Resources

Compliance, explained plainly.

Practical guides on SOC 2, ISO 27001, HIPAA and how to run compliance without giving up your data boundary.

SOC 2

How much does a SOC 2 cost?

An honest breakdown of auditor fees, tooling, and internal time — and how to reduce each.

Read the guide →
SOC 2

SOC 2 Type I vs Type II

What each report proves, how long each takes, and how they fit together.

Read the guide →
Frameworks

SOC 2 vs ISO 27001: which do you need?

Attestation vs certification, US vs global, and when to do both.

Read the guide →
ISO 27001

The ISO 27001 certification process

Every step from scoping your ISMS to a two-stage audit — and rough timelines.

Read the guide →
HIPAA

HIPAA compliance checklist

A practical checklist of the safeguards, BAAs and documentation you actually need.

Read the guide →
SOC 2

What is SOC 2?

A plain-English explainer of SOC 2, the Trust Services Criteria, and who needs it.

Read the guide →
ISO 27001

What is ISO 27001?

What the standard is, what an ISMS is, and how certification works.

Read the guide →
SOC 2

SOC 2 compliance checklist

A step-by-step checklist from scoping to a Type II report.

Read the guide →
GDPR

GDPR compliance checklist

The practical steps to meet GDPR — data mapping, DSRs, DPAs and more.

Read the guide →
NIS2

NIS2 explained

Who NIS2 applies to across the EU, and what it now requires.

Read the guide →
DORA

DORA explained

ICT resilience rules for EU financial entities, in plain English.

Read the guide →
HITRUST

What is HITRUST?

The certifiable framework that harmonizes HIPAA, ISO and NIST.

Read the guide →
AI

ISO 42001 explained

Governing AI with a certifiable management system.

Read the guide →
Privacy

GDPR vs CCPA

How the EU and California privacy laws differ — and overlap.

Read the guide →
CMMC

What is CMMC?

The US DoD certification for defense contractors, explained.

Read the guide →
FedRAMP

What is FedRAMP?

How cloud services get authorized for US federal use.

Read the guide →
AI

The EU AI Act, explained

How the EU regulates AI by risk tier, and who's affected.

Read the guide →
TPRM

Third-party risk management guide

Inventory vendors, run reviews, and track contracts.

Read the guide →
Trust

What is a Trust Center?

Why a public trust page starts security reviews with a yes.

Read the guide →
SOC

SOC 1 vs SOC 2

What each report covers and which one you need.

Read the guide →
Deployment

Self-hosted vs SaaS compliance tools

Where should your evidence live? A practical comparison, and when each fits.

Read the guide →
By framework

Framework guides

V
Vallorix AssistantAI · answers about compliance & the product
AI assistant · not a human · answers may be imperfect