Compliance, explained without the fog
Practical guides on SOC 2, ISO 27001, ISO 42001, HIPAA and GDPR from the team that runs these programmes for a living.
AI Governance 3
How to build an AI system inventory that survives an audit
Every AI governance framework starts with an inventory. Here is how to build one that is complete, current and defensible.
Read article →NIST AI Risk Management Framework, explained
NIST AI RMF is a voluntary framework built on four functions. Here is how each works and how it fits alongside ISO 42001.
Read article →The EU AI Act, explained for product and engineering teams
The EU AI Act classifies AI systems by risk and attaches obligations to each tier. Here is what it means for your roadmap.
Read article →Comparisons 4
Compliance automation pricing compared: Vanta, Drata, Secureframe and Certifyi
None of the major platforms publish list pricing. Here are the market ranges, the hidden fees, and how the cost models differ.
Read article →The best ISO 27001 compliance software in 2026
ISO 27001 demands governance artefacts SOC 2 does not. Here is which platforms handle an ISMS properly.
Read article →The best SOC 2 compliance software in 2026
An honest comparison of SOC 2 platforms including Vanta, Drata, Secureframe, Sprinto, Scrut and Certifyi, with where each genuinely wins.
Read article →The hidden costs of compliance platforms nobody quotes you
The subscription is the number you are quoted. Here are the six costs that appear later and how to surface them during evaluation.
Read article →Compliance 1
GDPR 2
GDPR data subject requests: a workflow that actually works
DSARs have a one-month clock. Here is a workflow that meets the deadline without derailing your engineering team.
Read article →GDPR for SaaS: lawful basis and data mapping done properly
Most GDPR programmes fail at the first two steps. Here is how to map data and choose a lawful basis you can defend.
Read article →GRC 5
Automated vs manual evidence collection: what auditors accept
Auditors accept both, but they are not equal in cost or reliability. Here is where each works and where manual evidence fails.
Read article →Do you need a compliance hire or a compliance platform?
A platform without an owner stalls. A hire without tooling drowns. Here is how to decide which you need first, honestly.
Read article →How to prepare for an auditor evidence request
Fieldwork goes badly when evidence is assembled reactively. Here is how to prepare so the request list is routine.
Read article →How to write security policies people actually follow
Template policies pass a document check and fail in practice. Here is how to write a policy set that survives an audit and real use.
Read article →What is GRC, and when does a startup actually need it?
GRC covers governance, risk and compliance as one discipline. Here is what it means practically and when it stops being premature.
Read article →HIPAA 2
HIPAA compliance for health-tech startups: what actually matters
HIPAA has no certification. Here is what the safeguards require, when you need a BAA, and how to build a defensible position.
Read article →What is a Business Associate Agreement (BAA)?
A BAA is the contract HIPAA requires before a vendor touches PHI. Here is what it must contain and who needs one.
Read article →ISO 27001 4
ISO 27001 Stage 1 vs Stage 2 audit: what to expect
Stage 1 reviews your documentation, Stage 2 tests whether the ISMS operates. Here is what auditors check at each.
Read article →ISO 27001 vs SOC 2: which should you do first?
The honest answer depends on where your buyers are. Here is how to choose, and how to avoid paying twice when you eventually need both.
Read article →The ISO 27001 Statement of Applicability, explained
The SoA is the document auditors scrutinise hardest. Here is what it must contain, how to justify exclusions, and the mistakes that fail Stage 1.
Read article →What is ISO 27001 certification and who actually needs it?
ISO 27001 certifies your information security management system. Here is what an ISMS is, how certification works, and when it beats SOC 2.
Read article →ISO 42001 1
SOC 2 6
How long does SOC 2 actually take?
Type 1 in one to three months, Type 2 adds the observation window. Here is what drives the timeline and what compresses it.
Read article →How much does SOC 2 cost in 2026? A full breakdown
SOC 2 costs more than the platform fee. Here is the real budget: software, auditor, pen test, remediation and internal time, with 2026 ranges.
Read article →SOC 2 for SaaS startups: getting your first report without derailing the roadmap
Your first SOC 2 competes with product work for engineering time. Here is how to scope and sequence it to minimise that.
Read article →SOC 2 Trust Service Criteria explained (and which to include)
Security, Availability, Confidentiality, Processing Integrity and Privacy. What each criterion covers and how to decide which belong in your scope.
Read article →SOC 2 Type 1 vs Type 2: which one do you actually need?
Type 1 proves controls are designed well at a point in time. Type 2 proves they operated over months. Here is how to choose without wasting an audit cycle.
Read article →What is SOC 2 compliance? A plain-English guide for founders
SOC 2 is an attestation report proving you handle customer data securely. Here is what it covers, who needs it, and what it takes to pass.
Read article →Security 2
How to handle security questionnaires without stalling deals
Security review is often the longest step in enterprise sales. Here is how to compress it from weeks to days.
Read article →How to run access reviews auditors will accept
Access reviews are a top audit finding because they are performed but not evidenced. Here is how to run one that holds up.
Read article →TPRM 1
Stop reading, start shipping the report
Certifyi gets you audit-ready in 8 to 12 weeks with a named compliance lead, from $8,000/year.
Book a 20-min deal readiness call