Leave request
Burger logoBurger logo
Security & compliance automation

Compliance that runs every day, not the week before the audit.

We implement the technical controls behind NIS2, DORA, the EU AI Act, SOC 2 and ISO 27001 in your infrastructure as code, then keep them enforced, monitored and evidenced continuously, with remediation shipped as pull requests your engineers merge.

Where our role ends

DigitalCare is an engineering partner, not an auditor or a certification body. We build, monitor and remediate the technical controls and produce the evidence. Certification is issued by your auditor. We never certify anyone and we do not promise an audit outcome.

What applies to you

Two kinds of pressure: the deal you want to close, and the law you are already under.

The technical work underneath is largely the same. What differs is who asks, what they accept as proof, and what happens if the answer is thin.

Buyer-driven: your customer asks
Asked for in the deal

SOC 2

The report enterprise buyers ask for by name, most often Type II, which covers a period rather than a date. It attests that your controls actually operated over three to twelve months, so the evidence has to exist continuously, not be assembled the week before.

Asked for in the deal

ISO 27001

The certificate European, UK and Asian buyers and public tenders ask for. Certification covers a management system: scope, risk treatment, a Statement of Applicability against the 93 controls of Annex A, internal audit, then a three-year cycle with annual surveillance audits.

Law-driven: a regulator asks
Overdue since Oct 2024

NIS2

Essential and important entities across many sectors, and often their suppliers by contract. Most member states have transposed and national supervision is live: in July 2026 the Commission referred four of the remaining ones to the EU Court.

Applicable since Jan 2025

DORA

Financial entities: ICT risk management, incident reporting, resilience testing, registers of information. ICT vendors are bound through contract, and providers designated as critical sit under direct EU oversight.

Transparency live since Aug 2026

EU AI Act

Disclosure for chatbots and marking of generated content apply now. The high-risk obligations (oversight, logging, traceability, data governance) were deferred to December 2027 and August 2028.

11 September 2026

Cyber Resilience Act

Manufacturers of products with digital elements start reporting actively exploited vulnerabilities and severe incidents: 24 hours to an early warning, 72 hours to a notification. The full obligations follow in December 2027.

Dates are as publicly published and current as of August 2026; your scope and the dates that actually bind you depend on your sector, size and member state. We are engineers, not your legal counsel.

Which one do we need

Different questions, one infrastructure underneath.

Most teams end up doing more than one, usually because buyers on different markets ask for different things. The controls overlap heavily; the proof each one wants does not.

SOC 2ISO 27001NIS2
What it isAn auditor’s report on how your controls operatedCertification of a management systemEU law, with a supervisory authority behind it
Who asks for itEnterprise buyers, most often from the USEuropean, UK and Asian buyers, public tendersYour national regulator, and customers by contract
What you getA Type I or Type II report shared under NDAA certificate valid three years, with annual surveillanceNo certificate: you show evidence on request
What decides the outcomeWhether controls operated across the whole periodWhether the management system exists and is followedWhether the service stays resilient and incidents are reported in time
The engineering workContinuous, attributable evidenceControls mapped to Annex A, plus the documented systemEnforced controls, tested recovery, a 24 and 72 hour reporting path

Swipe the table sideways →

Our part is the same in all three cases: build and operate the controls, and make the evidence a by-product of running the system. The report, the certificate and the regulator’s judgement stay with your auditor and your authority.

The honest framing

A binder and a screenshot folder that went stale a week later.

That is what most compliance projects produce. But the technical controls behind every one of these frameworks (access control, encryption in transit and at rest, logging and retention, backup and restore testing, change management, vulnerability management, incident response, supplier oversight) are infrastructure work.

That is what we do. And it is what we keep doing after the certificate is issued, because a control that isn’t enforced between audits was never a control.

Control → evidence → who does it

Every control has an implementation, an artifact your auditor asks for, and a name against it.

ControlHow it’s implementedEvidence the auditor wantsWho produces it
Access controlRBAC and SSO defined as code, least privilege by defaultAccess reviews and role diffs over timeGenerated from the repository history
Change managementGitOps: every change is a reviewed pull requestMerge history as the audit trail: who approved what, whenProduced by the workflow itself
Logging & monitoringCentralized logs with defined retention, alerting on the gapsCoverage and retention proof across systemsMetatron, continuously
Vulnerability managementScanning in the pipeline and in the running clusterOpen and closed findings with timestampsVerdict opens the remediation pull requests
EncryptionIn transit and at rest, keys and secrets managed, enforced by policyConfiguration state and policy denial recordsPolicy engine, evidence collected automatically
Backup & restoreAutomated backups plus scheduled restore tests, not just backup jobsRestore test results with dates and outcomesScheduled and evidenced by the platform
Incident responseOn-call rotation, runbooks, defined severities and comms pathsIncident timelines and postmortemsProduced by the operations you already pay for

Swipe the table sideways →

What we do

Assess, implement, harden, operate.

01 · Assess

Gap assessment against the frameworks in scope

Which frameworks actually apply, what the current state of the technical controls is, and a prioritized gap list with a remediation plan, ordered by risk and effort, not alphabetically.

02 · Implement

Controls as code

Network policy, secrets management, RBAC and SSO, encryption, centralized logging and retention, backup and restore testing, a hardened CI/CD supply chain, and policy as code so the compliant option is the default one.

03 · Harden

Kubernetes security posture

Cluster hardening, admission policy, image provenance and signing, runtime monitoring and benchmark drift: the natural extension of Managed Kubernetes rather than a separate product.

04 · Operate

Continuous evidence, not an annual sprint

Continuous evidence collection, drift detection, remediation pull requests, and audit support when your auditor asks. We answer the technical questions so your team doesn’t rebuild the story each cycle.

Where the agents fit

Continuous monitoring is evidence collection. Remediation is a pull request.

Metatron already watches infrastructure continuously and investigates deviations with evidence chains attached rather than raising a bare alert, which is exactly what an auditor means by continuous monitoring. Verdict ships fixes as pull requests a human reviews and merges, so every remediation carries its own audit trail and a named approver. Read-only investigation, human-gated change, full auditability.

1

Control implemented

As code, in your repositories, enforced by policy.

2

Posture monitored

Metatron watches configuration, coverage and drift continuously.

3

Deviation investigated

Read-only: what changed, where, when, and what it affects.

4

Fix merged by a human

Verdict proposes; a senior engineer reviews, merges and owns it.

5

Evidence stored

Timestamped, attributable, ready when the auditor asks. Then the loop repeats.

The old shape: a once-a-year audit sprint that reconstructs the last twelve months from memory and screenshots. The loop above is the same work, spread across every day, produced by the system that does the work anyway.

Who this is for

Four situations, and one where you should not hire us.

EU SaaS and fintech facing NIS2 or DORA

Obligations landing on a fixed date, against infrastructure that was built for speed rather than for evidence.

Startups whose enterprise deals hinge on a questionnaire

SOC 2 or ISO 27001 has become a sales blocker, and the honest answers require engineering work first.

Companies deploying AI systems under the AI Act

Data flows, logging, retention and human oversight become infrastructure questions. A private LLM deployment answers several of them structurally: the data never leaves your perimeter.

Public sector organizations aligning with EU frameworks

Documented data flows, residency and continuity requirements, with the operational record to back them. See the Government case.

When to call someone else

If you need only a certificate and have no infrastructure to change, an auditor or a compliance platform is the cheaper and more direct route. We are worth hiring when the controls themselves have to be built and then kept running.

Tooling

Open source, in your accounts, with the evidence in your systems.

OPA / GatekeeperKyvernoTrivy / GrypeCosign / SBOMVault / External SecretsSSO / identityCentralized loggingBackup & restore toolingCIS benchmarks

If you already run a compliance platform, we integrate with it and feed it the technical evidence instead of duplicating your control register.

FAQ9 questionsCloseOpen
Are you an auditor?

No, and that is better for you. We are an engineering partner: we build, monitor and remediate the technical controls and produce the evidence. Your auditor issues the certification. The party implementing controls should not be the party attesting to them.

Do you guarantee we pass the audit?

No one honest can promise that. What we can do is make the technical evidence real, current and continuously produced, so your audit reviews a live system instead of a folder of screenshots from last quarter.

Does NIS2 apply to us?

It reaches well beyond classic critical infrastructure: essential and important entities across many sectors, and frequently their suppliers through contractual requirements. Applicability depends on your sector, size and national transposition, which is what the gap assessment establishes.

What does DORA require from an ICT provider like you?

DORA places obligations on financial entities for how they manage ICT third parties: contractual terms, oversight, incident reporting paths, exit strategies and testing. Practically, we support your register of information, produce incident timelines and evidence, and work to the contractual requirements your legal team sets.

What about the AI Act if we run AI internally?

Obligations depend on your role, provider or deployer, and on the risk classification of the system. On the infrastructure side the recurring questions are data flows, logging and retention, human oversight and traceability. A private LLM deployment answers several of them structurally, because inference stays inside your perimeter.

How long does a gap assessment take?

It is a scoped engagement rather than an open-ended project: frameworks in scope, current state of the technical controls, a prioritized gap list and a remediation plan. Duration is agreed up front and depends on how many frameworks and environments are involved.

Can you work with our existing auditor or compliance platform?

Yes. Your auditor stays your auditor and we produce what they ask for. If you already run a compliance platform, we feed the technical evidence into it rather than duplicating your control register.

What can the agents change?

Nothing directly. Monitoring and investigation are read-only; every remediation ships as a pull request a human reviews and merges, which is also what gives each fix an audit trail.

How is this different from a penetration test?

A penetration test is a point-in-time attempt to break in. This is the ongoing engineering work of implementing, enforcing and evidencing controls. They complement each other; neither replaces the other.

Start with a gap assessment.

Which frameworks apply to you, where the technical controls stand today, and a prioritized plan to close the gaps, before the deadline picks the order for you.