The frameworks

Which frameworks do we engineer toward?

Five, each on its own page: SOC 2, HIPAA, ISO/IEC 27001, PCI DSS, and GDPR with LGPD. They share a core of engineering controls but differ in what they protect, who tests them and what the text requires, so each page covers only its own controls. Frameworks we do not cover are listed further down.

SOC 2

A report that an independent CPA firm issues on security and related criteria. The engineering: change management, access, monitoring, infrastructure as code, recovery and vulnerability gates.

HIPAA

The US Security Rule for electronic protected health information: access, audit controls, integrity, transmission security and contingency plans, plus business associate agreements. There is no HIPAA certification. We sign a BAA when an engagement touches PHI.

ISO/IEC 27001

A management system standard that an accredited certification body can certify. The engineering: the technological controls you selected in your Statement of Applicability, and the supplier controls that apply to us.

PCI DSS

Twelve requirements for any entity that stores, processes or transmits card data or can affect its security. The engineering: scope, cryptography, secure software, MFA, logging and scans. A QSA or a self-assessment validates it.

GDPR and LGPD

Two privacy laws, not certifications: privacy by design, security of processing and breach notification (GDPR Articles 25, 32 and 33, LGPD Articles 46 to 49). The engineering builds the technical measures; your counsel decides what the law requires of you.

Who assesses

Who tests, certifies or enforces each one?

Never the engineering vendor. A CPA firm issues SOC 2 reports and an accredited certification body issues ISO/IEC 27001 certificates. A Qualified Security Assessor or your own self-assessment validates PCI DSS. HIPAA, GDPR and LGPD are laws that regulators enforce, and none has a certificate you can buy.

  • SOC 2: an independent CPA firm tests your controls and issues the report.
  • ISO/IEC 27001: an external certification body certifies. ISO does not perform certification or issue certificates.
  • PCI DSS: whether you must validate, and how, is decided by the payment brands and your acquirer. A QSA company writes a Report on Compliance, or you complete a self-assessment questionnaire.
  • HIPAA: no certification. The Security Rule requires a periodic evaluation, and when HHS adopted it in 2003 it said it did not intend to create certification criteria.
  • GDPR and LGPD: supervisory authorities in the EU and the ANPD in Brazil enforce them. An approved certification mechanism under GDPR Article 42 can be one element that shows compliance, not a replacement for it.

The shared core

Which engineering controls do the frameworks share?

Six areas come up in every framework, under different names: access and authentication, logging and monitoring, change management and secure development, encryption and data protection, backup and recovery, and vulnerability and incident handling. Each row gives the clause where each framework asks for it, read from the text on 2026-10-09, then the engineering and the published case behind it.

Access and authentication

What it asks of engineeringWho can reach production and data, how do they prove who they are, and is access removed when it should be?

Unique identities on your SSO, MFA, least privilege, break-glass access that is logged, secrets in a managed store and workload identity for services. Our own engineers use your accounts, and access is revoked when the engagement ends.

  • HIPAA: §164.312(a) access control and §164.312(d) person or entity authentication.
  • ISO/IEC 27002:2022: controls 5.15 to 5.18, 8.2 and 8.5.
  • PCI DSS v4.0.1: Requirements 7 and 8, including 8.4.2, MFA for all non-console access into the cardholder data environment.
  • GDPR Article 32(1) and (4), LGPD Article 46. SOC 2: logical access, on its own page.

Where we have done it

No fixed package covers access control on its own. We scope it in Discovery or with engineers by the hour.

Logging and monitoring

What it asks of engineeringWhat do you record, who watches it, and do the alerts fire when they should?

Metrics, logs and traces wired, alerts tested until they fire, and a runbook. Logs are designed so that protected data, card numbers and personal data do not land in log lines.

  • HIPAA: §164.312(b) audit controls and §164.308(a)(1)(ii)(D), a regular review of audit logs and access reports.
  • ISO/IEC 27002:2022: controls 8.15 and 8.16.
  • PCI DSS v4.0.1: Requirement 10, including 10.2.1 audit logs on all system components and 10.5.1, at least 12 months of history with the latest three months immediately available.
  • GDPR Article 33(3) and (5) and LGPD Article 48 §1: after a breach you must describe the data affected, which depends on records that survive it.

Where we have done it

Delivered by

Change management and secure development

What it asks of engineeringHow does a change get approved, tested and released, and can you show the record?

Changes reach production through a pipeline whose gates can stop a release. Every release is a traceable version with a rehearsed way back.

  • ISO/IEC 27002:2022: controls 8.25 to 8.32, from secure development life cycle to change management.
  • PCI DSS v4.0.1: 6.2.1 and 6.2.4 on secure development, 6.3.2 on an inventory of custom software, and 6.5.1, changes made with a reason, a security impact, approval and testing.
  • HIPAA: the Security Rule has no change-management standard by name. Release controls serve risk management (§164.308(a)(1)(ii)(B)) and integrity (§164.312(c)).
  • GDPR Article 25 and LGPD Article 46 §2: protection from the design of the product through its operation.

Where we have done it

Delivered by

Encryption and data protection

What it asks of engineeringIs the data encrypted where it moves and where it rests, and who holds the keys?

TLS in transit, managed keys and encryption at rest, private network paths to data stores, a web application firewall at the edge, and masked data outside production.

  • HIPAA: §164.312(a)(2)(iv) and (e)(2)(ii), both addressable.
  • ISO/IEC 27002:2022: controls 8.24, 8.10, 8.11 and 8.12.
  • PCI DSS v4.0.1: Requirement 3, including 3.3.1, no sensitive authentication data kept after authorization, and 3.5.1, PAN rendered unreadable wherever it is stored. Requirement 4 covers transmission.
  • GDPR Article 32(1)(a) and Article 25; LGPD Article 46.

Where we have done it

No fixed package covers encryption on its own. We scope it in Discovery or with engineers by the hour.

Backup and recovery

What it asks of engineeringAre there backups, and has anyone shown that a restore works?

Encrypted, scheduled backups and restore drills, so recovery is shown rather than assumed.

  • HIPAA: §164.308(a)(7), where the data backup plan, the disaster recovery plan and the emergency mode operation plan are required.
  • ISO/IEC 27002:2022: controls 8.13, 8.14 and 5.30.
  • PCI DSS v4.0.1: 12.10.1 puts business recovery and data backup processes inside the incident response plan.
  • GDPR Article 32(1)(c): restore availability and access to personal data in a timely manner.

Where we have done it

No fixed package covers backups and recovery on their own. We scope them in Discovery or with engineers by the hour.

Vulnerability and incident handling

What it asks of engineeringHow do you find known vulnerabilities before code ships, and what happens in the first hours of an incident?

Scans run in the pipeline on every change, and a suppressed finding expires. An incident runbook names who decides, who is told and what is recorded.

  • HIPAA: §164.308(a)(6), security incident procedures, and §164.410, a business associate notifies the covered entity without unreasonable delay and within 60 calendar days at most.
  • ISO/IEC 27002:2022: controls 8.7, 8.8 and 5.24 to 5.28.
  • PCI DSS v4.0.1: 11.3.1, internal scans at least every three months with rescans, and 12.10.1, an incident response plan.
  • GDPR Article 33: 72 hours to notify the authority where feasible, and a processor tells the controller without undue delay. LGPD Article 48.

Where we have done it

Delivered by

Other frameworks

What about HITRUST, SOX, FedRAMP, CMMC and the rest?

We name them because buyers ask, and we make no claim about any of them: no published case, no standing to assess. If a control from one of them is on your list, ask on the first call and we will say whether we can staff it.

  • HITRUST: no claim.
  • SOX: Section 404 requires management to assess internal control over financial reporting, and the registered public accounting firm of most issuers to attest to that assessment (15 U.S.C. 7262). The change and access records in the shared core are built the same way for any audit, but financial reporting controls and the auditor's opinion are not ours.
  • FedRAMP, CMMC and NIST SP 800-53 programmes: no claim and no published case.
  • CCPA, DORA and sector rules such as banking regulation: no claim. Ask first.

What we do not claim

What do we not claim?

We are not an auditor, a CPA firm, a certification body, a QSA or a law firm. We hold no SOC 2 report, ISO/IEC 27001 certificate or PCI DSS attestation of compliance, and we claim none for any client.

  • We have no healthcare client and no payments client. Our published cases are in fintech analytics, govtech, proptech, AI, gaming and transportation, and the controls shown on these pages are transferable, not proof of experience in a regulated sector.
  • We guarantee no audit, assessment or regulatory outcome.
  • Policies, risk assessments, training, vendor reviews and legal interpretation stay with your company and your counsel.
  • We claim no partnership with any compliance-automation (GRC) platform.

How we deliver

How do our packages and engineers deliver it?

Start with a fixed-price package, or hire engineers by the hour. The CI/CD & IaC package builds the pipeline and the infrastructure as code. SRE / Observability Foundations wires the monitoring. QA Automation Foundations puts tests in your CI. Discovery turns your assessor's list, your customer's questionnaire or a framework's text into a roadmap with a backlog.

Pipeline and infrastructure as code

A 2-week build or re-architecture of your CI/CD pipelines and your infrastructure as code. The gates that go into the pipeline, such as a vulnerability scan, are agreed in the SOW.

Delivered by

Logging and monitoring

Metrics, logs and traces wired, 3 SLOs defined, alerts tested until they fire, and a runbook.

Delivered by

Tests on every change

A Playwright suite for your 5 critical flows, running in your CI, with accessibility checks.

Delivered by

From the requirement list to a backlog

Discovery understands your product and its configuration end to end and delivers a roadmap with a backlog, roles, critical changes and needs. Bring the requirement list, the assessor's findings or the customer questionnaire, and we turn them into engineering work.

Delivered by

Engineers by the hour

For the work that continues after a package: Senior USD 45–⁠50 an hour, Lead or Architect USD 55–⁠60, with a 6-month minimum, billed per hour worked. You interview the engineer who will do the work.

Sources

Which texts did we read?

Primary texts, read on 2026-10-09. Each framework page lists the exact sections it relies on.

  • HIPAA: 45 CFR Part 164, Subpart C (Security Rule), eCFR text in force on 2026-10-01, with 45 CFR 160.103 and 164.410.
  • ISO/IEC 27001:2022 and ISO/IEC 27002:2022: the publisher's preview extracts (clauses 4 to 10 and the control list), and the certification page of iso.org.
  • PCI DSS: Requirements and Testing Procedures v4.0.1, June 2024, PCI Security Standards Council.
  • GDPR: Regulation (EU) 2016/679 on EUR-Lex. LGPD: Lei nº 13.709/2018 on planalto.gov.br.
  • SOX Section 404: 15 U.S.C. 7262.

Frequently asked questions

Do you cover HIPAA, ISO 27001, PCI DSS and GDPR?

Yes, as engineering toward the controls, with a page for each. We build the pipelines, access, monitoring, encryption and recovery these frameworks ask for. We do not audit, assess or certify, and we have no published healthcare or payments case.

Is Clouditive certified for any of them?

No. We hold no SOC 2 report, ISO/IEC 27001 certificate or PCI DSS attestation of compliance. HIPAA, GDPR and LGPD have no certificate to hold. Security and procurement lists what we do and do not claim.

Do you sign a HIPAA business associate agreement?

Yes. Clouditive signs a HIPAA BAA when an engagement touches PHI. Ask for it on the first call, so it is in place before an engineer has access to PHI.

Which framework should we start with?

The one your customer, regulator or contract names. If several apply, start with the shared core above, because a gated pipeline, access you can prove, tested alerts and drilled recovery serve most of them at once. We recommend no framework; the choice follows who is asking.

Can you make us compliant?

No one can from the outside. Compliance covers policies, people and operations as well as engineering, and the opinion belongs to an assessor or a regulator. We build the engineering controls and leave the evidence an assessor can read.

Do you have healthcare or payments clients?

We have no published case in either sector. Our published work is in fintech analytics, govtech, proptech, AI, gaming and transportation, and each framework page shows which of those cases demonstrates which control.

How long does it take to get ready?

It depends on what you already have, and we give no guarantee about an audit or an assessment. A 2-week package builds one area, such as the CI/CD pipeline and infrastructure as code, and Discovery, 1 to 4 weeks, turns the rest into a roadmap.

Do you work with a compliance-automation platform?

We claim no partnership with any compliance-automation (GRC) platform, and these pages recommend none. If you use one, tell us on the first call.

How do your engineers get access to our systems?

Through your own accounts and identities, with your SSO, your MFA and least-privilege access, revoked when the engagement ends. Every engineer passes a background check before assignment.

Who does the work?

Mat Caniglia leads every project end to end, and the engineers are in LATAM and share your working day. We present candidates within 1 week, and you interview the engineer who will do the work.

Tell us your case.

We reply to every request within 1 business day. We sign an NDA before the call if you ask.