SOC2 & HIPAA Claude Deployment
Budget: $15 – $25 USD
Deploying a suite of Claude-generated web applications on Google Cloud is the next milestone. The codebase spans Python/Django for core services, a JavaScript/React front-end, and several Java/Spring components. What remains is a rock-solid, automated path to production that meets SOC 2 Type II and HIPAA requirements, plus complementary security hardening.
Scope of work
• Build (or refine) an end-to-end CI/CD pipeline on Google Cloud services—Cloud Build, Artifact Registry, and Cloud Run/GKE are all acceptable as long as images are signed and provenance is tracked.
• Implement infrastructure-as-code so environments are reproducible; Terraform or Google Deployment Manager are fine.
• Apply Google Cloud best practices for IAM, VPC Service Controls, CMEK, logging, and monitoring.
• Integrate security scans (SAST, SCA, container vulnerability scans) and automated policy gates before any artifact is promoted.
• Configure audit-ready logging, evidence collection, and retention settings aligned with SOC 2 controls and HIPAA’s Security Rule.
• Produce concise documentation that outlines the architecture, control mappings, and day-to-day operational playbooks.
Acceptance criteria
1. Pipeline runs from commit to deployment with no manual steps and passes all automated security gates.
2. Independently verifiable SOC 2 & HIPAA control mapping document is delivered.
3. Pen-test or GCP Forseti/Cloud Security Scanner reports show no high-severity findings in the deployed stack.
4. A deployment-ready Git repo (or Terraform state) plus a walkthrough video is handed over.
With the technical groundwork already complete in Python/Django, JavaScript/React, and Java/Spring, the emphasis is on compliant, secure, repeatable operations.
I need the architecture to always be learning from user interactions and behaviour and create a second brain (obsidian) so that I can evolute and innovate.
This will be ongoing and you will help me with all my projects if this works out. Thank you!
Scope of work
• Build (or refine) an end-to-end CI/CD pipeline on Google Cloud services—Cloud Build, Artifact Registry, and Cloud Run/GKE are all acceptable as long as images are signed and provenance is tracked.
• Implement infrastructure-as-code so environments are reproducible; Terraform or Google Deployment Manager are fine.
• Apply Google Cloud best practices for IAM, VPC Service Controls, CMEK, logging, and monitoring.
• Integrate security scans (SAST, SCA, container vulnerability scans) and automated policy gates before any artifact is promoted.
• Configure audit-ready logging, evidence collection, and retention settings aligned with SOC 2 controls and HIPAA’s Security Rule.
• Produce concise documentation that outlines the architecture, control mappings, and day-to-day operational playbooks.
Acceptance criteria
1. Pipeline runs from commit to deployment with no manual steps and passes all automated security gates.
2. Independently verifiable SOC 2 & HIPAA control mapping document is delivered.
3. Pen-test or GCP Forseti/Cloud Security Scanner reports show no high-severity findings in the deployed stack.
4. A deployment-ready Git repo (or Terraform state) plus a walkthrough video is handed over.
With the technical groundwork already complete in Python/Django, JavaScript/React, and Java/Spring, the emphasis is on compliant, secure, repeatable operations.
I need the architecture to always be learning from user interactions and behaviour and create a second brain (obsidian) so that I can evolute and innovate.
This will be ongoing and you will help me with all my projects if this works out. Thank you!