A stack of regulations holds you responsible for vetting and certifying every vendor —
and every sub-processor — your data passes through. These guides explain each rule in
plain language and how keeping data on a self-hosted system removes the third party at the root.
Educational summaries, not legal advice.
The Safeguards Rule requires financial institutions — defined broadly enough to cover many accountants, tax preparers, advisers, and lenders — to maintain a written information-security program with administrative, technical, and physical safeguards for customer information.
IRS Publication 4557 guides tax professionals on safeguarding taxpayer data and points to the FTC Safeguards Rule as the legal baseline, including the duty to have a written security plan.
Regulation S-P requires broker-dealers and investment advisers to adopt written policies to safeguard customer records and information, with FINRA reinforcing vendor-oversight and incident-response expectations.
The Payment Card Industry Data Security Standard sets requirements for protecting cardholder data across everyone who stores, processes, or transmits it.
A SOC 2 examination reports on how an organization meets the AICPA Trust Services Criteria (security, availability, processing integrity, confidentiality, and privacy).
HIPAA requires covered entities and their business associates to protect the confidentiality, integrity, and availability of protected health information (PHI) through administrative, physical, and technical safeguards.
The HITECH Act strengthened HIPAA: it made business associates directly liable for many requirements, raised penalties, and introduced breach-notification duties that ripple across everyone holding the data.
Defense contractors handling Controlled Unclassified Information (CUI) must implement the security controls in NIST SP 800-171, with CMMC 2.0 adding assessment and certification to prove it.
FBI Criminal Justice Information Services (CJIS) Security Policy
The CJIS Security Policy sets the minimum security controls for handling criminal justice information (CJI), covering access control, encryption, auditing, and personnel screening.
FedRAMP (federal) / GovRAMP, formerly StateRAMP (state & local)
FedRAMP (federal) and GovRAMP — the state and local program formerly called StateRAMP — standardize how cloud services are security-assessed and authorized before government agencies may use them to handle government data.
Model Rule 1.6 requires lawyers to make reasonable efforts to prevent unauthorized disclosure of client information, and Rule 5.3 requires reasonable supervision of nonlawyer assistance — including outside vendors.
These pages are general, educational summaries and are not legal advice;
requirements vary by jurisdiction, data type, and engagement. Confirm your obligations with counsel.
Modern software, kept inside your walls.
Tell us about your organization and the data you need to protect. We’ll help you put
capable, modern tools to work on a private system we ship, install, and support — with
nothing ever leaving your network.