About
ComplianceBase is the independent technical reference where CTOs, security engineers, and compliance leads at B2B SaaS companies go to understand what security compliance frameworks actually require — without being sold software, consulting, or a training course on the way out.
What we cover
We publish control-level and framework-level guidance for SOC 2 (AICPA Trust Services Criteria), ISO/IEC 27001:2022, GDPR, and HIPAA — including comparisons, cost ranges, glossary terms, guides, and interactive tools as they ship. Primary sources are linked from Resources.
What we are not
- Not a compliance automation product or audit firm.
- Not legal, accounting, or compliance advice.
- Not a lead-generation funnel — no demo CTAs on reference pages, no email gates on educational content.
How we work
Framework claims cite governing texts (for example AICPA TSP Section 100, ISO/IEC 27001:2022, Regulation (EU) 2016/679, and 45 CFR Part 164). Cost figures are educational composites with methodology notes and dates — not bids. Pages carry a last-verified stamp and an educational disclaimer. Independence is structural: editorial judgment is not subordinated to a product SKU.
Contact
Editorial and corrections: editorial@compliancebase.org. For privacy requests, see our Privacy policy.