<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Compliance on PercussiveRepair.net</title><link>https://percussiverepair.net/tags/compliance/</link><description>Recent content in Compliance on PercussiveRepair.net</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Mon, 20 Nov 2023 00:00:00 +0000</lastBuildDate><atom:link href="https://percussiverepair.net/tags/compliance/index.xml" rel="self" type="application/rss+xml"/><item><title>Building a Platform We Weren't Allowed to Run</title><link>https://percussiverepair.net/posts/2023-11-20-building-a-platform-we-couldnt-run/</link><pubDate>Mon, 20 Nov 2023 00:00:00 +0000</pubDate><guid>https://percussiverepair.net/posts/2023-11-20-building-a-platform-we-couldnt-run/</guid><description>&lt;p&gt;Over the last few years a good chunk of my time at Okta has gone on compliance: PCI, GDPR and HIPAA, and then the US government programmes, FedRAMP Moderate, FedRAMP High and DoD IL4.&lt;/p&gt;&#10;&lt;p&gt;The lower levels are mostly about showing you do what you say you do. The higher levels also restrict who is allowed to do it. For the most sensitive environments, anyone operating the platform had to be a US citizen working on US soil.&lt;/p&gt;</description></item></channel></rss>