Compliance library

The rules that make you certify every vendor.

A stack of regulations holds you responsible for vetting and certifying every vendor — and every sub-processor — your data passes through. These guides explain each rule in plain language and how keeping data on a self-hosted system removes the third party at the root. Educational summaries, not legal advice.

Financial privacy & safeguards

GLBA Safeguards Rule (16 CFR 314)

16 CFR Part 314 — U.S. Federal Trade Commission

The Safeguards Rule requires financial institutions — defined broadly enough to cover many accountants, tax preparers, advisers, and lenders — to maintain a written information-security program with administrative, technical, and physical safeguards for customer information.

Read the guide →

IRS Pub. 4557 (FTC Safeguards)

IRS Publication 4557

IRS Publication 4557 guides tax professionals on safeguarding taxpayer data and points to the FTC Safeguards Rule as the legal baseline, including the duty to have a written security plan.

Read the guide →

SEC Reg S-P / FINRA

17 CFR Part 248 (Reg S-P); FINRA rules

Regulation S-P requires broker-dealers and investment advisers to adopt written policies to safeguard customer records and information, with FINRA reinforcing vendor-oversight and incident-response expectations.

Read the guide →

PCI DSS (service providers)

PCI DSS — PCI Security Standards Council

The Payment Card Industry Data Security Standard sets requirements for protecting cardholder data across everyone who stores, processes, or transmits it.

Read the guide →

Privacy (international)

Audit & assurance

SOC 2 vendor management

AICPA Trust Services Criteria (SOC 2)

A SOC 2 examination reports on how an organization meets the AICPA Trust Services Criteria (security, availability, processing integrity, confidentiality, and privacy).

Read the guide →

Healthcare

HIPAA Privacy & Security Rules

45 CFR Parts 160 & 164 — U.S. HHS

HIPAA requires covered entities and their business associates to protect the confidentiality, integrity, and availability of protected health information (PHI) through administrative, physical, and technical safeguards.

Read the guide →

HITECH Act (BAAs & subcontractors)

HITECH Act (2009) — U.S. HHS

The HITECH Act strengthened HIPAA: it made business associates directly liable for many requirements, raised penalties, and introduced breach-notification duties that ripple across everyone holding the data.

Read the guide →

Defense & controlled data

CMMC certification & assessments

DoD CMMC; NIST SP 800-171

Defense contractors handling Controlled Unclassified Information (CUI) must implement the security controls in NIST SP 800-171, with CMMC 2.0 adding assessment and certification to prove it.

Read the guide →

CJIS Security Policy

FBI Criminal Justice Information Services (CJIS) Security Policy

The CJIS Security Policy sets the minimum security controls for handling criminal justice information (CJI), covering access control, encryption, auditing, and personnel screening.

Read the guide →

Government cloud authorization

FedRAMP / GovRAMP

FedRAMP (federal) / GovRAMP, formerly StateRAMP (state & local)

FedRAMP (federal) and GovRAMP — the state and local program formerly called StateRAMP — standardize how cloud services are security-assessed and authorized before government agencies may use them to handle government data.

Read the guide →

Professional responsibility

ABA Model Rules 1.6 & 5.3

ABA Model Rules of Professional Conduct 1.6 & 5.3

Model Rule 1.6 requires lawyers to make reasonable efforts to prevent unauthorized disclosure of client information, and Rule 5.3 requires reasonable supervision of nonlawyer assistance — including outside vendors.

Read the guide →

These pages are general, educational summaries and are not legal advice; requirements vary by jurisdiction, data type, and engagement. Confirm your obligations with counsel.

Modern software, kept inside your walls.

Tell us about your organization and the data you need to protect. We’ll help you put capable, modern tools to work on a private system we ship, install, and support — with nothing ever leaving your network.