Skip to content
compliancebase

About

ComplianceBase is the independent technical reference where CTOs, security engineers, and compliance leads at B2B SaaS companies go to understand what security compliance frameworks actually require — without being sold software, consulting, or a training course on the way out.

What we cover

We publish control-level and framework-level guidance for SOC 2 (AICPA Trust Services Criteria), ISO/IEC 27001:2022, GDPR, and HIPAA — including comparisons, cost ranges, glossary terms, guides, and interactive tools as they ship. Primary sources are linked from Resources.

Independence

ComplianceBase has no compliance automation product, no audit practice, and no consulting arm. We are not owned by a CPA firm, a certification body, or a software vendor, and no framework page is written to steer a reader toward a certification because it is easier to sell tooling for afterward.

The site is supported by display advertising and by labeled affiliate links to compliance automation vendors, which appear only on comparison and cost pages — never on control reference pages. Affiliate relationships do not change what a page says a vendor does or does not do; every vendor mentioned is described with its stated limitations alongside its stated strengths. There are no demo request buttons, no email gates on content, and no "book a call" prompts anywhere on the site. If a page ever reads like it is selling you something, that is a defect — report it to editorial@compliancebase.org.

How we source and verify

Every framework claim cites the governing text it comes from — AICPA TSP Section 100, ISO/IEC 27001:2022, Regulation (EU) 2016/679, or 45 CFR Part 164 — with the specific control, article, or CFR section number rather than a paraphrase. Where a requirement is genuinely ambiguous or left to auditor discretion, the page says so instead of projecting false confidence.

Cost and timeline figures are educational composites built from published auditor and certification-body pricing, vendor list prices, and practitioner-reported figures — each with a methodology note and an access date, not a bid or a quote. Every content page carries a last-verified stamp so you can see how current the citation is at a glance. When a framework body updates guidance or a regulator issues a new interpretation, we update the affected pages and move the stamp forward; we do not silently backdate corrections.

Corrections are welcome and expected — precision is the product here, and a wrong citation is a failure state we want to hear about. Email editorial@compliancebase.org with the page URL and what looks wrong.

What this site is not

  • Not a compliance automation product, an audit firm, or a certification body — we do not issue attestations or certificates, and nothing on this site substitutes for one.
  • Not legal, accounting, or compliance advice, and not a substitute for engaging a licensed CPA firm, an accredited certification body, or qualified legal counsel for an actual audit or certification decision.
  • Not a lead-generation funnel — no demo CTAs on reference pages, no email gates on educational content, and no sales follow-up triggered by anything you read here.
  • Not a vendor ranking site. Where automation platforms are discussed, they are described neutrally, with limitations stated alongside capabilities — we do not endorse a "best" tool.

Disclaimer

Content on ComplianceBase is provided for informational and educational purposes only. It does not constitute legal, audit, accounting, or compliance advice, and reading it does not create an advisory relationship of any kind. Framework requirements, interpretations, and pricing change over time and vary by jurisdiction, industry, and individual auditor or certification body — verify anything here against the primary source and your own engaged professionals before relying on it for an audit, certification, or legal decision. We make no warranty as to the completeness or current accuracy of any page beyond its stated last-verified date.

Contact

Editorial and corrections: editorial@compliancebase.org. For privacy requests, see our Privacy policy.