About this talk
This talk by Matthew Connerton explores the journey to achieving SOC 2 and HITRUST compliance for a Drupal-based SaaS platform at Encore Healthcare. The session emphasizes the need for continuous compliance rather than seasonal checklists, highlighting the importance of designing Drupal architecture and CI/CD processes that inherently support security and governance. The speaker discusses aligning Drupal's configuration management and custom modules with essential security controls, as well as implementing observability practices that transform audit requirements into real-time visibility. Attendees will gain insights into creating compliance-aware Drupal applications where infrastructure, code, and processes seamlessly integrate to ensure ongoing assurance and streamline audits.