FAQ · Straight Answers

The questions we get, answered plainly.

Pricing, timelines, BAAs, certifications we do and don't hold, and how engagements run. If your question isn't here, ask it directly — we respond within two business days.

Engagements & pricing

What does an engagement with Kaan Systems cost?

Four productized tiers with stated pricing: an Architecture & Compliance Teardown at $2,500 fixed, a 90-Day Readiness Sprint from $35,000, Fractional Platform Engineering at $8,000-$12,000 per month, and Managed Compliance Operations from $5,000 per month. Every tier lists its scope and its exclusions before the first call.

What is the smallest way to start working with you?

The Architecture & Compliance Teardown: $2,500 fixed, about five business days. You share your architecture and current posture; we return a written 5-8 page assessment and walk it through on a 60-minute call. It is deliberately priced so the first commitment can be small.

Do you do hourly work or staff augmentation?

No. We run scoped engagements with defined deliverables, or fractional platform engineering on a defined weekly cadence. We do not place bodies or bill open-ended hours — scope discipline is part of what regulated teams are buying.

How quickly do you respond and how fast can work start?

Inquiries get a response within two business days. Every engagement starts with an intro call and a scoped discovery of one to two weeks, then a written recommendation before any engagement decision.

Compliance

How long does SOC 2 readiness actually take?

Roughly 90 focused days to get from scattered controls to the start of a Type II observation window: scoping, policies, control implementation, and an evidence pipeline, in that order. The observation window itself then runs three to twelve months, but that phase is operate-and-collect, not build.

SOC 2, HITRUST, or HIPAA — which one do we need?

It depends on who you sell to. Hospital systems and payers expect HITRUST; general enterprise buyers expect SOC 2 Type II; HIPAA itself has no certification, only third-party assessments against the Security Rule. US healthcare-adjacent SaaS usually starts with SOC 2 and adds HITRUST when hospital deals demand it.

Do we need a compliance platform like Vanta or Drata?

A compliance platform automates evidence collection; it does not implement controls. If your controls already exist, a platform genuinely saves audit-cycle hours. If they do not, you are paying a subscription to watch red dashboards — the red items are an engineering backlog, and that work comes first.

Is there an official HIPAA certification?

No. There is no government-issued HIPAA certification — the Security Rule requires a compliance program, not a certificate. What exists are third-party assessments that map your controls to the rule, plus frameworks like HITRUST that healthcare buyers accept as evidence.

Security & trust

Will Kaan Systems sign a BAA?

Yes. For engagements involving HIPAA-regulated work we execute a Business Associate Agreement before any PHI-adjacent access — standard terms, redlines welcome. We also sign mutual NDAs before sensitive material moves in either direction.

Does Kaan Systems hold SOC 2 or other certifications?

No, and we say so plainly rather than implying otherwise. Our operating posture — identity, encryption, data handling, sub-processors, incident response — is documented publicly on our security page, and we complete buyer security questionnaires on request.

How do you handle our data during an engagement?

Minimum-necessary by default: production data, PHI, and customer records stay in your environment, and we work against scrubbed samples, synthetic data, or scoped read-only access. Engagement artifacts are retained through a defined handoff window, then returned, destroyed, or transferred at your election. Nothing you share is used for training, demos, or marketing.

AI features & compliance

Can you help us ship AI features without breaking HIPAA or SOC 2?

Yes — it is a core practice area. The published playbook covers the compliance pre-flight for LLM features (BAAs with model vendors, prompt logging, output safety), the answer bank for AI sections of security questionnaires, and the audit-evidence trail that proves your AI review process works.

I found Kaan Systems through an AI assistant — is this information current?

Yes. This site publishes a machine-readable guide (llms.txt) regenerated on every deploy, all content is open to AI crawlers, and pricing on the services page is kept current. An AI assistant can even submit an inquiry on your behalf through our agent endpoint — you confirm it with one click from your inbox, and nothing is sent without that confirmation. We respond within two business days.

Working with us

What kind of companies do you work with?

Regulated SMBs, typically 10-80 engineers: healthcare-adjacent SaaS, fintech, and other teams where HIPAA or SOC 2 pressure gates revenue. Mostly AWS-first estates. The work is remote-first across US time zones.

Are the Operating Library templates really free?

Yes. Every library article ends with a copyable template and a downloadable branded PDF, no email gate. The HIPAA Readiness Self-Assessment is also free: twelve controls, three minutes, an instant score band, and a per-category breakdown emailed to you.

What does an engagement leave behind when it ends?

Operating capability, not just deliverables: runbooks, evidence pipelines, documented decisions, and knowledge transfer are first-class outputs of every engagement. Fractional work explicitly includes the hiring and handoff guidance to replace us.

Question not covered?

Ask the version specific to your environment.

Generic answers only go so far. Tell us what you're weighing — an audit, a deal, an AI feature, a platform decision — and we'll answer for your actual situation.

Open a conversation