COMPLIANCE-FOCUSED MANAGED IT

Managed IT built to pass your next audit, not just survive your next outage.

We build, harden, and maintain IT environments to meet PCI DSS, HIPAA, and CMMC/NIST SP 800-171 standards, for any organization handling payment card data, healthcare organizations handling PHI, and DoW contractors and subcontractors with flow-down requirements.

Peregrine falcon

Start with Foundation IT. Add Compliance-Managed IT on top.

Every client gets Foundation IT. Regulated clients layer Compliance-Managed IT on top of it, as an addition, not a replacement.

Foundation IT

Included for every client

Foundation IT is the day-to-day layer every client runs on: the devices, network, email, and backups your business depends on, all managed and monitored around the clock. It keeps your environment stable, patched, and supported, the base every compliance layer sits on top of.

What's Included in Foundation IT →

  • Endpoint management and patching
  • Help desk and remote support
  • Backup and disaster recovery
  • Email security hardening (M365 / Google Workspace)
  • Network monitoring and firewall management
  • Vulnerability scanning
  • Documented 30-day onboarding
  • 24/7 SOC monitoring with off-hours emergency escalation

Compliance-Managed IT

Added on top of Foundation IT, for regulated clients

For businesses operating under a regulatory framework, generic managed IT isn't enough. Compliance-Managed IT wraps everything in Foundation IT around the specific standard your business has to meet, so you're audit-ready year-round instead of scrambling every twelve months. Choose the framework that matches your obligations.

PCI DSS

For businesses that accept, process, or store payment card data

We scope and segment your cardholder data environment, manage the technical controls PCI DSS v4.0.1 requires, and keep your evidence trail current so the annual assessment is a formality, not a fire drill.

  • ∙ CDE scoping and network segmentation
  • ∙ SAQ determination and completion support
  • ∙ Quarterly ASV vulnerability scans
  • ∙ Tokenization and P2PE guidance
  • ∙ Continuous evidence collection for your QSA or acquirer

HIPAA

For dental practices, healthcare providers, and business associates handling PHI

We implement and maintain the technical safeguards HIPAA's Security Rule requires, encryption, access control, and audit logging, and keep your environment aligned to your annual Security Risk Analysis, so a breach doesn't become an OCR investigation.

  • ∙ Technical safeguards implemented and maintained to meet or exceed SRA requirements
  • ∙ Evidence and documentation support for your independent SRA assessor
  • ∙ BAA tracking for every tool we deploy or manage
  • ∙ Breach notification readiness
  • ∙ M365 HIPAA-aligned configuration

CMMC / NIST SP 800-171

For defense contractors and subcontractors handling FCI or CUI

We implement and maintain the controls NIST SP 800-171 requires, manage your CUI boundary, and support you toward certification or simple compliance demonstration, whether you're a prime flowing requirements down or a sub meeting them.

  • ∙ Control implementation across all 14 NIST SP 800-171 practice families, including your CUI boundary
  • ∙ Continuous monitoring to sustain and improve your control posture
  • ∙ Assessment support, interviews, technical testing, and evidence packaging, for your C3PAO assessment or 800-171 compliance verification
  • ∙ CUI and RPO boundary scoping support

Additional Frameworks

Operating under SOC 2, a state privacy law, or another standard?

Compliance-Managed IT isn't limited to PCI, HIPAA, and CMMC. If your business answers to a different framework, we'll scope the technical controls it requires and fold them into the same continuous-monitoring model.

  • ∙ Framework-specific control mapping
  • ∙ Gap identification against your existing environment
  • ∙ Ongoing monitoring aligned to your audit cycle
  • ∙ Evidence collection built into daily operations

Assessment support included: we act as your technical and compliance subject matter expert during your HIPAA Security Risk Analysis, PCI DSS SAQ or ROC, and CMMC readiness.

Formal assessments are performed by independent assessment partners and billed separately from your managed IT service. Don't have an assessor? We'll connect you with a trusted partner. For CMMC certification assessments, we recommend authorized CMMC third-party assessors (C3PAOs), who bill you directly.

We support the assessment; we are not the assessor. We don't issue AOCs, ROCs, SAQs, or CMMC certifications, and we don't own your SSP, POA&M, or SPRS score. You own the documentation. We own the environment underneath it: we maintain it, collect the evidence it produces, and sit at the table as your technical SME when the assessor has questions.

Not sure which framework applies to you? PCI, HIPAA, and CMMC are common, but they're far from the only ones with technical requirements. We'll help you sort out exactly what applies to your business.

Schedule a Discovery Call

Governed AI

Adopt Microsoft Copilot without putting your compliance at risk.

We get your Microsoft 365 environment ready for Copilot, then secure and govern it, so your team gets the productivity and your auditor gets the evidence. Copilot surfaces anything a user has permission to open, so we clean up who can see what before it goes live.

Choose what you need

  • ∙ AI Readiness Assessment (required first step): a scored review of your Microsoft 365 tenant across seven domains, with a written report and remediation roadmap.
  • ∙ Governed Copilot Rollout: Conditional Access, sensitivity labels, DLP and Purview configuration, SharePoint oversharing cleanup, and Copilot licensing at no markup.
  • ∙ Training and Adoption: AI literacy training, change management, and a 30/60/90 day adoption program.
  • ∙ AI Governance & Advisory: acceptable use policy, usage reporting, and quarterly strategy reviews.
  • ∙ Custom Agents and Automation: Copilot Studio agents and process automation, built inside your governed tenant.

Every Copilot deployment starts with the assessment. We do not sell Copilot as a standalone license.

Governed for your framework

HIPAA

Map AI use to Security Rule safeguards, keep ePHI out of ungoverned tools, document the decisions.

PCI DSS

Keep cardholder data out of prompts and out of scope, with DLP and access controls that support your assessment.

Other Frameworks

We map AI governance to the framework your business answers to.

Peregrine uses Microsoft 365 Copilot heavily in our own daily operations. We deploy what we depend on.

Scoped to your environment. 12-month agreement for recurring services.

Schedule a Discovery Call AI readiness is part of the conversation.

Beyond managed IT

Some clients need an ongoing seat at the table. Others need a defined project done right. We do both.

Fractional Leadership

Security and technology leadership, without a full-time hire. Available with or without managed IT.

vCISO

Security posture, policy development, incident response planning, and third-party vendor auditing across your whole environment.

vCIO

Technology roadmap planning, budget and vendor strategy, and IT decision-making support.

IT Consulting & Projects

A clear project, or a problem you haven't scoped yet. Either way, we'll get you to a defined plan.

Cloud Migration

M365 and cloud environment migrations, including GCC High for organizations that need to handle CUI.

BC/DR Planning

A documented recovery plan, tested through tabletop exercises with lessons learned rolled into an annual review, distinct from your day-to-day backups.

Project SOWs

From infrastructure refreshes and endpoint rollouts to server migrations and cloud app reviews, we'll help you scope the work first, then execute it.

Scoped to your environment.

Schedule a Discovery Call
Brad Cassada, founder of Peregrine Data Solutions
ABOUT

IT run by someone who has been audited, and has audited others.

Peregrine Data Solutions is a compliance-native managed service provider in Fate, Texas, serving businesses across Dallas-Fort Worth and the surrounding region. We run your IT and build PCI DSS, HIPAA, and CMMC requirements into the work from day one, so an audit is a review, not a scramble.

I'm Brad Cassada, the founder. I spent 20 years in Air Force cyber operations, retiring as a Master Sergeant, then 14 years as an enterprise security consultant. That's 34 years of hands-on engineering and compliance work, from network operations and vulnerability management to leading assessments for retail, hospitality, entertainment, healthcare, and defense contractors. Every Peregrine engagement is led by me personally.

  • CISSP
  • CISA
  • Retired USAF Master Sergeant
  • PCI DSS
  • HIPAA
  • CMMC / NIST SP 800-171
of experience
34 years
of USAF cyber operations
20 years
of enterprise consulting
14 years

How we work

  • ∙ Compliance built in: Requirements are part of how we manage your environment, not a project we add before an audit.
  • ∙ Evidence as we go: Documentation and reporting are kept current, so you're ready when an assessor asks.
  • ∙ Direct access: You talk to the person accountable for your environment.

Backed by enterprise-grade tooling

The same stack the large shops run, sized for a business with 30 people.

  • Huntress
  • WatchGuard
  • ConnectSecure
  • Syncro
  • DNSFilter
  • Microsoft Defender for O365

Before it's a fire drill, it's just a phone call.

Tell us what you're being asked to prove and who's asking. Some of you have a date circled in red. Some of you just know something's off. Either way, better to call us now than during the scramble.

Schedule a Discovery Call