Healthcare & public benefitsSafeguards across complex program boundaries
Security and privacy decisions involving eligibility, enrollment, claims, provider, constituent, and program data; cloud and SaaS boundaries; third-party oversight; and evidence that must support both operations and review.
HIPAA-related safeguards, NIST-based controls, state requirements, and program-specific obligations are context—not a promise of legal interpretation or certification.
Government-facing systemsAuthorization, corrective action & annual evidence
Security program plans, authorization artifacts, CAPs, POA&Ms, annual submissions, common-control dependencies, interconnection boundaries, and remediation evidence.
FISMA, NIST RMF, IRS Publication 1075, and SSA-related expectations may inform the work. Formal authorization and agency acceptance remain with designated officials.
Payment securityDefensible boundaries in the PCI environment
Cardholder-data boundaries, responsibility allocation, architecture decisions, compensating-control reasoning, remediation, and readiness for assessor review in the current PCI DSS v4.0.1 context.
Nerthus does not act as a QSA or issue a ROC, AOC, or PCI certification unless separately qualified and expressly engaged.
Privacy engineeringTurn stated commitments into system decisions
Data flows, purpose and access, retention, vendor boundaries, privacy-by-design decisions, and the technical implementation of stated privacy commitments.
GDPR and other privacy regimes may shape design requirements. Nerthus does not provide legal advice or determine legal applicability.
FERPA-oriented education dataStudent-data safeguards that match operations
Student-data flows, identity and access, vendor responsibilities, retention, incident readiness, and alignment between policy and system operation.
FERPA does not prescribe specific security controls. Nerthus provides security and privacy engineering support informed by the institution’s requirements; legal interpretations remain with qualified counsel and responsible institutions.
AI governanceMake the decision trail exist before launch
Pre-launch risk decisions, data provenance, access, human oversight, monitoring, vendor boundaries, and evidence that governance operates beyond the policy statement.
Nerthus provides architecture and governance advisory—not model certification, legal classification, or a guarantee of regulatory conformity.