Learn Privacy, Security, and Compliance
Plain-English guides to the frameworks, laws, and security reviews that gate your growth. From SOC 2 and GDPR to DSARs and AI governance, written for the team that has to answer the questionnaire, not only pass the audit.
Security & Compliance
What buyers check before they sign.
SOC 2
The default trust signal for SaaS: the framework, the audit, Type 1 vs Type 2, cost, and staying current.
ISO 27001
The international ISMS standard: the certification path, Annex A controls, and the Statement of Applicability.
Trust Center
The buyer-facing page that proves your security posture: what it is, why buyers expect one, and what it should include.
AI Governance
The EU AI Act, ISO 42001, and NIST AI RMF as one program: AI policies, disclosures, and the AI security review.
Data Privacy
Consent, rights requests, and the law behind them.
GDPR
The EU's core privacy law in operational terms: who must comply, the data subject rights, RoPA, and consent.
CCPA/CPRA & US State
California plus the wider state patchwork: opt-outs, GPC, and the new ADMT rules, kept current.
DSAR / Privacy Requests
Data subject access requests end to end: what one is, response timelines by law, and fulfilling them at scale.
Consent Management
Cookie and tracker consent from first principles: Google Consent Mode v2, the IAB TCF, and geo-targeted banners.
Tools & Reference
Free interactive tools and quick definitions to use alongside the guides.
Compliance Glossary
Short, answer-first definitions for every term across the guides, from DSAR and RoPA to the Trust Services Criteria.
SOC 2 Readiness Assessment
A free self-check: answer 13 questions and see how close you are to a SOC 2 audit. No signup.
US State Privacy Law Tracker
Every US state privacy law at a glance: effective dates, opt-out rules, and which ones require honoring GPC.
Google Consent Mode Scanner
Scan your site to check whether your Google Consent Mode v2 signals are set up correctly.