Minimal SOC2
A lean set covering minimum requirements for SOC2 Type I/II. Ideal for early-stage startups.
SOC2
View Policies
Each set is designed for a specific compliance scenario.
| Policy Set | Best For | Frameworks | Complexity |
|---|---|---|---|
| Minimal SOC2 | Early-stage startups | SOC2 | Low |
| Health Tech | Companies handling PHI | SOC2 HIPAA | Medium |
| Health Tech (HITRUST) | HITRUST certification | HITRUST HIPAA | High |
| Streaming | Media services, global users | SOC2 GDPR COPPA DSA | High |
| Fintech Payments | Payment processors, fintech | SOC2 PCI-DSS GLBA | High |
| Ed-Tech | Education technology, student data | SOC2 FERPA COPPA | Medium |
A lean set covering minimum requirements for SOC2 Type I/II. Ideal for early-stage startups.
Comprehensive coverage for healthcare technology companies handling protected health information.
Extended health tech coverage mapped to HITRUST CSF for organizations pursuing certification.
For media and streaming services with global audiences. Includes privacy regulations.
Comprehensive coverage for payment processors and fintech companies handling cardholder data.
Policies for educational technology companies handling student data and children's privacy.
Different industry or framework requirements? Let's discuss your needs.
Contact for custom work