Infrastructure Engineering
Infrastructure Compliance (PCI, SOC 2)
Infrastructure compliance covers the technical security controls, monitoring, and documentation required by standards like PCI DSS and SOC 2, the certifications that prove your infrastructure is actually secure, not just that a policy document says it should be. Trellist supports infrastructure compliance work for organizations that need these controls built into their systems, not bolted on right before an audit.
What we do
PCI DSS Compliance Support
Implementing and maintaining the technical controls required for payment card data environments.
Tools we work with
AWS for segmented cardholder data environments
Microsoft Azure for segmented cardholder data environments
Cloudflare for web application firewall and edge protection for payment pages
SOC 2 Readiness & Support
Building the security controls and evidence collection processes SOC 2 audits require, across the relevant Trust Services Criteria.
Tools we work with
Vanta for control tracking and automated evidence across the Trust Services Criteria
Infrastructure Security Configuration
Hardening cloud and on-premise infrastructure against the specific control requirements each standard demands.
Tools we work with
Terraform for hardened configuration kept as version-controlled code
AWS for Security Hub, IAM, and encryption settings
Microsoft Azure for Defender for Cloud and Azure Policy
Continuous Monitoring & Evidence Collection
Building the ongoing logging and monitoring infrastructure both PCI DSS and SOC 2 require as standing practice, not a pre-audit scramble.
Tools we work with
Datadog for centralized logging, monitoring, and alerting
Vanta for continuous evidence collection between audits
Audit Support & Documentation
Preparing the technical documentation and evidence your certification auditor will actually need.
Tools we work with
Confluence for control narratives and runbooks your auditor can follow
PCI DSS Compliance Support
Implementing and maintaining the technical controls required for payment card data environments.
Tools we work with
AWS for segmented cardholder data environments
Microsoft Azure for segmented cardholder data environments
Cloudflare for web application firewall and edge protection for payment pages
SOC 2 Readiness & Support
Building the security controls and evidence collection processes SOC 2 audits require, across the relevant Trust Services Criteria.
Tools we work with
Vanta for control tracking and automated evidence across the Trust Services Criteria
Infrastructure Security Configuration
Hardening cloud and on-premise infrastructure against the specific control requirements each standard demands.
Tools we work with
Terraform for hardened configuration kept as version-controlled code
AWS for Security Hub, IAM, and encryption settings
Microsoft Azure for Defender for Cloud and Azure Policy
Continuous Monitoring & Evidence Collection
Building the ongoing logging and monitoring infrastructure both PCI DSS and SOC 2 require as standing practice, not a pre-audit scramble.
Tools we work with
Datadog for centralized logging, monitoring, and alerting
Vanta for continuous evidence collection between audits
Audit Support & Documentation
Preparing the technical documentation and evidence your certification auditor will actually need.
Tools we work with
Confluence for control narratives and runbooks your auditor can follow
Our approach
We start by assessing your infrastructure against the specific requirements of PCI DSS, SOC 2, or both. From there we implement the technical controls and monitoring these standards require, build the evidence collection processes your auditor will need, and keep the controls running on an ongoing basis, since both standards require continuous compliance, not a one-time fix.
Signs you need this
- Your last PCI or SOC 2 audit involved a scramble to assemble evidence that should have been collected continuously.
- Security controls exist on paper but aren’t consistently enforced or monitored in your actual infrastructure.
- You’re pursuing SOC 2 or PCI DSS for the first time and aren’t sure what technical controls it actually requires.
- Your compliance posture hasn’t been reassessed since your infrastructure meaningfully changed.
What you’ll gain
- Technical controls that are actually built into your infrastructure, not documented and hoped for.
- Continuous evidence collection instead of a stressful pre-audit scramble.
- A clearer path through your first PCI DSS or SOC 2 audit.
- Compliance posture that holds as your infrastructure evolves, not a snapshot that goes stale.
How it compares
Trellist builds the technical controls and continuous monitoring PCI DSS and SOC 2 actually require into your infrastructure. That’s different from a compliance consultancy that focuses on policy documentation without the engineering depth to implement the underlying controls, and different from a pre-audit scramble, which both standards are specifically designed to catch.
FAQ
Do you replace our audit firm?
No. PCI DSS and SOC 2 require an independent qualified assessor or auditor; we build and maintain the technical controls and evidence your auditor will assess.
Can you support both PCI DSS and SOC 2 at once?
Yes. There’s real overlap in the underlying technical controls, and we scope engagements to cover both efficiently where that overlap exists.
Is this a one-time project or ongoing?
Both standards require continuous compliance, not a point-in-time certification; most engagements include ongoing monitoring and support to keep controls in place between audit cycles.
Why Trellist
We build the actual technical controls these standards require into your infrastructure, with the engineering depth to maintain them, not just document them.
Signs you need this
- Your last PCI or SOC 2 audit involved a scramble to assemble evidence that should have been collected continuously.
- Security controls exist on paper but aren’t consistently enforced or monitored in your actual infrastructure.
- You’re pursuing SOC 2 or PCI DSS for the first time and aren’t sure what technical controls it actually requires.
- Your compliance posture hasn’t been reassessed since your infrastructure meaningfully changed.
What you’ll gain
- Technical controls that are actually built into your infrastructure, not documented and hoped for.
- Continuous evidence collection instead of a stressful pre-audit scramble.
- A clearer path through your first PCI DSS or SOC 2 audit.
- Compliance posture that holds as your infrastructure evolves, not a snapshot that goes stale.
How it compares
Trellist builds the technical controls and continuous monitoring PCI DSS and SOC 2 actually require into your infrastructure. That’s different from a compliance consultancy that focuses on policy documentation without the engineering depth to implement the underlying controls, and different from a pre-audit scramble, which both standards are specifically designed to catch.
FAQ
Do you replace our audit firm?
No. PCI DSS and SOC 2 require an independent qualified assessor or auditor; we build and maintain the technical controls and evidence your auditor will assess.
Can you support both PCI DSS and SOC 2 at once?
Yes. There’s real overlap in the underlying technical controls, and we scope engagements to cover both efficiently where that overlap exists.
Is this a one-time project or ongoing?
Both standards require continuous compliance, not a point-in-time certification; most engagements include ongoing monitoring and support to keep controls in place between audit cycles.
Why Trellist
We build the actual technical controls these standards require into your infrastructure, with the engineering depth to maintain them, not just document them.
Ready for compliance that’s actually built into your infrastructure, not assembled right before an audit?
Let’s talk
We’re ready to listen
Tell us a little about yourself and our team will reach out to schedule a call.
Looking for a job? Visit our Careers section to see open roles.
Required
