Skip to content
AtheronLABS

You're visiting from the United States. Prices are shown in US dollars. Not right?

labs@atheron:~/services/compliance$ build --to-controls --support-audit

Compliance engineering

Built in, then audited.

We build the controls into your product and support you through your audit. Certification and attestation reports are issued by independent auditors, and we help you get ready for them.

// what we build

The controls auditors ask for.

01

Access

Single sign-on, multi-factor sign-in and access by role, with every grant recorded.

02

Audit logs and encryption

Logs that show who did what. Encryption in transit and at rest, with keys managed properly.

03

Backups and recovery

Backups whose restores are tested, and runbooks for when something goes wrong.

04

Monitoring and scanning

Logging, alerting, and vulnerability and dependency scanning that run on every change.

05

A secure way of working

Change management in CI, reviewed code, and secrets kept out of the code.

06

Privacy features

Consent, data subject requests to export or erase, data residency, retention and deletion, and help keeping your records of processing.

07

Incident response

Incident runbooks, so your first hour is a plan rather than a scramble.

08

Accessibility

WCAG 2.1 and 2.2 AA and AODA remediation, with an accessibility conformance report (ACR or VPAT).

09

Audit readiness

A gap assessment, a written policy set, evidence collected in your compliance platform, and help through fieldwork and findings.

// how we work

Built once, for every framework.

  • Frameworks share most of their controls. We build each control once and map it to every framework you need, so a second framework costs only the difference.
  • We build to the controls and support your audit. Certification and attestation reports are issued by independent auditors, never by us.
  • GDPR, PIPEDA and HIPAA have no official certification. We build for them, and we say so plainly.
  • Where a requirement is a legal question, we scope it with you and your counsel.

// frameworks

The frameworks we build for.

attestation
SOC 2 Type I and Type II
certification
ISO 27001, through your certification body
privacy
GDPR, PIPEDA and Quebec Law 25, CCPA
health
HIPAA-ready architecture, and PHIPA for Ontario health
payments
PCI DSS, scoped by your payment design
accessibility
WCAG 2.1 and 2.2 AA and AODA
government
Security classification such as Protected B, scope only

// a typical first project

Readiness for a first SOC 2 report.

The controls built into your product, a gap assessment, and policies and evidence set up in your compliance platform. Open it in the estimator to see our price, the auditor's likely cost and the timeline.

// questions

Questions about compliance work.

Will you certify our app?

No one at a studio can. We build to the controls and support your audit. The report comes from an independent auditor you choose.

How long does SOC 2 take?

A first Type I report usually means two to four months of readiness and building, then a few weeks of fieldwork. Type II adds an observation window of three to twelve months.

What will the auditor cost?

The estimate shows an indicative range for the auditor and any compliance platform, separate from our price, so you can see the likely first-year total.

Do you hold these certifications yourselves?

No. We build for them and help our clients through them.

// industries

How it fits your industry.

See what this looks like in your industry: the questions buyers ask, and example projects with a price range.

// where we work

Find your market.

See this work from your city: what changes there, the questions buyers ask, and prices in your currency.

// start

Not sure which you need?

Tell us the problem, not the solution. We will tell you what we would build, and what we would not.

Compliance and security engineering | Atheron Network Labs