Compliance programs

Each program takes you from where you are to the audit, with controls built in your systems rather than written into a binder. Enterprise buyers ask for SOC 2 Type 2 first, European buyers for ISO 27001, and buyers of AI products increasingly for ISO 42001.

What it includes

  • SOC 2 Type 1 and Type 2, from build-out through the observation period and audit fieldwork
  • ISO 27001 certification, with the ISO 27701 privacy extension
  • ISO 42001 and AIUC-1 certification for AI systems and agent platforms
  • SOX IT general controls readiness before an initial public offering
  • GDPR and CCPA privacy programs
  • Other frameworks your customers require, including CMMC, HIPAA and PCI DSS
  • Policies written for how your company operates, rolled out with training and acknowledgment tracking

What you get

The audit confirms work you already finished, and the program underneath it holds up against a real attacker.

How it runs

Every engagement is scoped to your organization, its size and its risk, with a fixed price or monthly retainer agreed before work starts.

Trellis works inside your environment with read-only access your team can revoke at any time, and delivers every change as a pull request or configuration change your engineers approve. Trellis never holds standing administrator access. Read how Trellis works →

Other services

Talk through your situation.

Thirty minutes with Nick. Bring your questions, and we’ll work through the options together. If Trellis isn’t the right fit, we’ll introduce you to someone who is.

Book a call

Not ready for a call? Email hello [at] trellissecurityadvisors.com