SOLUTIONS

Different industries.
Same structural problem.

Every regulated industry has its own framework dialect. The underlying need — a defensible control architecture, mapped, scored, and continuously evidenced — is the same everywhere. Below, four overlays we ship out of the box.

01 /Financial services

For risk teams who answer to two regulators before lunch.

Banking, insurance, and fintech compliance is the original use-case for structured control architecture. We ship overlays for the regimes that matter and a content team that tracks the consultations as they happen.

DORAPCI DSS 4SOX 404NYDFS Part 500FFIEC CATPRA SS 1/21CPS 234MAS TRM
  • DORA register of information. Pre-built schema for the EU-wide ICT third-party register, with quarterly export.
  • Operational resilience scenarios. Severe-but-plausible test library; results map to control gaps automatically.
  • Model risk attestation. SR 11-7 ready — model inventory, validation evidence, change history.
CASE · NORTHWIND BANK
“DORA went from a 14-month fire drill to a quarterly export. The register reads itself.”
Marielle Okafor
VP, INFOSEC · NORTHWIND BANK
−71%
DORA PREP HOURS
3wk
FROM SCRATCH TO LIVE
02 /Healthcare
CASE · HALBERD HEALTH
“Twelve hospitals, one BAA library, one HIPAA risk analysis that actually rolls up. The OCR audit prep that used to take a quarter now lives as a saved view.”
Daniel Yoon
CHIEF COMPLIANCE OFFICER · HALBERD HEALTH

HIPAA, on a timeline.

The §164.308(a)(1)(ii)(A) risk analysis is supposed to be a living document. Most aren't. Ours is. We model BAAs, ePHI flows, and safeguards as the same control graph everything else lives on.

HIPAA SecurityHIPAA PrivacyHITRUST CSF v1121 CFR Part 11FDA QSR42 CFR Part 2
  • BAA registry. Tier business associates, surface lapsing agreements, attach evidence to the link.
  • ePHI inventory. Map data flows to systems, systems to controls, controls to risks.
  • Breach response. 60-day notification clock starts on incident creation; tracked through to disposition.
03 /SaaS & technology

Your first SOC 2.
Your tenth.

Built for the company that just hired its first security engineer and the one running global ISO audits across eight legal entities. The mapping graph collapses duplicate work; the audit room replaces the email chain.

SOC 2 Type I/IIISO 27001:2022ISO 27701ISO 42001 (AI)CSA STARCCPA / CPRA
  • Customer trust portal. Public-facing trust page driven by your live control state. No more screenshot dumps.
  • Subprocessor disclosure. Versioned list, change subscription, jurisdiction tags.
  • AI governance overlay (ISO 42001). Model card library, risk classification, and the EU AI Act mapping for high-risk systems.
TRUST PORTAL · TRUST.PARALLAXLABS.COM
Parallax Labs · Trust

Live as of 2026·05·08 · 09:14 UTC

✓ ACTIVE
SOC 2 Type II
2026·02·14
✓ ACTIVE
ISO 27001:2022
2026·01·08
✓ ACTIVE
GDPR DPA
CONTINUOUS
↻ IN PROGRESS
ISO 42001
EXP. 2026·09
04 /Public sector
DEPLOYMENT

Three deployment modes for sensitive workloads.

  • FEDRAMP MODERATE · GOVCLOUD
    Multi-tenant SaaS in AWS GovCloud (US). FIPS 140-3 modules. CJIS Tier-3 datacenter chain.
  • DEDICATED · AGENCY-CONTROLLED
    Single-tenant, dedicated VPC, agency-managed KMS. Annual ATO support.
  • ON-PREM · CLASSIFIED
    Air-gapped install for IL5/IL6 environments. Quarterly content updates via signed package.

Compliance for environments where downtime is policy.

Federal, state, and defense customers run VigiliaRes in dedicated and on-prem deployments. Every module ships with the audit trail granularity their inspectors require, and a content library kept current with NIST RMF, CMMC, and CJIS revisions.

FedRAMP Mod / HighCMMC L2 / L3CJISNIST 800-53r5NIST 800-171r3StateRAMP

Find your overlay.
Or build your own with our team.