Engineering under compliance
Shipping inside regulated environments — HIPAA, FedRAMP and the architecture decisions those constraints force.
What Changed in the FedRAMP 2026 Rules
Teams get told to collect FedRAMP evidence on AWS with no map attached. The controls are published; what is missing is the link between an obligation and the call that proves it.
6 August 2026 · 3 min read
HIPAA-Compliant Architecture on a Startup Budget
HIPAA compliance is usually described as a procurement problem. Most of what matters is a handful of architecture decisions that are cheap early and close to impossible to retrofit.
30 July 2026 · 4 min read