Security and compliance

Get SOC 2 and HIPAA off the ground without stalling the roadmap.

A compliance platform will tell you which infrastructure controls are failing. Someone still has to fix them, in Terraform, in IAM, in the cluster, and keep them fixed after the audit. That is what we do. Digital Buttes builds the controls into your AWS, Google Cloud, and Kubernetes platform, gathers the evidence, and sits with you and your auditor. We sign BAAs.

The gap

Why compliance stalls on the infrastructure side

Vanta, Drata, Secureframe, or an auditor's spreadsheet connects to your cloud account and produces a list. Policies and HR checks get done in an afternoon. The infrastructure items sit open for months, because each one is real engineering work and the team is busy shipping. These are the ones we see most often.

  • Shared root or owner credentials, MFA not enforced, no record of access reviews
  • Cloud and Kubernetes audit logs not enabled, not retained, or never looked at
  • Databases and buckets without encryption at rest, backups that have never been restored
  • Secrets living in environment variables, CI settings, and someone's laptop
  • No scanning of container images or dependencies, no patch cadence
  • Deploys with no change trail: nobody can say who shipped what, when, or who approved it
  • Production reachable without SSO, VPN, or a bastion, and no way to prove who accessed PHI
What we implement

Controls built into the platform, not bolted on

Every control is implemented in code and reviewed like any other change, so it is still true at the next audit and the one after that.

Identity and access

  • SSO and enforced MFA across cloud, Kubernetes, and SaaS
  • Least-privilege IAM roles instead of shared admin keys
  • Key rotation and short-lived credentials
  • Quarterly access reviews with evidence

Logging and monitoring

  • CloudTrail, GCP audit logs, and Kubernetes audit logs, centralized and retained
  • Alerting on privilege changes and unusual access
  • Application logs with access to sensitive records traceable to a person

Data protection

  • Encryption at rest and in transit, with managed keys
  • Backups with tested, documented restores
  • Network segmentation and a defined PHI boundary
  • Secrets in a secrets manager, out of CI and env files

Change management

  • Every infrastructure change through a reviewed pull request
  • CI/CD as the only path to production
  • Container image and dependency scanning in the pipeline
  • A deploy history your auditor can read

Vulnerability management

  • Scheduled patching for nodes, images, and dependencies
  • EKS and GKE upgrades on a cadence, not in a panic
  • Findings triaged and tracked to closure

Policies and evidence

  • Incident response plan, runbooks, and post-mortems
  • Risk assessment and documented SOPs
  • Evidence collected as a by-product of how the platform runs
  • Auditor walkthroughs with the people who built it
HIPAA

For healthcare and other regulated teams

Much of our work is for companies handling PHI. HIPAA adds a few things SOC 2 does not, and getting them right early is much cheaper than retrofitting them.

  • We sign a Business Associate Agreement with you
  • PHI scoping: which services, databases, and logs actually hold it, so the boundary is small and defensible
  • Only HIPAA-eligible AWS and Google Cloud services inside that boundary
  • Access to PHI logged, attributable to a person, and reviewable
  • Breach response procedures written down before you need them
The process

From gap list to audit

  1. 1

    Gap review

    We go through your compliance platform's findings, or your auditor's request list, alongside your architecture. Each item is sorted into fix now, redesign, or policy.

  2. 2

    Remediate in code

    Fixes land as reviewed changes to Terraform, IAM, CI/CD, and the cluster. Failing checks turn green as the changes ship, and your developers see how each one was done.

  3. 3

    Evidence and policies

    We write the SOPs and runbooks that match how the platform actually works, collect the evidence, and do a dry run before the auditor arrives.

  4. 4

    Stay compliant

    Controls keep running because they are part of the platform. If we run operations with you, drift gets fixed when it happens instead of rediscovered at the next audit.

Questions

Common questions

Do you replace Vanta, Drata, or Secureframe?

No. We work alongside whichever platform you use, or without one. They track the controls; we implement the ones that live in your infrastructure.

Do you perform the audit?

No. Auditors have to be independent. We get you ready, sit in on the walkthroughs, and answer the technical questions.

Will you sign a BAA?

Yes.

Do we need Kubernetes for this?

No. The same controls apply on plain VMs, ECS, or Cloud Run. Kubernetes is just where we do most of our work.

How long does it take?

It depends on the size of the gap list and how much of the platform is already in code. We scope it after the gap review, not before.

Will this slow down shipping?

Usually the opposite. Change management through CI/CD means fewer manual steps and fewer surprises, and the audit trail is a side effect.

Send us your gap list

Share your compliance platform's findings or your auditor's request list. We'll tell you what the infrastructure work looks like and how long we think it takes.