Resources
The basics, explained.
A small, maintained knowledge hub. Definitions, comparisons and practical checklists.
- Guide
SOC 2 requirements, explained
What a SOC 2 examination actually requires: Trust Services Criteria, scope, controls, evidence and the difference between Type I and Type II.
- Comparison
SOC 2 vs ISO 27001
How SOC 2 and ISO 27001 differ in scope, assessment, output and audience — and where the same controls and evidence can be reused.
- Checklist
GDPR compliance checklist
A practical GDPR checklist for SaaS companies: processing records, lawful bases, rights handling, DPIAs, processors, security measures and breach readiness.
- Explainer
What is continuous compliance?
Continuous compliance means controls, evidence and risk information stay current between audits instead of being reconstructed before one.
- Guide
HIPAA for SaaS companies
When a SaaS company becomes a business associate, what the HIPAA Security Rule requires, and how to evidence safeguards for ePHI.