VanRein Compliance
VanRein Compliance is a bootstrapped Texas-based data security and compliance services company serving SMB and mid-market healthcare, SaaS, and call center organizations with HIPAA, SOC2, ISO, HITRUST, and GDPR compliance consulting, proprietary VRC1 platform, and an online training course library.
- Company typePrivate
- Founded2016
- HeadquartersNew Braunfels, United States
- Headcount1–10
- GTM typeB2B
- OfferingServices
What VanRein Compliance does
VanRein Compliance, LLC is a privately held, bootstrapped data security and compliance services company founded in 2016 by Rob and Dawn Van Buskirk and headquartered in New Braunfels, Texas. The company serves small and mid-market organizations primarily in healthcare, SaaS/health tech, and call center verticals, helping them achieve and maintain regulatory compliance with HIPAA, HITECH, SOC2, ISO 27001, ISO 42001, HITRUST, GDPR, and state-level privacy laws including Texas HB300, CPRA, and New York SHIELD. VanRein has trained over 12,000 users across its online course catalog and maintains a 5-star rating with 85 customer reviews.
The company's core technology is VRC1 (VanRein Compliance Command Center), a proprietary compliance management platform that unifies project management, documentation, evidence collection, expert messaging, and training delivery. VRC1 is complemented by a Book of Evidence (BOE) framework for organized audit documentation, a learning management system for self-serve course delivery, and a dedicated e-commerce storefront. Service offerings span three subscription tiers (Essentials at $529/month, Guided at $829/month, Concierge at $1,229/month) plus Compliance-as-a-Service with fractional CISO engagements, custom training development starting at $6,000, penetration testing, vulnerability scanning, tabletop exercises, dark web credential monitoring, and disaster recovery planning. Individual compliance courses are priced at $32-$39 per seat.
VanRein operates a hybrid go-to-market combining product-led growth through its self-serve training platform with direct sales for consulting engagements. The company markets through LinkedIn, Facebook, Instagram, X, YouTube, a proprietary podcast, blog content, email newsletters, and a NAEO Preferred Vendor channel partnership. The team consists of approximately 8 named members including a Chief of Staff and a Cybersecurity Executive (vCISO) with CCISO, CISM, CISA, and CGEIT credentials. VanRein is founder-owned with no external funding, no parent company, and no institutional investors.
VanRein Compliance firmographics
Firmographics- Name
- VanRein Compliance
- Legal name
- VanRein Compliance, LLC
- Website
- https://vanreincompliance.com
- Company type
- Private
- Founded year
- 2016
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- VanRein Compliance is a bootstrapped Texas-based data security and compliance services company serving SMB and mid-market healthcare, SaaS, and call center organizations with HIPAA, SOC2, ISO, HITRUST, and GDPR compliance consulting, proprietary VRC1 platform, and an online training course library.
- Ownership category
- akta.pro rank
VanRein Compliance industry classification
Industry- Product category
- Compliance Management Services
- NAICS
- Custom Computer Programming Services (541511), Computer Training (611420)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Consent, Preference & Data Rights Management (incl. HIPAA/GDPR support) (HLACAIAG)
- akta.pro secondary industries
- Privacy, Consent & Data Protection Management (BPAEAPAF), Compliance, Risk & Audit Management (SOC 2/ISO/PCI) (HDABANAK)
Keywords
Where VanRein Compliance is headquartered
LocationHeadquarters
- HQ city
- New Braunfels
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
VanRein Compliance business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations
Revenue model
- Subscription Consulting & Compliance Packages: Monthly recurring subscription packages (Essentials at $529/mo, Guided at $829/mo, Concierge at $1,229/mo) providing compliance assessments, policy frameworks, training licenses, account management, and ongoing compliance support. Higher tiers include more training licenses, dedicated Slack channels, penetration testing, and disaster recovery frameworks.
- Individual Online Courses: One-time purchase of individual compliance training courses ranging from $32 to $39 per course, with options for annual subscription/auto-renewal (e.g., HIPAA at $39/year, HB300 at $39 every 2 years). Courses cover HIPAA, GDPR, CPRA, PCI, FERPA, Cybersecurity, AI Security, and other compliance topics.
- Custom Training Development: Bespoke course creation starting at $6,000, including script creation, storyboard blueprint, production with actor(s) or 2D/3D animation, 2 edits, and up to 50 licenses. Targets organizations needing customized compliance training content.
- Compliance-as-a-Service (CaaS): Dedicated Compliance Officer engagement where a VanRein professional serves as an extension of the client's team to build and implement their compliance program. Priced via custom quote based on scope.
- Proactive Cybersecurity Services: Penetration testing, vulnerability scanning, tabletop exercises, and fractional CISO services offered as add-ons or standalone engagements, typically bundled within subscription tiers or quoted separately.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Subscription | Monthly | Self-guided compliance package at $529/month |
| Subscription | Monthly | Guided compliance package at $829/month |
| Subscription | Monthly | Full-service compliance package at $1,229/month |
| One time/ perpetual license | Multi-year contract | Custom training development starting at $6,000 |
| Other | Multi-year contract | Compliance-as-a-Service with dedicated Compliance Officer |
| Subscription | Annual | Standard online courses at $32–$39 per seat |
| Subscription | Annual | Hazard Communication (HazCom) course at $35 |
Go-to-market motion1 record
Distribution channels4 records
Marketing channels10 records
VanRein Compliance product offering
Product offeringCore offering
VanRein Compliance provides data security and regulatory compliance consulting services combined with a proprietary VRC1 (VanRein Compliance Command Center) platform and an online training course library. The company helps organizations achieve and maintain compliance with HIPAA, SOC2, ISO27001, ISO42001, HITRUST, GDPR, and state-level privacy laws through tiered consulting packages, risk assessments, policy development, penetration testing, fractional CISO services, dark web monitoring, and over 16 specialized online training courses.
Product overview
VanRein Compliance offers a comprehensive data security and compliance solutions portfolio centered on its VRC1 unified compliance management platform combined with professional consulting services and an online training course library. The core VRC1 platform provides real-time progress tracking, expert collaboration, centralized documentation, and compliance dashboards. Consulting services span HIPAA, SOC2, ISO 27001, ISO 42001, and HITRUST compliance across three service tiers (Base/Peak/Apex). The training division offers 16+ online courses including specialized HIPAA tracks for operators, compliance officers, and SaaS vendors, plus courses on cybersecurity, AI security awareness, GDPR, CPRA, PCI, FERPA, Texas HB 300, and workplace safety topics. Additional offerings include penetration testing, vulnerability scanning, tabletop exercises, dark web monitoring, fractional CISO services, disaster recovery planning, and state-level compliance consulting. The company serves healthcare, technology, insurance, and other regulated industries with over 12,000 users trained across its platform.
Differentiator
Problem solved
Functional benefit
Products and services
- VRC1 (VanRein Compliance Command Center) A unified compliance management platform that brings together project management, documentation, evidence collection, and expert support with real-time progress tracking, direct collaboration with compliance experts through integrated messaging, and dashboards for monitoring deadlines, tasks, and audit readiness. For organizations needing a centralized workspace to manage multi-framework compliance programs.
- HIPAA Compliance Services HIPAA compliance consulting service including audit and remediation reporting, monthly compliance check-in meetings, dedicated account manager, policy framework creation, and up to 20 training licenses. For healthcare organizations and covered entities required to comply with HIPAA and HITECH regulations.
- HIPAA + ISO or SOC2 Services Combined multi-framework compliance package covering HIPAA, SOC2, ISO 27001, and ISO 42001 with monthly meetings, custom policies and procedures, business associate agreements, state compliance, online training with up to 50 licenses, and up to 2 security questionnaires annually. For organizations needing multiple compliance frameworks managed by a single partner.
- HITRUST + VISO Services Comprehensive enterprise service covering ISO and SOC2 with virtual CISO, monthly or bi-weekly meetings, unlimited training licenses, up to 6 security questionnaires annually, privacy policy and terms of service, incident response, disaster recovery, and business continuity planning. For enterprises pursuing HITRUST certification and full security program maturity.
- State-Level Compliance Consulting Consulting and training for organizations needing compliance with state, county, and local laws regarding privacy, data security, cybersecurity, and data breach notification. Serves lawyers, hospitals, physicians, call centers, laboratories, and other regulated occupations across multiple U.S. states.
- Custom Built Training Bespoke custom training and education development starting at $6,000, including up to 30-minute course, script creation, storyboard blueprint, production with actor or 2D/3D animation, 2 edits, and up to 50 licenses. For organizations needing customized compliance training content tailored to their industry.
- Compliance-as-a-Service Dedicated compliance officer service where a VanRein professional is assigned as an extension of the client's team to build and implement their compliance program. Custom-scoped and quoted per engagement. For organizations needing an embedded compliance expert without hiring a full-time executive.
- HIPAA Compliance Course Comprehensive HIPAA training course covering understanding HIPAA, defining PHI, HIPAA requirements, protecting PHI, patients' rights, HIPAA violations and data breaches, and AI and HIPAA compliance. $39 per user, approximately 30 minutes. For healthcare staff and anyone handling Protected Health Information.
- HIPAA for Operators Course Specialized HIPAA training for call center agents, telephone answering service staff, and operators covering handling PHI over calls and digital communications, HIPAA basics, Privacy/Security/Breach Notification Rules, caller verification, and social engineering threats. $39 per user.
- HIPAA for Compliance Officers Course Advanced HIPAA training for compliance officers covering developing, implementing, and overseeing HIPAA compliance programs, including policy development, staff training, risk management, regulatory compliance, AI in healthcare compliance, and OCR investigations. $39 per user.
- HIPAA for SaaS and Health Tech Vendors Course HIPAA training for product, engineering, security, support, and GTM teams building or operating software that touches patient data. Covers PHI in software, HIPAA requirements from vendor perspective, handling PHI in apps and digital communication, patients' rights, violations, and AI and HIPAA compliance. $39 per user.
- Texas HB 300 Course Training covering Texas House Bill 300 expanded privacy protections beyond HIPAA, including covered entities, training requirements, breach notification, medical records, enforcement, and duties to provide notice. $39 per user, valid for 2 years.
- Cybersecurity Course Comprehensive cybersecurity training covering introduction to cybersecurity, AI and machine learning, cloud security and IoT, ransomware and phishing, emerging threats, and cybersecurity best practices including MFA, password hygiene, and Zero Trust principles. $35 per user.
- GDPR Course General Data Protection Regulation training covering understanding GDPR, personal data and core principles, roles and responsibilities, individual data rights, Subject Access Requests, risk awareness, and reporting accountability. $32 per user.
- CPRA Course California Privacy Rights Act training covering CPRA foundations, personal and sensitive personal information, individual privacy rights, employee responsibilities, handling privacy requests, and building a culture of privacy. $32 per user.
- PCI Course Payment Card Industry Data Security Standard training covering PCI DSS requirements, violations, and questionnaire completion for organizations accepting, processing, storing, or transmitting credit card information. $32 per user.
- Medicare/Medicaid Fraud, Waste and Abuse Course Training covering prevention, detection, and reporting of Medicare/Medicaid fraud, waste, and abuse through real-world scenarios and review of key laws including False Claims Act, Anti-Kickback Statute, and Stark Law. $35 per user.
- FERPA Course Family Educational Rights and Privacy Act training covering federal law protecting confidentiality of student information and personally identifiable information in student records.
- AI Security Awareness Training Comprehensive AI training covering practical and governance-aligned approach to using AI safely and responsibly, including AI in the workplace, regulated environments, sensitive data (PHI, PII, PCI), AI risk awareness, safe use guidelines, accountability and reporting, and responsible AI governance. $39 per user.
- New York SHIELD Act Course Training covering New York SHIELD Act requirements including expanded definition of private information such as biometric information, email addresses, security questions, and credit/debit card numbers.
- Bloodborne Pathogens Course Training covering prevention of exposure to bloodborne pathogens including OSHA standards, universal precautions, and standard precautions for healthcare environments. $32 per user.
- Essential Workplace Training Training covering workplace respect, professionalism, recognizing inappropriate behavior, professional communication, boundary-setting, de-escalation techniques, and workplace accountability. $35 per user.
- Hazard Communication (HazCom) Course OSHA Hazard Communication Standard training covering chemical hazards, labels, pictograms, Safety Data Sheets, routes of exposure, hierarchy of controls, PPE, and spill response. $35 per user, with auto-renewal and group purchase options available.
- Building a Diverse and Inclusive Workplace Course Training covering diversity, equity, and inclusion concepts, strategies for creating a diverse and inclusive environment, and workplace culture development. $32 per user.
- Free AI Security Awareness Training Free foundational course providing introduction to safe and responsible AI use in the workplace, covering AI in the workplace, understanding AI risk, regulated environments and sensitive data, common risk scenarios, and basic safe AI use guidelines.
Quantifiable outcome
- 80% improvement in data compliance in 60 days
- +4 more outcomes
Companies that use VanRein Compliance
Customer profileNamed customers24 records
Segments6 records
Ideal customer profiles5 records
VanRein Compliance technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration5 records
AI capability4 records
Feature4 records
VanRein Compliance partnerships and signals
Strategic signalPartnerships
One partnership is on record.
- NAEO (National Association of Telephone Marketing Enterprises)coreVanRein Compliance is recognized as a NAEO Preferred Vendor Member, serving as a compliance solutions partner for NAEO member organizations. NAEO represents telephone marketing enterprises, call centers, and telephone answering services — a natural fit for VanRin's HIPAA compliance services targeting the call center industry.
Scale indicators7 records
Recent moves6 records
Expansion highlights6 records
VanRein Compliance competitors and assessment
Company assessmentDirect peers
- Vanta: Leading automated GRC platform supporting SOC2, ISO 27001, HIPAA, and other frameworks. While product-led rather than service-led, Vanta targets the same compliance buyers and increasingly competes for the evidence-collection work VanRein performs manually.
- Drata: Automated compliance and security monitoring platform for SOC2, ISO 27001, HIPAA, and more. Drata's self-serve automation directly competes with the lower tiers of VanRein's compliance service offerings for SMB and mid-market customers.
- Secureframe: Compliance automation platform that helps businesses achieve and maintain SOC2, ISO 27001, HIPAA, PCI, and other certifications. Competes with VanRein in the same regulated-customer segment with a more automated, less service-intensive model.
- Compliancy Group: HIPAA-focused compliance software and consulting firm serving healthcare providers and business associates. Closely comparable in mission and customer base, combining compliance software with dedicated support and training.
- A-LIGN: Cybersecurity and compliance auditing firm offering SOC2, ISO 27001, HITRUST, HIPAA, and PCI assessments. Direct peer in regulated-industry compliance services, though operating at a larger enterprise scale.
- Schellman & Co: National attestation, cybersecurity, and compliance firm specializing in SOC2, ISO 27001, HITRUST, HIPAA, and FedRAMP. Larger peer in the multi-framework compliance services space with broader enterprise reach.
- Total HIPAA: HIPAA compliance solutions provider offering training, risk assessments, policies, and ongoing compliance support. Closely comparable in offering mix and target customer (healthcare SMBs and call centers).
- Accountable HQ: HIPAA compliance software and services company providing privacy and security compliance programs for healthcare providers and business associates. Competes directly with VanRein's Essentials and Guided tiers.
Emerging players
- Sprinto: Automated compliance platform for SOC2, ISO 27001, HIPAA, and GDPR aimed at fast-growing SaaS companies. Targets the same SaaS/health-tech business associate customers VanRein serves via HIPAA for SaaS training.
Broad incumbents
- HITRUST: The HITRUST Alliance operates the widely adopted HITRUST CSF certification framework. VanRein supports HITRUST readiness for clients, making HITRUST both a partner relationship and a structural incumbent in the certification ecosystem.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks5 records
Key highlights7 records
Customer concentration
VanRein Compliance social profiles
Digital presenceVanRein Compliance financial estimates
Financial estimateRevenue estimate
Valuation estimate
VanRein Compliance leadership team
Management profileNumber of profiles
Profiles8 records
VanRein Compliance funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
VanRein Compliance M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about VanRein Compliance
What does VanRein Compliance do?
VanRein Compliance provides data security and regulatory compliance consulting services combined with a proprietary VRC1 (VanRein Compliance Command Center) platform and an online training course library. The company helps organizations achieve and maintain compliance with HIPAA, SOC2, ISO27001, ISO42001, HITRUST, GDPR, and state-level privacy laws through tiered consulting packages, risk assessments, policy development, penetration testing, fractional CISO services, dark web monitoring, and over 16 specialized online training courses.
Is VanRein Compliance a public or private company?
VanRein Compliance is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was VanRein Compliance founded?
VanRein Compliance was founded in 2016. It employs 1 to 10 people.
Where is VanRein Compliance based?
VanRein Compliance is headquartered in New Braunfels, United States, in the North America region.
How does VanRein Compliance make money?
Five revenue lines are on record. Subscription Consulting & Compliance Packages are the primary driver. The others are individual Online Courses, custom Training Development, compliance-as-a-Service (CaaS) and proactive Cybersecurity Services.
Who are VanRein Compliance's main competitors?
Direct peers on record are Vanta, Drata, Secureframe, Compliancy Group, A-LIGN, Schellman & Co, Total HIPAA and Accountable HQ. Sprinto is listed as an emerging player. HITRUST is listed as a broad incumbent.
Does VanRein Compliance have an API?
No public API is recorded for VanRein Compliance.
What industry is VanRein Compliance in?
VanRein Compliance's product category is Compliance Management Services. Its primary akta.pro industry code is HLACAIAG, Consent, Preference & Data Rights Management (incl. HIPAA/GDPR support), with a secondary code of BPAEAPAF, Privacy, Consent & Data Protection Management. Its NAICS code is 541511 and its SIC code is 7370.