Security · Regulation · Compliance
AI security and regulation, built to be shown
Security and regulation are converging on one demand: prove it. The work here is built for that world — local-first and data-sovereign, secure by construction, and governed so every action is lawful, explainable, reversible, and evidenced on demand. For teams shipping AI into HIPAA, PCI-DSS, GDPR, and the EU AI Act.
The question isn't "can the AI do it?" — it's can you show what it did, prove it was lawful, and undo it?
A regulator calls on a Tuesday. Who owns the risk in the system that failed, what control was supposed to treat it, where is the evidence it actually worked, and when did the board last look. An organization either has those answers within reach or it does not — and the distance between the two is the whole game. The systems built and studied here treat that chain of evidence as the product, not an afterthought.
The frame
Four surfaces of technology responsibility
Read the study →Lawful
Do we meet the statutory and contractual obligations that govern our data and systems? Owned by Legal, Compliance, and the DPO.
Secure
Are confidentiality, integrity, and availability protected against credible threats? Owned by the CISO and Security Engineering.
Ethical
Are outcomes fair, transparent, and open to human oversight — especially where systems decide about people? Owned by Product, Risk, and the AI board.
Accountable
Is ownership clear, and can every claim above be evidenced on demand? Owned by the Board, Executive, and Internal Audit.
Flagships
The frame, and the systems that live inside it
Technology Responsibility
A study of the duty to build and run technology that is lawful, secure, ethical, and accountable — mapping the regulatory lattice (GDPR, NIST CSF 2.0, the EU AI Act, SOC 2, ISO 27001) to the controls that satisfy it, with a maturity model and breach-clock realities.
REEF
Governed network defense: a named fleet of sensors reports to an E-2 Hawkeye AWACS that fuses corroborating signals into one high-confidence card. The Bouncer sees it, explains it, proposes the fix — and acts only on your approval, every change PIN-gated, backed up, and reversible.
Why it fits
Local-first is a data-governance strategy
Data never leaves the box
MAX3, REEF, and FeedHacker run entirely on-premise. No third-party processor, no cloud egress of PII/PHI — the smallest possible breach surface and the simplest possible data-residency story.
Auditable by construction
Actions are logged with provenance and rationale. The evidence that satisfies an auditor falls out of operating the system, not reconstructed under pressure after an incident.
Reversible & approval-gated
Changes are proposed, not imposed — PIN-gated, backed up, and reversible. Automation stays inside human authority.
Built from real regulated work
Grounded in 25+ years across a $3.1B multi-brand health plan and Series A–C EHR/RCM systems — patterns that survived real audits, not whiteboard theory.
Field notes
Compliance & security writing
See all security writing →- Technology Responsibility: A Compliance and Security StudyStudy · Lawful · Secure · Ethical · Accountable
- The README Is the PayloadAgentic AI · Threat brief & defense design
- The 9-Layer Agentic AI Stack: How Modern Organizations Build Run and Secure AI Agents at ScaleAgentic AI · Build, run & secure agents
- The Data Never Leaves the BoxMAX3 · Local-first compliance
- Navigating the Complexities of PCI ComplianceCompliance · PCI-DSS
- The Crucial Role of HIPAA in Healthcare Software DevelopmentHealthcare · HIPAA
- The Promise of AI in Healthcare Transformation from data to diagnosis.Healthcare
- The Untapped Potential of Software Developers in Improving Patient Outcomes pub 3/27Healthcare
- Unlocking Healthcare Data: The Intersection of HL7, FHIR, and HIPAA ComplianceHealthcare · HL7 / FHIR / HIPAA
- Unmasking Healthcare Costs- The Urgent Need for TransparencyHealthcare
- What Startups and Multi-Billion Healthcare Enterprises Can Learn From Each OtherHealthcare
- Wiring the Clinical RecordHealthcare · Clinical data
- From Data Revolution to Data Protection: Safeguarding PII and PHI in TechnologyData privacy · PII & PHI
- Securing the Future: Technology's Role in Data Privacy ComplianceData privacy
Engage
Building AI where the rules are real?
If you're bringing agents or automation into a regulated environment — HIPAA, PCI, GDPR, the EU AI Act — and it has to survive an audit, that's the work.
This site: HTTPS only · no third-party trackers · no analytics cookies · security.txt