ComplianceBase
The independent technical reference where CTOs, security engineers, and compliance leads at B2B SaaS companies go to understand what security compliance frameworks actually require — without being sold software, consulting, or a training course.
Security compliance, without the spin.
Frameworks
Start with the framework your prospect or regulator asked for. Each overview links into control-level reference pages as they ship.
- SOC 2
AICPA attestation against the Trust Services Criteria — the default ask for US B2B SaaS procurement.
- ISO/IEC 27001
International ISMS certification with 93 Annex A controls — strong in EU, UK, and APAC deals.
- GDPR
EU Regulation (EU) 2016/679 on personal data processing — rights, lawful bases, and security of processing.
- HIPAA
US health privacy and security rules for PHI/ePHI — Privacy Rule, Security Rule, and BAAs.