- Can you make my app HIPAA or SOC 2 compliant?
- No one can make software compliant on your behalf. Compliance is an organizational and legal state that depends on your policies, contracts, and an auditor's or regulator's judgment. What we do is build the technical controls a framework expects — access, encryption, logging, retention — and prepare the evidence so your path to readiness is shorter. Certification is a decision for your auditor and counsel.
- What is the shared-responsibility split?
- We are responsible for the security properties of the code and architecture we build — how data is accessed, encrypted, logged, and retained. You remain responsible for your policies, your contracts (including any BAAs or processor agreements), staff training, and the legal determination of which frameworks apply. We document the line clearly so nothing falls through it.
- Do you sign an NDA before seeing our system?
- Yes. We work under an NDA before reviewing your app, data model, or export, and we treat access as read-only unless a task explicitly requires more.
- What evidence do we get out of the build?
- Architecture and data-flow documentation, an access model, an encryption and secrets summary, a logging and retention description, and the results of the security testing performed. This is technical evidence that supports an audit; it is not an audit report or a certificate, and we do not present it as one.
- Do you provide legal advice on which regulations apply?
- No. Which frameworks apply to your business, and whether you meet them, are legal questions for your counsel and auditor. We build and document the technical side so those conversations start from a stronger position.