Compliance that healthcare technology and fintech companies can actually build on.
Keystone Assurance helps Series A through C companies design, build, and mature their security and compliance programs — and prepares them for SOC 1, SOC 2, and HIPAA attestation with an attestation firm.
From first policy to formal attestation.
Most compliance firms only show up once you're ready for an audit. We don't. We work with companies at every stage — designing programs from scratch for teams that haven't written a policy yet, closing gaps before a formal audit begins, coordinating the audit process once you're ready for attestation, and staying on as your program matures year over year. If you're a healthcare technology or fintech company that needs to get compliant and isn't sure where to start, that's exactly who we built this for.
Compliance Program Buildout
Advisory work to design and implement your security and compliance function — policies, a controls framework, and GRC platform implementation. For companies that need to build before they can be audited.
Readiness Assessment
A structured gap assessment before formal audit work begins, so you know exactly what needs remediation before attestation starts.
Audit Coordination
When you're ready for formal attestation, we help you select the right audit firm, manage the audit process, and ensure your team is prepared for fieldwork. We stay involved throughout so the audit runs smoothly and findings don't come as a surprise.
Ongoing Advisory
Annual audit cycles and continued program maturation, so compliance keeps pace with your company instead of stalling after year one.
Every service you need, under one advisory engagement.
Each engagement is scoped to where your program actually is — not a one-size audit package.
Compliance Program Design & Buildout
Policies, a controls framework, and GRC platform implementation for companies building their program from the ground up.
SOC 2 Type 1 & Type 2
We build and mature the controls behind Security, Availability, Confidentiality, Processing Integrity, and Privacy, and prepare your team for examination by an attestation firm.
SOC 1 Type 1 & Type 2
Dedicated advisory experience with the control environments fintech and financial services companies need before a SOC 1 examination.
HIPAA Risk Assessment
A documented, defensible risk analysis — the foundation covered entities and business associates are expected to have on file.
HIPAA Compliance Advisory
Ongoing HIPAA advisory for covered entities and business associates — policy development, program maturity, and preparation ahead of formal attestation.
Combined SOC + HIPAA Readiness
One coordinated advisory engagement covering both frameworks — for companies that need to satisfy healthcare and enterprise buyers at once.
Ongoing Compliance Advisory
Annual audit cycles and continued program maturity for companies that don't want compliance to stall after the first attestation.
A boutique firm, built for the depth this work actually requires.
We work with a focused client list at higher engagement depth — not a commodity audit shop.
Practitioner-led engagements
Every engagement is led directly by a senior compliance expert — not outsourced to junior staff after the sales call.
Built for healthcare and fintech
HITRUST assessor background and direct HIPAA covered-entity experience mean we already speak the regulatory language your board is asking about.
Real SOC 1 practice
One of the few boutique firms with dedicated SOC 1 capability for fintech and financial services clients — not a generalist audit shop stretching into it.
We start wherever you are
No program yet? We build one. Already audited? We keep it moving. You don't need to be audit-ready to call us.
Fractional vCISO model
Senior compliance leadership without the full time hire. We serve as your embedded compliance partner, not just a vendor who shows up for the audit.
Built for the companies growing fastest under the most scrutiny.
Three steps. One firm, start to finish.
Like a keystone locks the top of an arch, attestation is what makes everything underneath it hold.
Assess
Know exactly where your program stands today.
Build
Implement the controls and policies your program is missing.
Validate
Move through SOC 1, SOC 2, or HIPAA attestation with the right audit firm at your side.
Wherever you are in your compliance journey, start here.
Whether you haven't written a single policy yet or you're six months from your next SOC 2 renewal, we want to hear where you are. Tell us about your company and we'll tell you honestly what stage you're at and what it will take to get you attested.
hello@keystoneassurancecpa.comStraight answers on compliance, from the field.
Plain-English guidance for healthcare technology and fintech companies navigating SOC 1, SOC 2, and HIPAA.
Does Your Series B Healthtech Company Need a Standalone HIPAA Attestation?
A plain-English guide to when growth-stage healthcare technology companies need a standalone HIPAA attestation — and when SOC 2 with a HIPAA supplement is enough.
Read More →Don't Let Your GRC Tool Choose Your Control Set For You
Buying a GRC platform before you know what your control set should be is a common, expensive mistake. Here's a better sequence — and where automation genuinely fits once you get there.
Read More →