 and Stage 2 — and the clause that quietly sets your minimum.