skip to content
$empowered.guru

Legal · regulatory

Regulatory & Industry Coverage.

What regulated industries we support, what additional paperwork each regime requires, and what we will not touch.

// scope

This page describes the additional contractual and operational commitments we accept for engagements that involve regulated data. Each regime requires its own paperwork, which we negotiate as an addendum to the MSA. None of this is legal advice; we recommend you involve your own counsel for material regulated-data questions.

Last updated: August 16, 2026

1. Our approach

We are a small consultancy. We do not claim broad regulatory certifications (HITRUST, PCI QSA, FedRAMP Moderate). What we do claim:

  • Architectural support for the controls required by each regime (encryption, access control, logging, segmentation).
  • Willingness to enter the paperwork each regime requires (BAA, GLBA addendum, FERPA addendum, DFARS clause).
  • Honest disclosure of where you will need a different vendor for the parts that need a formal attestation we do not hold.

For regimes that require a third-party attestation (PCI-DSS Level 1, FedRAMP Moderate, HITRUST r2), we either partner with an attestation-ready vendor or recommend you host the regulated component on an already-attested platform.

2. HIPAA (health and life sciences)

We support HIPAA-regulated work. We will sign a Business Associate Agreement (BAA) covering PHI we process on your behalf.

Architectural commitments

  • Encryption of PHI at rest (AES-256) and in transit (TLS 1.2+).
  • Role-based access control with quarterly access review.
  • Audit logging of every read/write of PHI.
  • Breach notification to you within 48 hours of confirmation, per the BAA.
  • Workforce confidentiality training for personnel with PHI access.
  • Where you request it, on-prem or single-tenant inference only. No public frontier models.

What we will not do

  • We do not claim HITRUST certification.
  • We will not act as your HIPAA-covered entity or business associate for medical-device or clinical-decision-support workloads that require FDA oversight.

3. GLBA (financial services)

We support work subject to the Gramm-Leach-Bliley Act (consumer financial data). We will sign a GLBA addendum covering NPI we process on your behalf.

  • We treat NPI as confidential client material under our NDA and DPA.
  • We implement the Safeguards Rule elements (access controls, encryption, monitoring, training, incident response).
  • We will not transmit NPI to a public frontier model unless the SoW expressly permits it.

4. SOX (public-company controls)

For issuers subject to Sarbanes-Oxley § 404, we support the engineering side of IT general controls (ITGCs) and automated application controls (ITACs) that your auditor will test:

  • Change-management evidence (commit hash → pull request → review → deployment timestamp).
  • Privileged-access logs.
  • Separation-of-duties on production deploys (no single individual can merge and deploy).
  • Quarterly user-access reviews with documented evidence.

We are not your auditor and we do not opine on the design effectiveness of your controls; your auditor does that. We provide the evidence they need.

5. FERPA (education)

We support work subject to FERPA (student education records). We treat education records as confidential client material and will sign a FERPA addendum designating us as a "school official" with a legitimate educational interest, where the institution requires it.

6. PCI-DSS (cardholder data)

For PCI-DSS scope, we recommend you do not put cardholder data on systems we operate. We integrate with Stripe (our subprocessor) so we never see primary account numbers (PAN); what we receive is the tokenized last-four and brand. If your engagement genuinely requires PAN handling, we partner with a PCI Level 1 service provider; we do not operate one ourselves.

7. CMMC / DFARS (defense industrial base)

For work subject to CMMC (Cybersecurity Maturity Model Certification) and DFARS 252.204-7012, we operate as a subcontractor. We will:

  • Sign the DFARS clause provided by the prime.
  • Implement NIST SP 800-171 Rev. 2 controls appropriate to the level you require (typically Level 2).
  • Provide a System Security Plan (SSP) and Plan of Action & Milestones (POA&M) for the scope we operate.
  • For Level 3 (CUI), coordinate with a C3PAO for assessment.

8. FedRAMP / IL5 (federal)

We are not a FedRAMP-authorized service provider. For federal workloads, we recommend one of the following:

  • Deploy the engagement on your FedRAMP-authorized platform (e.g., GovCloud, Azure Government, GCP Gov). We operate the workload on top.
  • Engage us in a code-review / advisory role only; the federal customer hosts the system.

For IL5-sensitive workloads, we are not the right primary contractor; we can serve as a subcontractor under a FedRAMP Moderate or High provider.

9. GDPR / UK GDPR (EU and UK)

For personal data of EU or UK residents, our DPA applies, with the EU SCCs and the UK Addendum as applicable. Where you are a controller established in the EU/UK, we are your processor. Cross-border transfers use the mechanisms in the DPA.

10. Other PII regimes

We also support work subject to:

  • CCPA / CPRA (California).
  • Colorado CPA, Virginia CDPA, Connecticut CTDPA, Utah UCPA, and other US state privacy laws.
  • PIPEDA (Canada) and Law 25 (Quebec).
  • LGPD (Brazil), PDPA (Singapore and Thailand), PIPL (China, subject to additional diligence).
  • POPIA (South Africa), Privacy Act (Australia), NZ Privacy Act (New Zealand).

For regimes where local data-residency is mandatory, we deploy the engagement in the required region and document the controls in the SoW.

11. What we will not touch

  • Illicit content (CSAM, content that violates U.S. sanctions, content that would cause us to lose safe-harbor protection).
  • Medical-device software subject to FDA premarket review (Class II/III).
  • Federal IT systems that require us to be a FedRAMP-authorized service provider (we can subcontract, but not be prime).
  • Casino gaming or sports betting under regimes that require a state-specific license we do not hold.
  • Weapons systems, weapon design files, or any ITAR-controlled technical data we are not licensed to receive.

12. How to add a BAA / addendum

Email compliance@empowered.guru with the regime (HIPAA, GLBA, FERPA, etc.) and the engagement name. We will respond within 2 business days with a draft addendum or with an honest "we are not the right vendor for this" if that is the answer.

13. Contact

Compliance: compliance@empowered.guru. Legal: legal@empowered.guru.