All case studies
CybersecurityFinancial technology7 months

A payments startup passes SOC 2 Type II on its first attempt, with the engineering team still shipping

Series B payments platform

An enterprise prospect made SOC 2 Type II a condition of contract. The company had a strong engineering culture and almost no compliance programme. We built the controls into the cloud estate and the identity layer, collected evidence by automation, and walked the team through the audit — without a single sprint lost to screenshot-hunting.

1st

attempt

SOC 2 Type II report issued with no exceptions

0

sprints lost to audit preparation

evidence was collected by integrations, not by engineers

−71%

standing privileged accounts

replaced with time-boxed, recorded privileged access

3

enterprise contracts unblocked

including the prospect that set the deadline

The situation

The platform ran on a well-built but organically grown cloud estate: dozens of AWS accounts, permissions granted as needed and never revoked, logging switched on in some places and not others. Engineers had admin access because they always had. Policies existed as a folder of templates someone had downloaded and never edited.

The prospect's security questionnaire had a hard date, and the Type II observation window meant controls had to be operating months before the auditor arrived. The CTO's constraint was blunt: the compliance programme could not slow down releases, and the engineering team would not accept a process that treated them as the problem.

What we did

  1. 01

    Gap assessment against the Trust Services Criteria

    Four weeks mapping the existing estate against SOC 2's security, availability, and confidentiality criteria. Each gap was ranked by audit weight and by engineering effort, so the plan closed the expensive gaps first and the cheap ones in bulk.

  2. 02

    Fix the cloud, not the paperwork

    Posture remediation across every account as reviewed pull requests — public endpoints closed, logging centralised, encryption enforced — with preventive guardrails written in Terraform so a new account was compliant on creation.

  3. 03

    Identity as the control plane

    Single sign-on across every tool, phishing-resistant MFA enforced, standing admin access replaced with time-boxed privileged access, and joiner-mover-leaver automated from the HR system. Access reviews became a report, not a meeting.

  4. 04

    Evidence collected by machines

    Integrations with the identity provider, cloud accounts, ticketing, and endpoint management pulled control evidence on a schedule into the compliance platform. When the observation window opened, evidence had already been accumulating for two months.

  5. 05

    Policies people could read, and an audit they were ready for

    Policies rewritten to describe what the company actually did, in plain language, and reviewed by the people they applied to. Control owners were briefed before fieldwork, and we sat alongside them for every auditor session.

I expected compliance to be a tax on the team. Instead the infrastructure got better and the auditors left early.

Chief Technology Officer, Series B payments platform

Start with what Security Compliance could do for you.

Tell us about your situation and we will walk you through it against this engagement — what carries over, what is different, and what to expect.