EA · 02Learn
Compliance, explained.
Frameworks, audit mechanics, and the controls behind them — written for founders and engineers who need the certification, not a security career.
Start here
The fundamentals, framework by framework.
SOC 2
The Trust Services Criteria, Type I vs Type II, and what an auditor actually asks you to evidence.
ISO 27001
Building an ISMS, running the Statement of Applicability, and surviving the Stage 1 / Stage 2 audit.
ISO 42001
The AI management standard — governance for teams shipping models into regulated markets.
HIPAA
Safeguards, BAAs, and what covered entities expect before they route PHI through your product.
GDPR
Lawful basis, data subject rights, and the records processors are asked to produce.
Cost of compliance
Model your scope, timeline, and audit cost before you commit to a framework.