Skip to content
compliancebase

About

ComplianceBase is the independent technical reference where CTOs, security engineers, and compliance leads at B2B SaaS companies go to understand what security compliance frameworks actually require — without being sold software, consulting, or a training course on the way out.

What we cover

We publish control-level and framework-level guidance for SOC 2 (AICPA Trust Services Criteria), ISO/IEC 27001:2022, GDPR, and HIPAA — including comparisons, cost ranges, glossary terms, guides, and interactive tools as they ship. Primary sources are linked from Resources.

What we are not

  • Not a compliance automation product or audit firm.
  • Not legal, accounting, or compliance advice.
  • Not a lead-generation funnel — no demo CTAs on reference pages, no email gates on educational content.

How we work

Framework claims cite governing texts (for example AICPA TSP Section 100, ISO/IEC 27001:2022, Regulation (EU) 2016/679, and 45 CFR Part 164). Cost figures are educational composites with methodology notes and dates — not bids. Pages carry a last-verified stamp and an educational disclaimer. Independence is structural: editorial judgment is not subordinated to a product SKU.

Contact

Editorial and corrections: editorial@compliancebase.org. For privacy requests, see our Privacy policy.