
What Nankai Means, and Why It Is In Our Name
Nankai is the Tianjin school founded in 1904, and we took the name for what it stood for: Gong – public spirit. Neng – ability.
Practical writing on SOC 2, ISO 27001 and the privacy law Canadian companies actually have to follow. We are a Toronto compliance firm, and this is where we explain the work: what a report costs, how long an audit really takes, and what an auditor asks for. Start with our Compliance as a Service overview, or go straight to the compliance library.

Nankai is the Tianjin school founded in 1904, and we took the name for what it stood for: Gong – public spirit. Neng – ability.

How one compliance practitioner’s breaking point with GRC software became the foundation for a different kind of compliance company.

One is a certificate. The other is a report on controls you wrote. Why the overlap runs one way, and which your buyers ask for.

USD 25,000 to 80,000 in year one for most small and mid-sized companies. What drives the number, and which parts you can actually control.

Six to nine months from a standing start for a first SOC 2 Type 2 report. What happens in each phase, and where teams lose time.

OWASP, PTES, NIST and OSSTMM compared. Which methodology fits your scope, and what an auditor expects to see in the report.

ISO 27001 is the standard you certify against. ISO 27002 explains how the controls work. Why that difference matters for your project.

Designing an ISO 27001 ISMS doesn’t have to be overwhelming. Explore our definitive 10-step guide to navigating mandatory clauses, mastering risk assessments, and accelerating your path

Information security is no longer optional, but achieving ISO 27001 certification can feel like a daunting task. We’ve broken down the complexities of ISMS design into
Most of what we write here comes out of engagements with Canadian companies. Buyers ask for the same two reports again and again. Our SOC2 service Canada engagements answer the first. Our ISO 27001 certification Toronto engagements answer the second. Alongside them sit obligations that United States vendors gloss over: PIPEDA federally, PHIPA for health information in Ontario, Law 25 in Quebec, and OSFI expectations for federally regulated financial institutions.
Our compliance services Canada engagements account for all of that from the first conversation. One control library covers the framework you are certifying against and the privacy law you already follow.
Canadian data residency compliance is a standing condition in public sector and healthcare contracts, and a growing one in enterprise procurement. Your evidence, policies and control records stay in Canada, so the answer to that questionnaire question is short and provable.
Readiness, control design, evidence and auditor coordination for the Trust Services Criteria. Buyers write it SOC2 or SOC 2. Same report.
Scoping, Statement of Applicability, risk assessment and internal audit, through Stage 1 and Stage 2 with an accredited certification body.
PIPEDA, PHIPA and GDPR advice, security program design and penetration testing coordination for teams without a CISO.
New here? The compliance platform shows how the controls, evidence and audits fit together, and about Nank.ai explains why we built it the way we did.
Tell us which framework your buyers are asking for and what you have in place today. We will tell you what the program looks like and how long it takes. A real compliance manager on the call, no obligation.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
These cookies are needed for adding comments on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics
Service URL: www.nank.ai (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.