Building a Secure Client Document Vault Your Accounting Firm Can Defend

Most accounting-firm document vaults do not fail at the bucket. They fail at the edges: a download link that outlives the engagement, a KMS key policy as wide as the bucket policy, a retention lock that cannot be undone, and an audit trail nobody switched on. Six failure families, and the control that closes each.

Continue ReadingBuilding a Secure Client Document Vault Your Accounting Firm Can Defend

As-Planned vs As-Built Analysis: Building a Platform That Survives Cross-Examination

Most as-planned vs as-built analysis compares the baseline to the last P6 update and calls the result an as-built. It isn't one. This is how to build the data layer underneath a delay analysis: versioned XER ingestion, activity identity across renumbering, a first-appearance table that proves when every actual date entered the record, calendar-safe float, and record linking that proposes candidates instead of asserting cause.

Continue ReadingAs-Planned vs As-Built Analysis: Building a Platform That Survives Cross-Examination

HIPAA Compliance on AWS: The Gaps That Pass Every Security Check

A working engineer's guide to HIPAA compliance on AWS, organised by the gap between the control you configured and the obligation you actually carry. Covers BAA account scope, the eligible services list as a contract boundary, KMS key policy versus the encryption checkbox, what "six years" really applies to, backup and restore scope, and the subprocessor chain nobody inventories.

Continue ReadingHIPAA Compliance on AWS: The Gaps That Pass Every Security Check