Skip to content
ELIS / COMPLIANCE / Q1 2025 REF · ELIS-CMP-2025-Q1
§ 01 — Compliance Matrix

The controls, the dates, and the auditor — all in one place.

An auditor-grade reference of every framework ELIS Data & Cloud currently operates under. Built so your CISO, your external auditor, and your procurement officer can verify the same set of facts you verified against.

  • Frameworks5
  • Audits listed5
  • Last refresh04 Feb 2025
  • Owned byELIS Compliance Desk
§ 02 — Current attestation status

Current attestation status across five frameworks.

Each row is independently attested by the named audit partner and re-issued on a 12-month rolling cadence. The table below is the artifact your procurement team will forward internally — no marketing paraphrase, no rounding.

Framework Attestation status Last audit Next recertification window Audit partner Scope
SOC 2 Type II AICPA Trust Services Criteria Issued — no exceptions 15 Nov 2024 Oct – Dec 2025 Schellman & Co., LLC All five TSC: Security, Availability, Processing Integrity, Confidentiality, Privacy
HIPAA Security & Privacy Rules Attested — no findings 22 Sep 2024 Aug – Oct 2025 A-LIGN Covered Entity / Business Associate — ePHI handling across production & BAA-eligible workloads
PCI-DSS v4.0 Compliant — Level 1 04 Dec 2024 Nov 2025 – Jan 2026 Coalfire Federal Service Provider Level 1 — cardholder data environment & adjacent systems
ISO/IEC 27001 2022 revision Certified — Statement of Applicability v3.2 11 Jul 2024 Jun – Aug 2025 BSI Group America, Inc. ISMS across ELIS Data & Cloud, Inc. — all four offices; 114 Annex A controls applicable
FedRAMP Moderate Rev. 5 In active 3-Year refresh cycle 19 Mar 2024 Continuous monitoring; annual assessment Mar 2025 EY (Ernst & Young LLP) Moderate baseline — 323 controls; CSP authorization maintained
Source: ELIS Compliance Desk internal register. Last synchronized 04 Feb 2025. Request the evidence package →
§ 03 — The compliance desk

One engagement. One audit calendar. Five frameworks.

The traditional path to multi-framework compliance stacks five separate audit windows, five consulting contracts, and five sets of duplicate evidence collection onto the same engineering team. ELIS collapses that into a single in-house compliance desk, reporting to our VP of Information Security, with a unified audit calendar and a shared evidence vault.

When you sign a SOC 2 / HIPAA / PCI-DSS / ISO 27001 / FedRAMP engagement with us, you engage one team — not five. The same controls are mapped once, evidenced once, and tested across all five frameworks in a single observation window. Your auditors see a single register, not five.

Evidence reuse is the leverage. A working access-review control is tested by Schellman for SOC 2, by A-LIGN for HIPAA, by Coalfire for PCI-DSS, and by BSI for ISO 27001 — and the same screenshot, the same timestamp, the same approver list flows into all four reports. Mean audit-prep cost across our customers is reduced by roughly 60% versus running each framework independently.

The output your team gets is a single Compliance Posture Report updated weekly, with a per-framework dashboard, an open-finding list, and a recertification countdown — designed to be forwarded to your procurement, legal, and security teams without further interpretation.

01

Single audit calendar

One 12-month rolling cycle. All five recertifications sequenced so no quarter carries more than two concurrent audits.

02

Shared evidence vault

One immutable evidence store mapped once to all five control sets. Auditors read, never re-collect.

03

In-house desk

ELIS Compliance Desk reports to the VP of Information Security. No outsourced GRC analysts, no offshore scope.

04

Auditor-grade artifacts

Weekly posture reports, per-framework dashboards, open-finding lists — built to be forwarded without translation.

§ 04 — Continuous audit cadence

Our audit cycle, on a 12-month rolling cadence.

Map your procurement timeline against ours. Recertification is a recurring quarter, not a panic — every customer inherits the calendar above on day one of the engagement.

  1. 01 Weeks 1 – 4

    Evidence collection

    Automated and manual evidence harvested across all five frameworks into the shared vault. Control owners notified on miss.

    Continuous · Weekly sync
  2. 02 Months 2 – 9

    Type II observation window

    Controls operate under audit. Every exception is logged, dated, and tied back to a remediation ticket — never silently closed.

    ~270 days · live production
  3. 03 Months 10 – 11

    External audit

    Named independent auditor walks the evidence vault, samples controls, and issues the attestation report. No concurrent engagements.

    Schellman · A-LIGN · Coalfire · BSI · EY
  4. 04 Month 12

    Recertification & handoff

    Fresh attestation issued, register resealed, evidence vault rotated, and the cycle restarts. Customers receive the new report same day.

    0-day handoff · no coverage gap
§ 05 — Independent third-party attestation

Independently attested by the firms your procurement team already recognizes.

The compliance frameworks above sit on top of partner-tier attestations issued by AWS, Google Cloud, and Microsoft — verified directly on each partner locator.

Amazon Web Services

Premier Tier Partner

Held continuously since 2018. Carries 14 AWS Competencies including Financial Services, Healthcare, and Migration & Modernization.

Since 2018
Google Cloud

Service Partner of the Year — North America

Awarded at the Google Cloud Partner Summit, 2023. Verified live on the GCP Partner Locator under Managed Service Provider & Cloud Migration specializations.

2023 · ongoing
Microsoft

Azure Expert MSP

Re-certified for the fifth consecutive year in 2024. One of fewer than 100 firms worldwide to hold the Expert MSP designation.

5th consecutive year · 2024
The Wall Street Journal

Cloud 100 — Rising Stars

Featured on the WSJ Cloud 100 rising-stars list, 2022. Independent editorial selection; no fee for inclusion.

2022
  • Inc. 50002021 · 2022 · 2023 · 2024
  • G2 reviews4.9 / 5.0 across 412 verified reviews
  • ELIS Reliability IndexAnnual cloud-provider transparency benchmark since 2020
  • ELIS-Forge (OSS)38,000+ GitHub downloads
§ 06 — Frequently asked, before the page is forwarded

What your security and procurement teams will ask before forwarding this page internally.

Can we scope the engagement to a subset of the five frameworks?

Yes. Engagements commonly start with SOC 2 Type II + ISO 27001 and add HIPAA, PCI-DSS, or FedRAMP Moderate as the workload mix demands. The shared evidence vault is built once and reused, so adding a framework mid-engagement does not restart the audit clock.

Will our external auditor have read access to the evidence vault?

Yes — under NDA. Each engagement includes read-only auditor access to the relevant control slice, with timestamped evidence and an immutable audit trail. Your auditor receives the same view ELIS Compliance Desk uses internally; no parallel evidence set.

Do you cover multi-region workloads — EU, Canada, APAC — under the same attestations?

The attestations are issued against ELIS Data & Cloud, Inc. as the operating entity, with in-scope infrastructure across our four offices (Austin, Toronto, Berlin, Singapore) and the customer-deployed regions they support. Region-specific addenda (GDPR, PIPEDA, MAS TRM, IRAP) are handled as scoped engagements against the same control baseline.

What is your sub-processor disclosure process and how often is it refreshed?

A live sub-processor register is published to customer trust portals and refreshed within 5 business days of any change. New sub-processors trigger an opt-out window per your master agreement. The full list, with data residency per processor, is included in every Compliance Posture Report.

How are remediation findings handled between audit cycles?

Open findings are tracked in the weekly posture report with owner, severity, target close date, and audit-traceable evidence. Critical findings trigger an incident bridge within 4 hours; non-critical findings are reviewed in the standing weekly compliance review. No finding is closed without auditor-visible evidence.

What evidence do we receive, and in what format, at recertification?

Each recertification produces: the issued attestation letter (PDF), the auditor's full report (PDF, NDA-gated where required), the latest Compliance Posture Report, and a customer-facing summary one-pager. All delivered same-day via the trust portal and via signed email to your security contact.

Need the evidence package before the next procurement cycle?

Forward this page or book a 30-minute Architecture Review with a Principal Cloud Engineer. We will respond with the named audit partner's report within one business day, under NDA.