Discourse at the intersection of technology, compliance, and federal policy.
Curated dinners, on-demand sessions, and a resource library for the people building federal technology. New programming is on the way.
From first principles to deep cuts
SOC 2 Type I vs Type II: What the Difference Means for Your Timeline
The distinction is not rigor, it is time. What each report asserts, why the observation period cannot be compressed, and which one your buyers will actually accept.
ISO 27001 or SOC 2: How to Choose When a Customer Asks
One certifies a management system, the other is an auditor’s opinion on your controls. How to tell which your buyer actually needs, and what it costs to end up holding both.
What the EU AI Act Requires of Companies Outside the EU
The Act reaches organizations with no European entity. Which roles and risk tiers apply, what the 2026 amendments moved, and what the deferral did not cover.
ISO 42001 and the Emerging Shape of AI Management Systems
What an AI management system standard actually requires, how certification audits work, and where ISO 42001 sits against the EU AI Act and the NIST AI RMF.
FedRAMP Authorization Paths: Agency Sponsorship and the Alternatives
Authorization and an agency ATO are not the same thing. How the sponsored route compares to the 20x path, and what holds true whichever one you take.
HIPAA Security Rule Obligations for Technology Vendors
Business associates carry direct statutory obligations, not contractual ones. What the Security Rule requires, what "addressable" really means, and where the 2025 proposed update stands.
The table, set
Tech & Policy Dinner
An evening for builders, compliance leaders, and policy voices shaping technology regulation. Real conversation over a long table.
In the studio
Sessions in production.
Our first on-demand sessions are being filmed. Check back soon.
Live discourse
None for now.
We’re lining up our first sessions. Check back soon.