Premier Tier Partner
Held continuously since 2018. Carries 14 AWS Competencies including Financial Services, Healthcare, and Migration & Modernization.
Since 2018An auditor-grade reference of every framework ELIS Data & Cloud currently operates under. Built so your CISO, your external auditor, and your procurement officer can verify the same set of facts you verified against.
Each row is independently attested by the named audit partner and re-issued on a 12-month rolling cadence. The table below is the artifact your procurement team will forward internally — no marketing paraphrase, no rounding.
| Framework | Attestation status | Last audit | Next recertification window | Audit partner | Scope |
|---|---|---|---|---|---|
| SOC 2 Type II AICPA Trust Services Criteria | ● Issued — no exceptions | 15 Nov 2024 | Oct – Dec 2025 | Schellman & Co., LLC | All five TSC: Security, Availability, Processing Integrity, Confidentiality, Privacy |
| HIPAA Security & Privacy Rules | ● Attested — no findings | 22 Sep 2024 | Aug – Oct 2025 | A-LIGN | Covered Entity / Business Associate — ePHI handling across production & BAA-eligible workloads |
| PCI-DSS v4.0 | ● Compliant — Level 1 | 04 Dec 2024 | Nov 2025 – Jan 2026 | Coalfire Federal | Service Provider Level 1 — cardholder data environment & adjacent systems |
| ISO/IEC 27001 2022 revision | ● Certified — Statement of Applicability v3.2 | 11 Jul 2024 | Jun – Aug 2025 | BSI Group America, Inc. | ISMS across ELIS Data & Cloud, Inc. — all four offices; 114 Annex A controls applicable |
| FedRAMP Moderate Rev. 5 | ● In active 3-Year refresh cycle | 19 Mar 2024 | Continuous monitoring; annual assessment Mar 2025 | EY (Ernst & Young LLP) | Moderate baseline — 323 controls; CSP authorization maintained |
The traditional path to multi-framework compliance stacks five separate audit windows, five consulting contracts, and five sets of duplicate evidence collection onto the same engineering team. ELIS collapses that into a single in-house compliance desk, reporting to our VP of Information Security, with a unified audit calendar and a shared evidence vault.
When you sign a SOC 2 / HIPAA / PCI-DSS / ISO 27001 / FedRAMP engagement with us, you engage one team — not five. The same controls are mapped once, evidenced once, and tested across all five frameworks in a single observation window. Your auditors see a single register, not five.
Evidence reuse is the leverage. A working access-review control is tested by Schellman for SOC 2, by A-LIGN for HIPAA, by Coalfire for PCI-DSS, and by BSI for ISO 27001 — and the same screenshot, the same timestamp, the same approver list flows into all four reports. Mean audit-prep cost across our customers is reduced by roughly 60% versus running each framework independently.
The output your team gets is a single Compliance Posture Report updated weekly, with a per-framework dashboard, an open-finding list, and a recertification countdown — designed to be forwarded to your procurement, legal, and security teams without further interpretation.
One 12-month rolling cycle. All five recertifications sequenced so no quarter carries more than two concurrent audits.
One immutable evidence store mapped once to all five control sets. Auditors read, never re-collect.
ELIS Compliance Desk reports to the VP of Information Security. No outsourced GRC analysts, no offshore scope.
Weekly posture reports, per-framework dashboards, open-finding lists — built to be forwarded without translation.
Map your procurement timeline against ours. Recertification is a recurring quarter, not a panic — every customer inherits the calendar above on day one of the engagement.
Automated and manual evidence harvested across all five frameworks into the shared vault. Control owners notified on miss.
Continuous · Weekly syncControls operate under audit. Every exception is logged, dated, and tied back to a remediation ticket — never silently closed.
~270 days · live productionNamed independent auditor walks the evidence vault, samples controls, and issues the attestation report. No concurrent engagements.
Schellman · A-LIGN · Coalfire · BSI · EYFresh attestation issued, register resealed, evidence vault rotated, and the cycle restarts. Customers receive the new report same day.
0-day handoff · no coverage gapThe compliance frameworks above sit on top of partner-tier attestations issued by AWS, Google Cloud, and Microsoft — verified directly on each partner locator.
Held continuously since 2018. Carries 14 AWS Competencies including Financial Services, Healthcare, and Migration & Modernization.
Since 2018Awarded at the Google Cloud Partner Summit, 2023. Verified live on the GCP Partner Locator under Managed Service Provider & Cloud Migration specializations.
2023 · ongoingRe-certified for the fifth consecutive year in 2024. One of fewer than 100 firms worldwide to hold the Expert MSP designation.
5th consecutive year · 2024Featured on the WSJ Cloud 100 rising-stars list, 2022. Independent editorial selection; no fee for inclusion.
2022Yes. Engagements commonly start with SOC 2 Type II + ISO 27001 and add HIPAA, PCI-DSS, or FedRAMP Moderate as the workload mix demands. The shared evidence vault is built once and reused, so adding a framework mid-engagement does not restart the audit clock.
Yes — under NDA. Each engagement includes read-only auditor access to the relevant control slice, with timestamped evidence and an immutable audit trail. Your auditor receives the same view ELIS Compliance Desk uses internally; no parallel evidence set.
The attestations are issued against ELIS Data & Cloud, Inc. as the operating entity, with in-scope infrastructure across our four offices (Austin, Toronto, Berlin, Singapore) and the customer-deployed regions they support. Region-specific addenda (GDPR, PIPEDA, MAS TRM, IRAP) are handled as scoped engagements against the same control baseline.
A live sub-processor register is published to customer trust portals and refreshed within 5 business days of any change. New sub-processors trigger an opt-out window per your master agreement. The full list, with data residency per processor, is included in every Compliance Posture Report.
Open findings are tracked in the weekly posture report with owner, severity, target close date, and audit-traceable evidence. Critical findings trigger an incident bridge within 4 hours; non-critical findings are reviewed in the standing weekly compliance review. No finding is closed without auditor-visible evidence.
Each recertification produces: the issued attestation letter (PDF), the auditor's full report (PDF, NDA-gated where required), the latest Compliance Posture Report, and a customer-facing summary one-pager. All delivered same-day via the trust portal and via signed email to your security contact.
Forward this page or book a 30-minute Architecture Review with a Principal Cloud Engineer. We will respond with the named audit partner's report within one business day, under NDA.