The map, not the treasure.
RunDEETS exists because turning a pile of regulations into a real answer — "what are we on the hook for, and can we prove we did something about it" — shouldn't require handing a stranger the keys to your organization to find out.
The problem we exist to solve
Two kinds of teams end up here, for opposite reasons. The first never had to think about formal compliance and now does — the clearest case is Controlled Unclassified Information, where obligations flow down contractually from a prime contractor to every subcontractor that touches CUI, whether or not that subcontractor has ever run a security program before. The fallout for getting it wrong is real and immediate: lost eligibility to bid, breach of contract, liability that flows down again to their own subs. The same shape of exposure shows up well beyond defense contracting — anywhere a regulator, a partner, or an insurer suddenly wants a real, evidenced answer.
The second kind of team is chasing its first real certification — a startup or small business staring down a compliance framework for the first time, usually because closing an enterprise deal or landing a contract now depends on it, with no in-house function to lean on.
Both groups are stuck choosing between the same three bad options today: build and maintain it themselves in a spreadsheet, which works until an auditor stops trusting it; pay a consultant to do it by hand, which is slow and walks out the door with the knowledge when the engagement ends; or hand a SaaS platform standing access into their systems and credentials so it can watch for them — fast, but it asks an organization to trust a third party with exactly the kind of access a compliance program is supposed to be minimizing.
Why now
Two regulatory currents are moving in the same direction at once. Enforcement around Controlled Unclassified Information is shifting from self-attestation to third-party verification, flowing down the supply chain to companies with no compliance infrastructure of their own. At the same time, states keep adding their own privacy and security statutes on top of an already dense federal patchwork. The number of organizations that suddenly owe someone a real, evidenced answer is growing faster than the number of people qualified to give them one by hand.
The architecture is the promise
There are already tools in this space, and most of them force the same choice on a buyer: do it yourself, pay someone to do it by hand, or hand a platform deep, standing access into your environment so it can do the work continuously. That third option is the fastest-growing category, and it works by asking for exactly the kind of trust a compliance program exists to minimize.
RunDEETS is built to not need that trust in the first place. Every answer, upload, and attestation is created and stored client-side, inside storage provisioned in the customer's own cloud tenant — never on our servers. Walk away, and every attestation walks away with you; we never had the ability to hold it hostage. Authentication runs on the signed-in user's own delegated credentials, never a service credential held on an organization's behalf, so there is no standing server-side secret to leak in the first place.
What we actually hold is the map: statutes, standards, mandates, and controls linked into a single graph, so one real-world requirement is recognized under every name and framework it shows up in — that graph, and the workflow built around it, is the product. The standard security promise in this industry is "we won't look." Ours is structural: we can't.
Who's building this
RunDEETS is built by a small, founder-led team — a father-son engineering pair with a shared, decades-deep background in enterprise systems, security, and compliance. One half of the team has spent years as a working security leader on federal contract work, living with exactly the crosswalk problem this product solves before it existed. The other has spent a career in enterprise software and data engineering — database architecture, large-scale data migrations, and the systems work that compliance evidence ultimately has to live on top of.
The idea started small — nights and weekends, a rough internal tool built to solve one team's own problem — before becoming the full-time, full-team effort it is today. That practical, build-it-because-we-needed-it streak is still the whole approach: rebuild it when there's a genuinely better way to do it, not when it's comfortable to leave alone.