Security and compliance, in plain English.

Compliance, decoded for the people who ship it.

Plain-English guides to SOC 2, ISO 27001, vendor risk, and the tools that get you compliant without the consultant markup. Written by practitioners, for the people who actually have to ship it.

Vendor RiskAugust 5, 20267 min read
Fourth-Party Risk: Your Vendors' Vendors

The vendor register you've built only covers your direct relationships — here's how to get a handle on the layer beneath it without drowning in subcontractor audits you can't enforce anyway.

FrameworksAugust 3, 20268 min read
PCI DSS 4.0 Basics for SaaS Teams

What PCI DSS 4.0 actually requires, why most SaaS companies have less scope than they fear, and what the new rules in version 4.0 mean in practice.

ToolsJuly 31, 20266 min read
Vanta vs Secureframe: Which Fits Your Stage?

Vanta and Secureframe both automate SOC 2 evidence collection, but they're built for different kinds of buyers, and the wrong choice costs you either money or control.

Latest

RSS →
Vendor RiskJuly 27, 20268 min read
Is Microsoft 365 SOC 2 Compliant?

Microsoft 365 holds a semi-annual SOC 2 Type 2 report for its cloud services — but that report covers Microsoft's infrastructure, not how your organization has configured its tenant.

Vendor RiskJuly 17, 20267 min read
Is GitHub SOC 2 Compliant?

GitHub Enterprise Cloud maintains a SOC 2 Type 2 report covering its platform infrastructure, but that report says nothing about how your organization has configured its repositories and access controls.

Security 101July 13, 20267 min read
Zero Trust, Minus the Marketing

What "zero trust" actually means under the vendor noise, and the three things that make it real in practice.

FrameworksJuly 10, 20268 min read
The HIPAA Security Rule, in Plain English

What the Security Rule actually covers, how its three safeguard categories translate to real controls, and what the proposed 2025 overhaul changes for business associates.

Vendor RiskJuly 8, 20267 min read
Is Google Workspace SOC 2 Compliant?

Google Workspace holds a quarterly SOC 2 Type 2 report covering its infrastructure, but that report says nothing about how you've configured your tenant.