<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Compliance on FivexL. Cloud Engineering Specialists</title>
    <link>/tags/compliance/</link>
    <description>Recent content in Compliance on FivexL. Cloud Engineering Specialists</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <managingEditor>info@fivexl.io (FivexL)</managingEditor>
    <webMaster>info@fivexl.io (FivexL)</webMaster>
    <lastBuildDate>Mon, 04 May 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="/tags/compliance/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Can You Prove Who Accessed Your Data?</title>
      <link>/blog/just-in-time-access-aws/</link>
      <pubDate>Mon, 04 May 2026 00:00:00 +0000</pubDate><author>info@fivexl.io (FivexL)</author>
      <guid>/blog/just-in-time-access-aws/</guid>
      <description>&lt;p&gt;You have logs. You do not have proof.&lt;/p&gt;&#xA;&lt;p&gt;That is the gap most startups in regulated industries like healthcare or fintech discover during their first HIPAA or SOC 2 audit. The IAM policies are there. The roles are configured. Permissions are restricted. But when an auditor asks &amp;ldquo;who had access to this system on March 12th, and what did they do?&amp;rdquo; the answer involves digging through months of logs trying to reconstruct a timeline that was never recorded in the first place.&lt;/p&gt;&#xA;&lt;p&gt;A failed audit does not just cost time. It costs the partnership or enterprise contract that required it.&lt;/p&gt;&#xA;&lt;p&gt;This is the problem just-in-time access solves - and it is simpler than it sounds.&lt;/p&gt;</description>
    </item>
    <item>
      <title>AWS Compliance for Startups: SOC 2, HIPAA, and PCI DSS with RightStart</title>
      <link>/blog/soc2-hipaa-pci-aws-rightstart/</link>
      <pubDate>Fri, 10 Apr 2026 00:00:00 +0000</pubDate><author>info@fivexl.io (FivexL)</author>
      <guid>/blog/soc2-hipaa-pci-aws-rightstart/</guid>
      <description>&lt;p&gt;Setting up compliance-ready AWS infrastructure is one of the first real infrastructure challenges a healthcare or fintech startup faces. This post covers what HIPAA, SOC 2, and PCI DSS actually require from your AWS environment - and how to implement those controls without building everything from scratch.&lt;/p&gt;&#xA;&lt;p&gt;Startups don&amp;rsquo;t fail audits because they lack controls. They fail because they try to implement three frameworks manually in the middle of the night.&lt;/p&gt;&#xA;&lt;p&gt;Most early-stage teams building in healthcare or fintech don&amp;rsquo;t think about compliance until something forces the issue: an enterprise customer asks for a BAA, a partner requires a SOC 2 report, or an investor wants audit-ready infrastructure before closing the round. Suddenly it&amp;rsquo;s this quarter&amp;rsquo;s blocker - the thing standing between you and the deal, the funding, the partnership.&lt;/p&gt;&#xA;&lt;p&gt;SOC 2, HIPAA, and PCI DSS each require the same foundational AWS capabilities - access controls, encryption, network segmentation, audit logging, just weighted differently. But most startups don&amp;rsquo;t have a dedicated infra team to implement all three from scratch. Doing it manually is slow, error-prone, and easy to get wrong in ways that only surface during an audit.&lt;/p&gt;&#xA;&lt;p&gt;If you&amp;rsquo;re asking &amp;ldquo;how do I get SOC 2 on AWS?&amp;rdquo; or &amp;ldquo;I need HIPAA-compliant AWS infrastructure today, where do I start?&amp;rdquo; - &lt;a href=&#34;https://fivexl.io/rightstart&#34;&gt;RightStart&lt;/a&gt; is the answer. It&amp;rsquo;s FivexL&amp;rsquo;s compliance-as-code landing zone for regulated AWS workloads. It converts SOC 2, HIPAA, and PCI DSS controls into enforceable AWS configurations, deployed to your AWS Organization in about a month.&lt;/p&gt;</description>
    </item>
    <item>
      <title>From Leadership Values to Security: Building Audit-Ready Architecture</title>
      <link>/blog/from-leadership-values-to-security/</link>
      <pubDate>Tue, 24 Mar 2026 00:00:00 +0000</pubDate><author>info@fivexl.io (FivexL)</author>
      <guid>/blog/from-leadership-values-to-security/</guid>
      <description>&lt;p&gt;In a recent webinar, &lt;a href=&#34;https://www.linkedin.com/in/rustyatkinson/&#34;&gt;Rusty Atkinson&lt;/a&gt;, SVP, Technology at Clearway Health, joined FivexL&amp;rsquo;s &lt;a href=&#34;https://fivexl.io/specialist/andrey-devyatkin/&#34;&gt;Andrey Devyatkin&lt;/a&gt;, Co-Founder and Principal Cloud Engineering Consultant, and &lt;a href=&#34;https://fivexl.io/specialist/guilherme-ferreira/&#34;&gt;Guilherme Ferreira&lt;/a&gt;, Senior Cloud Engineering Consultant, to discuss a question that matters to every company operating under regulatory pressure: how do leadership values actually turn into secure, audit-ready architecture when deadlines hit?&lt;/p&gt;&#xA;&lt;p&gt;FivexL has worked closely with Clearway Health on building their HIPAA-compliant AWS infrastructure - so this was not a theoretical discussion. Rusty brought the leadership and culture perspective; Andrey and Guilherme brought the architecture and engineering depth. The session connected principles like integrity, clarity, and courage to the operational choices that make security real: least-privilege access, clear tenant boundaries, traceable change management, and HIPAA-aligned evidence practices.&lt;/p&gt;&#xA;&lt;p&gt;When Guilherme asked Rusty directly how he saw the FivexL partnership, Rusty&amp;rsquo;s answer was blunt: &lt;em&gt;&amp;ldquo;In my career, I never had a vendor that I trusted more. You presented to me something that resonated immediately as the answer to the question that I didn&amp;rsquo;t ask - how do you build it when the non-negotiable is security and privacy, when you don&amp;rsquo;t have an army of engineers, and you&amp;rsquo;re running fast? You answered that question before I even asked it.&amp;rdquo;&lt;/em&gt;&lt;/p&gt;&#xA;&lt;p&gt;That trust - between people, between teams, between an organisation and its infrastructure - was the thread running through the entire conversation.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Secure AWS Foundation for Fintech Startup, Neverless</title>
      <link>/case-studies/neverless-case-study/</link>
      <pubDate>Fri, 13 Feb 2026 00:00:00 +0000</pubDate><author>info@fivexl.io (FivexL)</author>
      <guid>/case-studies/neverless-case-study/</guid>
      <description>FivexL delivered a secure, production-ready AWS foundation for a London fintech company expanding beyond Google Cloud.</description>
    </item>
    <item>
      <title>AWS News You Can Actually Use In 2026</title>
      <link>/blog/aws-news-you-can-use-2026/</link>
      <pubDate>Thu, 12 Feb 2026 00:00:00 +0000</pubDate><author>info@fivexl.io (FivexL)</author>
      <guid>/blog/aws-news-you-can-use-2026/</guid>
      <description>&lt;p&gt;AWS ships fast. At AWS re:Invent 2025, AWS made 500+ announcements. Most teams don’t have time to read every release - but we did.&lt;/p&gt;&#xA;&lt;p&gt;We did it for one reason: to stay on top of the technology (and help you do the same). Below is our shortlist of AWS updates worth adopting in 2026 if you want to stay ahead of the competition.&lt;/p&gt;&#xA;&lt;p&gt;These updates help you lower the chance of security incidents, make audits less painful, and remove day-to-day operational friction. Here’s what you can do now to tighten security and compliance.&lt;/p&gt;</description>
    </item>
    <item>
      <title>How Hippo Achieved SOC 2 on AWS in About a Month</title>
      <link>/case-studies/hippo-case-study/</link>
      <pubDate>Sat, 30 Aug 2025 00:00:00 +0000</pubDate><author>info@fivexl.io (FivexL)</author>
      <guid>/case-studies/hippo-case-study/</guid>
      <description>A real-world case study: how Hippo built HIPAA-compliant AWS infrastructure and passed SOC 2 certification in about a month using FivexL&amp;rsquo;s RightStart multi-account setup and SSO Elevator for just-in-time access.</description>
    </item>
    <item>
      <title>HIPAA-Ready AWS Infrastructure from Day Zero: Clearway Health Case Study</title>
      <link>/case-studies/clearway-health-case-study/</link>
      <pubDate>Mon, 09 Dec 2024 00:00:00 +0000</pubDate><author>info@fivexl.io (FivexL)</author>
      <guid>/case-studies/clearway-health-case-study/</guid>
      <description>FivexL helped a U.S. pharmacy services company build a strong and secure foundation with AWS RightStart for future development and rapid scaling.</description>
    </item>
    <item>
      <title>How AFT Can Help You Achieve Compliance</title>
      <link>/blog/aft-for-compliance/</link>
      <pubDate>Thu, 07 Nov 2024 00:00:00 +0000</pubDate><author>info@fivexl.io (FivexL)</author>
      <guid>/blog/aft-for-compliance/</guid>
      <description>Introduction to AWS Control Tower and AWS Account Factory for Terraform (AFT) and how it can help you achieve compliance</description>
    </item>
  </channel>
</rss>
