Case study · B2B SaaS

Getting a SaaS platform audit-ready

From stalled enterprise deals to a SOC 2 audit entered with controls already operating and evidence collected automatically.

Audit-ready
Controls operating
0
Secrets in code
CI-gated
Vuln scanning

The challenge

Enterprise deals kept stalling at the security questionnaire. The product was sound but access was ad hoc, secrets sat in environment files, and there was no audit trail an assessor would accept.

Our approach

We ran an architecture and application review first, then fixed what it found: centralised identity with role-based access, secrets moved into a managed vault with rotation, audit logging on privileged actions, and dependency and container scanning wired into CI so regressions fail the build. Policies and evidence were assembled alongside the engineering work rather than written up afterwards.

The outcome

The team went into their SOC 2 audit with controls already operating and evidence collected automatically. We prepared the architecture and the evidence trail — the certification itself comes from their accredited third-party auditor, not from us.

Why this approach

Compliance projects fail when they are treated as documentation exercises. An auditor can tell the difference between a policy written last month and a control that has been operating for one — so the engineering came first: centralised identity, vaulted secrets, audit logging, scanning wired into CI. The evidence was collected automatically as a by-product of systems doing their job, which is exactly the posture an assessor hopes to find.

The order of work also mattered commercially. The controls that unblock enterprise security questionnaires went in first, so sales conversations improved months before the audit itself.

If you are facing something similar

If deals keep stalling at the security questionnaire, the questionnaire is telling you where to start. The SOC 2 readiness checklist shows what an audit will actually ask of your architecture, and our security and compliance service covers the remediation engineering — the certification itself always comes from an accredited third-party auditor.

This engagement is anonymised and the figures shown are representative of the outcomes this work targets, not audited results from a named client. Client-approved write-ups replace these as they are cleared for publication.

Facing something similar?

Tell us where it hurts — we'll tell you honestly whether we can help.