Playbooks & production notes

Compliance

What customers, auditors and regulators ask an AI-built app to prove: SOC 2, GDPR, HIPAA, DPAs and security questionnaires, and what each one costs.

SOC 2 reports, GDPR requests, HIPAA agreements and the security questionnaire a big customer sends before signing. For founders whose AI-built app has reached the point where someone asks for proof. Start with "Do I Need SOC 2? Who Asks For It and What Happens Next", then "GDPR for a Small SaaS: What You Actually Owe, in Order".

Compliance

SOC 2 compliance consultants, compliance platforms, auditors, pen testers and engineering: what each one actually does

28 min read
Compliance

A Customer Wants You to Sign a DPA: What Your SaaS Is Agreeing To

22 min read
Compliance

GDPR for a Small SaaS: What You Actually Owe, in Order

22 min read
Compliance

Is Supabase GDPR Compliant? The DPA, the Region and the Subprocessor List

21 min read
Compliance

Replit Compliance: What the SOC 2 Report and the DPA Actually Cover

20 min read
Compliance

Zero Data Retention for Your App's AI Features: What Each Model Vendor Offers

24 min read
Compliance

Do I Need SOC 2? Who Asks For It and What Happens Next

21 min read
Compliance

HIPAA Compliance Cost for a Small App: What Each Bill Is For

21 min read
Compliance

Which App Builders Sign a HIPAA BAA?

22 min read
Compliance

Is Firebase HIPAA Compliant? Which Services Google's BAA Covers

19 min read
Compliance

Is Lovable HIPAA Compliant? What Its Own Documents Say

18 min read
Compliance

Lovable Compliance: What a Customer Can Actually Be Sent

23 min read
Compliance

Your App Already Holds Health Records. What Has to Change

23 min read
Compliance

SOC 2 Cost for a Small SaaS: Who Gets Paid, and for What

23 min read
Compliance

SOC 2 Type 1 vs Type 2: Which Report Closes the Deal

19 min read
Compliance

SOC 2 With No Security Team: Which Controls Are Code and Which Are Paperwork

20 min read
Compliance

A Big Customer Sent a Software Security Assessment Questionnaire

23 min read
Compliance

Export User Data from a SaaS: GDPR Portability Guide

10 min read