attack-surface · your estatelive

// services / compliance

Get audit-ready without the paperwork spiral.

SOC 2, ISO 27001, HIPAA and the rest shouldn’t stall your next deal. We run the gap assessment, build a prioritised roadmap, put the controls and evidence in place, and stay beside you through the audit itself, so a security questionnaire or certification stops being the thing that holds a deal up.

// engagement scope
Cloud & infrastructure
Apps, APIs & mobile
Identity & access
Pipeline (CI/CD)
Compliance readiness
find·fix·verify

// what readiness means

We get you ready. An auditor signs it off.

Compliance readiness is the work of getting your security controls, policies and evidence into the shape a framework requires, before the formal audit. We handle that end to end. The certificate itself is issued by an independent auditor or certification body; our job is to make sure that when they look, everything is already in place.

Readiness, not a rubber stamp

We build the real controls behind the certificate, so it reflects how you actually run security.

Written for how you work

Policies and evidence shaped around your stack and team, not copied from a generic template.

// frameworks we prepare you for

The frameworks your customers and regulators ask about.

SOC 2

The report most SaaS buyers ask for. We get you ready for Type 1 or Type 2.

ISO 27001

The international standard for an information security management system (ISMS).

HIPAA

For handling US health data: safeguards, policies and evidence in order.

GDPR

EU data protection: lawful processing, records, and the rights your users have.

PCI DSS

If you touch cardholder data, the controls that keep you in scope and covered.

DPDP

India’s Digital Personal Data Protection Act. Get ahead of it before enforcement bites.

// how we get you there

From gap to green, in a clear order.

01

Gap assessment

We measure you against your target framework and show exactly what’s missing.

02

Prioritised roadmap

A plan sequenced by effort and impact, tied to your timeline and budget.

03

Controls and evidence

We put the technical and process controls in place and capture the evidence auditors want.

04

Policies that fit

Policies written for how you actually work, ready to show and easy to maintain.

05

Support through the audit

We stay beside you during fieldwork, so questions get answered and nothing stalls.

// proof

The groundwork compliance actually asks for.

For a venture-backed technology company, we hardened the cloud and applications that a framework audit scrutinises, and put the evidence in order. Client name withheld and specifics anonymised at their request.

900+

AWS findings surfaced and triaged

580+

GCP findings surfaced and triaged

100%

endpoints brought under EDR

The controls behind those numbers are exactly what SOC 2 and ISO 27001 auditors look for.

// soc 2 vs iso 27001

Which one do you actually need?

They overlap more than they differ, both prove you run security properly. The right first step usually comes down to where your customers are and what their procurement teams ask for.

Start with SOC 2 when

Your buyers are mostly US-based and their security questionnaires ask for a SOC 2 report.

Start with ISO 27001 when

You sell into Europe, Asia or enterprise procurement that expects the international standard.

// frequently asked

Compliance questions, answered straight.

What's the difference between SOC 2 Type 1 and Type 2?

Type 1 checks that your controls are designed correctly at a point in time. Type 2 checks that they actually operated over a period, usually three to twelve months. Most buyers eventually want Type 2; Type 1 is a faster first milestone.

How long does SOC 2 take?

Is SOC 2 mandatory?

Do you issue the certificate?

SOC 2 or ISO 27001, which should we do first?

Can you help with India's DPDP Act?

// start here

Make compliance a lever, not a fire drill.

Book a free security review and we’ll map the fastest path to the framework your customers are asking for. No obligation.