Product walkthrough

From requirement to compliant, running infrastructure.

Here's the whole journey, using a real scenario: a healthcare company needs a secure SFTP endpoint so a lab partner can drop PHI files. Five steps, one pull request, zero compliance archaeology.

01 Blueprint catalog

Choose a blueprint

Start in the blueprint catalog: hardened patterns like Partner SFTP, Secure Bucket, and API Service, each tagged with the compliance profiles it supports (HIPAA, SOC 2, baseline) and an estimated monthly cost before you commit to anything.

  • Filter by category, data classification, and compliance profile
  • Import your existing Terraform templates instead of starting over
  • Cost estimates up front, per blueprint

Blueprint Catalog

This demo is configurable: pick a blueprint or framework and the rest of the walkthrough follows.

02 Deploy wizard

Configure it compliantly

The deploy wizard asks about your use case (partner, data classification, retention) and translates the answers into controls. This one is live: rename the partner, or switch the classification to Internal, and watch the controls and cost react everywhere below.

  • Data classification drives the controls, not the other way around
  • Live preview: resources, controls applied, docs generated, cost
  • User groups scoped per role: partner ops, admins, auditors

Deploying Partner SFTP

Controls applied automatically

  • SSE-KMS encryption
  • Private networking
  • Audit logging
  • Least privilege
  • 7-year retention lock

Estimated cost $52/mo · 5 resources

03 Deployment plan & approval

Approve it as a pull request

Nothing deploys behind your back. StackTakt opens a real pull request in your repository with the full Infrastructure as Code (IaC) plan, shows exactly which resources will be created and which controls they implement, and routes the deployment through your required approvers. Flip the environment to see the approval chain adjust.

  • Real PR in your repo: review and merge like any other change
  • Control coverage stated per deployment: encryption, access, audit
  • Multi-party approval workflow with generated evidence

Planned resources

Managed transfer server Transfer::Server Create
Bucket meridian-inbound S3::Bucket Create
KMS key transfer-data KMS::Key Create

Control coverage

Encryption at rest 164.312(a)(2)(iv) Implemented
Access control 164.312(a)(1) Implemented
Policy signoff 164.308(a)(2) Manual
CAPending COPending POPending
Runtime ~12 min Approve & Deploy

04 Asset inventory

See it in your asset inventory

Once deployed, the SFTP endpoint appears in your asset inventory alongside everything else StackTakt manages, with its classification, owner, control status, and monthly cost. When something drifts from its approved state, the status tells you at a glance.

  • Every asset: classification, owner, controls, live status, cost
  • Drift surfaces as a status, not a surprise in the next audit
  • One click from any asset to its full detail and history

Asset Inventory

Meridian Partner SFTP Just deployed PHI Partner Ops 14/14 $52/mo Healthy
Atlas Labs SFTP PHI Partner Ops 11/12 $48/mo Drift
phi-docs-bucket PHI Platform 8/8 $6/mo Healthy
Analytics environment Internal Data team 6/6 $310/mo Healthy
Docs site Public Marketing 4/4 $0/mo Healthy

05 Knowledge graph

Explore the knowledge graph

Everything is connected in one graph: the SFTP endpoint, the bucket and KMS key it depends on, the IAM group that controls access, the HIPAA control it implements, and the evidence pack that proves it. This one is live: click any node to jump to the underlying asset docs or the control text.

  • Assets, controls, identities, and evidence in one connected view
  • Each node records why it exists and who owns it
  • Evidence collection status visible per asset: 12/12, not "probably"

…and after you deploy

06 Drift detection & response

Catch drift, respond with confidence

Someone opens a security group to the internet from the cloud console ('a temporary test'). StackTakt catches the change, shows the exact configuration diff, names the controls it degraded, notifies the owner, and offers a remediation pull request to revert it.

  • Before/after diff of the exact change, minutes after it happens
  • Impact analysis: which assets and controls are affected
  • Respond your way: remediation PR, auto-revert, or accept the risk

High-severity drift detected

Meridian Partner SFTP security group changed outside StackTakt

High

Remediation PR will revert the change and restore both controls.

07 Compliance repository

One compliance repository

Every framework, control, and piece of evidence lives in one library. The HIPAA control matrix shows each requirement, what implements it, its live status, and the evidence behind it, exportable for your auditor. HIPAA mappings ship first; SOC 2 and further frameworks map onto the same controls.

  • Control matrix per framework: requirement → control → evidence
  • Statuses stay live: passing, manual, or drifted, never stale
  • Remediation guidance attached to every failing control

HIPAA Control Matrix

46 Controls 42 Passing 3 Manual 1 Drift
164.312(a)(1) Access control Okta, AWS IAM Passing 3
164.312(e)(1) Transmission security TLS 1.2 enforced Manual 1
164.312(c)(1) Integrity AWS CloudTrail Drift 1
164.308(a)(1) Risk management GRC workflow Passing 4

Exportable for your auditor · SOC 2 mapping next

08 Identity & permissions

Access that matches responsibilities

Groups map to real responsibilities (partner ops, client admins, compliance, auditors) and each group's access is scoped per asset: read/write on their SFTP endpoints, read-only on logs, request-only for deployments. Every change is captured in the audit log.

  • Per-asset access levels: read/write, read, request only
  • Auditors get read-only access to exactly what they need
  • Full audit log of permission changes, built in

Groups

Partner Ops · resource access

Meridian Partner SFTP Read / Write
Transfer logs Read
Evidence packs Read
Blueprint execution Request only

Try the other groups. Every change lands in the audit log

Product views are illustrative and simplified. StackTakt helps you implement and evidence specific technical controls; it does not by itself make your organization compliant with any framework.

Want to see it live, on your stack?

We're onboarding a small group of design partners and running walkthroughs against real AWS accounts.

Book a walkthrough