Compliance is built in from the start — least-privilege IAM, encryption, and centralized logging — so audit obligations like HIPAA and SOC are addressed in the architecture, not bolted on later.