Compliance

Compliance hosting, built to order.

HIPAA, PCI DSS, SOC 2, CJIS or CMMC: we build the environment your framework asks for as a separate engagement, scoped and quoted on its own. Compliance hosting is not included in standard hosting plans.

  • Individually scoped & quoted
  • BAA signed with the engagement
  • DPA already in every agreement
  • SOC 1 & SOC 2 Type II audited datacenter

Managed hosting or a compliance engagement?

They’re different things, and knowing which one you need comes first.

Standard managed hosting

Every standard hosting plan

Managed hosting with security switched on by default, monitoring and patch management. What runs on each product.

  • Strong operational security, right for most business websites
  • Not a HIPAA, PCI DSS, SOC 2, CJIS, or CMMC compliant environment

Compliance engagement

Custom-engineered · individually scoped & quoted

A purpose-built environment on managed VPS or Virtual Dedicated Server infrastructure, designed around your framework’s controls from the start. Typical scope:

  • Dedicated infrastructure and isolation where your framework requires it
  • Role-based access, hardened configurations, private network segments and firewall policy
  • Event logging, access logs and audit trails to your retention and evidence requirements
  • Backup and disaster recovery designed to your framework
  • A BAA and a defined shared responsibility model, signed with the engagement

How an engagement works

We build these environments for healthcare, government, financial services and SaaS workloads.

Tell us your framework and workload

HIPAA, PCI DSS, SOC 2, CJIS, CMMC, GDPR or something else. We talk through what you run, what data it touches and what your auditors will ask for.

We scope it and quote it

You get a direct answer on what the environment involves, where the responsibility boundary sits and what it costs.

We build the environment and sign the paperwork

Isolation, access controls, logging and disaster recovery are designed to your controls. We sign a BAA with the engagement. Your DPA is already in force.

We run our side of the line

Our engineers run the infrastructure layer while your team runs the application, data and policy side, as set out below.

Who is responsible for what

Compliance is never one party’s job. This is where the line falls.

Blue Arctic

Infrastructure and network controls

  • Network-level firewall and DDoS protection
  • Server hardening and OS-level access control
  • Hardware isolation and dedicated tenancy options
  • Infrastructure-level logging, to the evidence requirements agreed in the engagement
  • A BAA signed with the engagement, and a DPA already in force

Physical security and access control at the building are run by the datacenter operator, under its own SOC 1 and SOC 2 Type II reports.

Your organization

Application logic, data handling and user access policies

  • Application-layer security and code practices
  • Data classification, encryption and retention policies
  • End-user authentication and access management
  • Internal policies, workforce training and procedures
  • Compliance program management and audit coordination
  • Third-party vendor assessments beyond hosting

Compliance questions

Are standard Blue Arctic plans HIPAA, PCI DSS or SOC 2 compliant?

No. Standard plans are not HIPAA, PCI DSS, SOC 2, CJIS, or CMMC compliant environments. Hosting on Blue Arctic does not by itself make your workload compliant with any framework. We build compliance environments as custom engagements and quote each one on its own.

Is Blue Arctic itself SOC 2 certified?

No. Blue Arctic holds no framework certification or SOC report of its own. The Tampa, FL datacenter has SOC 1 and SOC 2 Type II reports covering its physical and operational controls. Those reports belong to the datacenter operator. They are not a Blue Arctic product certification.

What does a compliance engagement cost?

Each one is scoped and quoted on its own. There’s no price list, because two frameworks rarely ask for the same controls and two auditors rarely ask for the same evidence. Tell us your framework and your workload, and we’ll tell you what the engagement involves and what it costs.

Will you sign a BAA or a DPA?

These are two different documents. A Data Processing Addendum already applies to every Blue Arctic account. It is part of your Master Service Agreement and it includes the Standard Contractual Clauses. You can read it now. A Business Associate Agreement is different. We sign BAAs as part of a compliance engagement, alongside a documented shared responsibility model.

Have compliance requirements?

Tell us your framework and your workload, and we’ll scope it with you.