Sign in Get early access
Now onboarding design partners · FTC Safeguards · HIPAA · NIST CSF · SOC 2 · CCPA · CTDPA

Continuous compliance for the companies the big firms forgot about.

CYCONFI is the vCISO SaaS platform for companies that need FTC Safeguards, HIPAA, NIST CSF, SOC 2, or state privacy law readiness — without a $250k CISO, a $50k Big 4 engagement, or a compliance spreadsheet you dread opening.

AWS us-east-1 SOC 2 Type II (in progress) Practitioner-built
cyconfi · gap-analysis · ftc-safeguards
cyconfi@acme-auto:~$ run gap-analysis --framework ftc-safeguards
→ Analyzing 23 controls · 4 policies · 2 risk assessments
→ AI reviewing against 16 CFR Part 314 requirements...

passDesignated qualified individual — documented
passAnnual board reporting — scheduled
gapEncryption policy — missing data-at-rest scope
critMFA — not documented for customer data access
gapIncident response — last tested 14 months ago
todoVendor risk assessment — 3 of 8 pending

→ 18 of 23 controls compliant (78%)
2 critical gaps · 3 policy gaps · 5 open action items
Generated remediation plan · est. 12 hours to Ready for Audit
Native support for
FTCSafeguards Rule
HIPAASecurity Rule
NISTCSF 2.0
SOCSOC 2 Type II
CCPACCPA / CPRA
CTCT Data Privacy Act
+4more

Your three options for compliance today are all bad.

If you're a 5-to-500 person company under FTC Safeguards, HIPAA, or trying to land enterprise deals that require SOC 2, you've felt this. Here's the standard menu:

Option A · $250,000/yr
Hire a full-time CISO

Great if you're a 500-person company with a real security team underneath them. Total overkill for a 30-person auto dealership.

Costs more than the FTC fine you're trying to avoid.
Option B · $25–50k/engagement
Hire a Big 4 firm

They show up, run a week of interviews, hand you a beautiful 80-page PDF, and leave. Then frameworks change, you have new vendors, and the PDF is stale in 3 months.

Compliance isn't a document. It's a state you have to maintain.
Option C · your weekends
The compliance spreadsheet

A Google Sheet with 200 rows, color-coded green/yellow/red, maintained by whoever cares most. Usually the same person who also fixes the WiFi.

One resignation and your audit trail is gone.
Option D · starting at $149/month
CYCONFI — compliance as a continuous platform

Framework-native workflows, AI-assisted gap analysis, auto-updating control libraries, and the policies you need — running as a SaaS you can actually maintain. Built by practitioners, not former auditors.

The fourth option

From blank to audit-ready in four phases.

No 80-page consulting deliverables. No open-ended engagements. A structured workflow that gets you to a defensible compliance posture, then keeps you there.

Scope & intake

Answer a 30-minute questionnaire. CYCONFI infers which frameworks apply to your business — FTC Safeguards, HIPAA, NIST, SOC 2 — and scopes the applicable controls.

AI gap analysis

Upload your existing policies, vendor contracts, and assessments. Claude analyzes them against framework requirements and flags gaps with severity and citations.

Guided remediation

For each gap, CYCONFI generates a fix: policy language, implementation steps, or a workflow task. Approve, customize, or delegate. No blank-page problem.

Continuous monitoring

Annual attestations, quarterly risk reviews, expiring controls, new employees, new vendors — all tracked. Auditor-ready export on demand.

Everything a vCISO does — packaged as software.

AI gap analysis that cites the regulation.

Upload your policies, procedures, and evidence. Claude reads them against the framework text — 16 CFR Part 314 for FTC, 45 CFR 164 for HIPAA, the Trust Services Criteria for SOC 2 — and flags gaps with paragraph-level citations. Every finding links back to the source.

Claude Opus 4.7 Zero data retention Citation-backed
acme-auto/policies/encryption-v2.pdf Analyzing
crit
Policy doesn't specify encryption for customer data at rest.
→ 16 CFR § 314.4(c)(3)
high
MFA mentioned only for admin accounts, not all customer-data access.
→ 16 CFR § 314.4(c)(5)
med
Annual testing cadence defined; last test exceeded 12 months.
→ 16 CFR § 314.4(d)
pass
Designated Qualified Individual clearly identified.
→ 16 CFR § 314.4(a)

Policy library & generator

50+ pre-written, framework-mapped policies. Customize variables, generate a signed PDF, route for e-sig. No more ChatGPT-plus-copy-paste.

50+ policies E-signature

Control & evidence mgmt

Every control mapped to evidence. Expiration tracking. Auditor-view with one-click export. No more scavenging for screenshots at audit time.

Evidence vault Expiration alerts

Risk register + quarterly assessment

Inherent vs. residual risk scoring. Quarterly risk review workflows. Auto-generated board-ready summaries. The risk assessment framework your framework already requires.

Inherent / residual Quarterly cadence Board summaries

Vendor & BAA tracker

Every sub-processor, its risk tier, its BAA/DPA status, and its renewal date. Proof-of-vendor-diligence that holds up in audit. Required by FTC Safeguards. Required by HIPAA. Usually a Google Doc.

BAA tracking Risk tiering Renewal alerts

Staff training & attestation

Annual security awareness training, per-role attestations, completion tracking. The thing auditors always ask for. Now evidenced automatically.

Annual training Attestations

Incident response & breach wf

Pre-built IR playbooks by framework. Breach notification timers (HHS, state AG, clients). Tabletop exercise templates. Tested-on-a-timer.

IR playbooks Notification timers

Auditor-ready exports

One click to produce a framework-specific audit package: control matrix, evidence, policy set, attestation log, risk register. In the format auditors actually expect.

SOC 2 format HIPAA 164.316 log

Multi-tenant for MSPs, MSSPs, and vCISOs

Run CYCONFI across your whole client book. Roll up status across organizations. Tag clients by framework. White-label available on the Partner tier. The platform you wish your compliance practice already had.

Unlimited clients Roll-up dashboards White-label (Partner) Partner co-branding

Six launch frameworks. More every quarter.

We don't try to be all frameworks to all people. The ones we support are mapped at the control level, with framework-specific workflows — not a generic questionnaire you're forced to interpret.

FTC Safeguards Rule
16 CFR Part 314 · as amended 2023
Our wedge

The rule non-banking financial institutions (including auto dealers) have been scrambling to implement since the 2023 amendments. Nine required elements including the designated Qualified Individual, MFA, encryption, incident response testing, and annual board reporting. We built CYCONFI here first because nobody else was solving it for companies under 100 employees.

Controls
23
Policies
12
Time to ready
2-4wk
HIPAA Security Rule
45 CFR Part 164 · Subparts C & E
Ready

Administrative, physical, and technical safeguards for PHI. BAA tracking, risk analysis, workforce sanctions, access management, audit controls, and the documentation retention requirements of § 164.316. Built for solo practitioners, group practices, and MSPs serving healthcare clients.

Safeguards
54
Policies
18
Time to ready
3-6wk
NIST CSF 2.0
Cybersecurity Framework v2.0 · 2024
Ready

The six-function framework (Govern, Identify, Protect, Detect, Respond, Recover) as the umbrella over your whole program. Tier-based maturity, category and subcategory scoring, profile comparisons. Useful as a standalone program or as the backbone that cross-references everything else.

Categories
23
Subcategories
106
Maturity tiers
4
SOC 2 Type II
Trust Services Criteria · AICPA 2017
Beta

Security (required), plus any of Availability, Processing Integrity, Confidentiality, or Privacy as you need them. Evidence collection built around the actual observation periods auditors look for. Aimed at the SMBs being asked for SOC 2 by their first enterprise customer — not at billion-dollar SaaS companies.

Common criteria
33
Policies
24
Observation
6-12mo
CCPA / CPRA
Cal. Civ. Code § 1798.100 et seq. · CPRA amendments
Ready

California's consumer privacy law, as amended by the CPRA. Covers every consumer right (access, deletion, correction, opt-out of sale/sharing), the new obligations around sensitive personal information, required contractual terms with service providers, and the risk assessments the CPPA increasingly expects. If you have California customers, this applies to you — even if you're not based there.

Consumer rights
7
Policies
9
Time to ready
2-3wk
CT Data Privacy Act
CTDPA · Conn. Gen. Stat. § 42-515 et seq.
Ready

Connecticut's comprehensive privacy law, effective July 2023. Applies to controllers processing 100,000+ consumers' data or deriving 25%+ revenue from data sales on 25,000+ consumers. Consumer rights, data protection assessments for high-risk processing, required privacy notices, and universal opt-out mechanism recognition. We cover CTDPA natively because it's one of the stricter state regimes — if you're compliant here, you're close on most other state privacy laws.

Consumer rights
5
Policies
8
Time to ready
2-3wk

CYCONFI is built for the underserved middle.

You're too small for Big 4, too serious for a spreadsheet, and too busy to hire a CISO. You have real compliance obligations — and the first time you failed to meet one properly wasn't on purpose.

Auto dealerships

Subject to FTC Safeguards since 2023. Fines start at $50k and scale fast. Most haven't designated a Qualified Individual. We start here.

FTC Safeguards · NIST CSF
Healthcare practices

Solo practitioners, group practices, and MSPs with healthcare clients. HIPAA Security Rule compliance without a $40k consulting engagement.

HIPAA · HITECH · State
SaaS pursuing SOC 2

Your first enterprise customer is asking for it. You don't need Vanta's feature set or pricing — you need a defensible Type I report in under 6 months.

SOC 2 · ISO 27001
MSPs and vCISOs

Run CYCONFI across your entire client book. White-label on the Partner tier. Add margin to your compliance services without hiring a senior analyst.

Multi-tenant · White-label

Pay for scope, not seat counts.

Transparent tiers. No "contact sales" for starter plans. Move up as your compliance footprint grows. All tiers include AI gap analysis, policy library, and auditor-ready exports.

Starter
One framework. One company. Get to audit-ready.
$149 /month
billed annually · $179/mo monthly
  • 1 framework of your choice
  • Up to 10 users
  • AI gap analysis (25/mo)
  • Policy library + generator
  • Risk register
  • Vendor & BAA tracker
  • Evidence vault (5 GB)
  • Auditor-ready exports
  • Email support
Request early access
Scale
For complex programs with audit pressure.
$999 /month
billed annually · $1,199/mo monthly
  • Unlimited frameworks
  • Unlimited users
  • Everything in Growth, plus:
  • SSO / SAML
  • Advanced access controls
  • Custom policy templates
  • Evidence vault (500 GB)
  • Quarterly review with our team
  • SLA & dedicated Slack channel
  • Phone support
Book a demo
Partner
For MSPs, MSSPs, and vCISO practices.
Custom
based on client count
  • Unlimited client tenants
  • Unlimited users per tenant
  • Everything in Scale, plus:
  • Multi-tenant roll-up dashboard
  • White-label (your brand)
  • Partner co-branded materials
  • Revenue share on referrals
  • Quarterly partner sync
  • Dedicated partner success
  • Phone + partner Slack
Talk to partnerships

How CYCONFI compares to what you're doing today.

Capability
CYCONFI
Full-time CISO
Big 4 PDF
Spreadsheet
Cost (year 1)
$1.8k–$12k
$250k+
$25–50k
Free-ish
Time to ready
2-6 weeks
3-6 months
2-4 months
Indefinite
Framework-native workflows
Yes
Depends
Static
No
AI-assisted gap analysis
Yes
No
No
No
Continuous monitoring
Yes
Yes
No
Manual
Auditor-ready export
1-click
Manual
Initial only
Painful
Works if someone quits
Yes
No
Yes
No
Auto-updates when frameworks change
Yes
Depends
No
No

Compliance shouldn't cost more than the fine you're trying to avoid.

Join the beta cohort. We'll walk through your framework obligations, show you what CYCONFI looks like against a real compliance program, and give you a written timeline to audit-ready.