Compliance Scope & Disclaimers
SiriusXM Technologies helps cannabis operators build IT systems, policies, and evidence aligned with state traceability, SOC 2, PCI-DSS, and HIPAA expectations. This page explains what we do, what we do not do, and how responsibility is shared between your team, regulators, and auditors.
We design the technical workflows, integrations, and data-quality controls that help you stay current with state-designated track-and-trace reporting obligations.
We help cannabis operators prepare the evidence, controls, and infrastructure needed for a successful SOC 2 audit by investors, partners, and regulators.
We scope, segment, and harden the systems that touch or transmit payment data so your environment aligns with PCI-DSS expectations.
We design access controls, encryption, and audit practices aligned with HIPAA Security and Privacy Rules for medical cannabis operators and wellness clinics.
Detailed Scope & Disclaimers
Expand each area to understand what SiriusXM Technologies delivers and where independent auditors, legal counsel, or regulators retain responsibility.
Shared Responsibility & Scope Guidance
Successful compliance programs require clear boundaries. These principles guide every engagement.
We deliver the technical architecture, documentation, and evidence needed for audits. We do not issue compliance certifications, audit opinions, or legal interpretations.
Your organization owns policies, employee training, physical security, and final submissions to state agencies or auditors. We support the IT and operational controls that feed those processes.
Cannabis regulations differ by state and change frequently. We align systems to your current requirements, but you should verify obligations with your licensed counsel or compliance officer.
Metrc, BioTrack, SOC 2 auditors, PCI QSAs, and HIPAA business associates remain independent parties. We do not control their platforms, timelines, or findings.
General Disclaimer
The information on this page and the services described are for technology consulting and operational readiness purposes only. SiriusXM Technologies does not provide legal, accounting, or audit services. Achieving and maintaining compliance with Metrc, BioTrack, SOC 2, PCI-DSS, HIPAA, or any other regulatory or industry framework depends on your organization's full adherence to applicable requirements, including legal, procedural, physical, and human elements outside of IT.
You should consult qualified legal counsel, licensed auditors, and accredited assessors for final interpretations, certifications, and attestations. Engagement terms, deliverables, and responsibilities are defined in the signed Statement of Work (SOW) for each project.