Industries
Regulated technology, read and run by an operator.
CCA works with PE firms and portfolio companies that operate under regulatory obligation: healthcare, education, and compliance-heavy software. We build the data foundations, compliance posture, and AI governance those businesses run on. We assess before we build, and we own what we ship through the hold.
The gap we fill
Between advisory and vendor.
Between the strategy consultant and the dev shop sits the work most regulated portfolios need: someone who has carried the P&L and can still write the architecture. That is the space CCA fills.
The strategy consultant
Maps the market and writes the plan, then hands it to someone else to build. Never carries the P&L, never owns the audit calendar, never ships the integration.
The operator who has run it - CCA
Has run a regulated technology organization end to end: engineering, security, compliance, and the roadmap the board reviews. Reads the risk, then owns the build.
The dev shop
Strong inside a single feature, thin across the seams, where regulated data, third-party systems, and compliance obligations meet. Great in the slice, poor at the whole.
What we build
The systems regulated businesses run on.
Compliance posture - SOC 2 and HIPAA
The controls, access model, audit logging, and documentation a buyer, customer, or auditor will ask to see. Built once, evidenced continuously, ready for the questionnaire before it arrives.
Regulated-document automation
Intake, classification, and routing for the contracts, attestations, and filings that pile up in every regulated business: automated where the rules are clear, escalated where judgment is required.
Data privacy programs - HIPAA, FERPA, PII
The data mapping, access boundaries, and audit trail that turn a privacy policy into an operating fact, for patient data, student records, and the personal information in between.
AI governance for regulated data
A control plane for where AI touches regulated data and consequential decisions: what models see, what they may decide, how outputs are reviewed, and the record that proves it, before a regulator or a customer asks.
Security run as an operating function
The CISO discipline without the full-time hire: controls owned, evidence collected continuously, vendors reviewed on a schedule. Security as a standing function, not an annual scramble.
Data foundations for regulated data
Records unified across the systems they fragment into (one governed view instead of five partial ones), so downstream analytics and AI stand on data that can survive an audit.
The record
Regulated data, operated at scale.
This vertical is not a positioning exercise. Sujit ran engineering, security, and compliance for a PE-backed education-data company - a category where the data is regulated, the customers are institutions, and the audit is never optional. Student records sit under FERPA the way patient data sits under HIPAA: the statute differs, the discipline does not.
That operating seat included taking the organization through SOC 2 Type II org-wide, carrying the CISO scope alongside the engineering roadmap, and integrating acquisitions without breaking the compliance posture customers depended on.
Current work in healthcare runs under NDA. We describe the discipline here, not the deals - the same operating pattern applies wherever data carries regulatory weight.
Nothing on this page is a composite or a projection. The record above is the operating history this practice is built on; the engagements under NDA stay that way.
How we engage
Four tracks, scoped to the hold period.
Every engagement is one of four tracks, matched to where the business sits in the hold.
ASSESS
A technology and compliance read of a regulated target (data integrity, security posture, audit readiness, and what it costs to fix), translated for a deal team, not an engineering team.
IMPROVE
Hold-period build: document automation, data foundations, and the compliance instrumentation that turn a manual back office into a system the company can scale on.
LEAD
Embedded technology leadership for a portco without it: fractional CTO, CISO, or CAIO who owns the roadmap, the audit calendar, and the AI governance a regulated board needs to see.
EXIT
Sell-side readiness: the documented posture, clean data story, and defensible AI and compliance controls a buyer's diligence team will test.
Every engagement starts with an assessment.
Fixed-fee. Scoped before kickoff.
Questions regulated buyers ask
Questions an operator answers.
- Do you sign a BAA, and how do you handle PHI?
- Yes. Any engagement that touches protected health information runs under a Business Associate Agreement, with access scoped to what the work requires, audit logging on PHI access, and PHI kept out of environments (including AI systems) that are not covered and controlled.
- How do you approach SOC 2 Type II for a portfolio company?
- Type II is about evidence over a period, not a one-time audit. We define the control set, instrument the systems so evidence is collected continuously, and close the gaps that would otherwise surface as exceptions, so the report reflects how the company operates, not a scramble before the auditor arrives.
- What does FERPA compliance look like in practice for an education-data business?
- Access scoped to educational purpose, sharing governed by agreement rather than habit, and a log that shows who saw what. We have operated student-data systems at institutional scale. The discipline is the same one HIPAA demands, applied to a different statute.
- Can AI be used on regulated data at all?
- Yes, inside a controlled boundary. Regulated data stays in covered systems, models see only what the engagement's control plane allows, outputs that affect a person are reviewed by one, and the record of what the model saw and decided is kept. Governance is designed in before the model ships, not bolted on after.
- How do you handle vendor risk and data-processing agreements?
- Subprocessors inventoried, agreements current, access reviewed on a schedule. Vendor risk is treated as part of the control set, reviewed continuously, not an annual questionnaire that goes stale the week after it is filed.
- What happens when the auditor (or the buyer's diligence team) arrives?
- If evidence has been collected continuously, an audit is retrieval, not archaeology. The same posture that satisfies an auditor is what a buyer's diligence team tests at exit. Building it once serves both.
- Is CCA a consultant or a vendor here?
- Neither, exactly. We assess like an advisor and build like an operator, and we own what we ship through the hold. The practice exists for the seam the two usually leave uncovered.
Bring us the regulated portfolio company before the plan is set.
Send a few lines about the business and where technology sits in the thesis. Sujit reads every brief, and you will get an operator's honest read, including whether we are the right team for it.