How Inflectra Saves 10 Hours a Month Maintaining Compliance Across its AWS Environments with Secureframe

Inflectra offers its customers a trusted and seamless platform for creating and releasing their most important technology products on time and with the highest quality. The Inflectra suite includes capabilities for managing requirements, test cases, resources, risks and automating all aspects of the entire software development lifecycle. Established in 2006 in the United States, Inflectra's influence reaches across the globe, with distributed teams and a robust partner network that serves more than 5,000 customers in sectors including health, finance, government, manufacturing and IT.

“Secureframe is a trusted partner who will value your journey and efforts to become more compliant. Their team of experts help improve your security awareness and fast-track your road to compliance.”

Simon Bor, CTO, Inflectra

Highlights

highlights

Challenges

  • Looking to get SOC 2 compliant to meet customer expectations.
  • Time-consuming, manual processes for reviewing AWS settings. 
  • Wanted to have better evidence of their strong security posture. 
  • Felt overwhelmed by SOC 2’s extensive guidance. 
  • Needed help understanding what success looked like for SOC 2. 
  • Searching for external expertise to help them streamline the process to achieve and maintain SOC 2.
highlights

Solutions

Secureframe provided Inflectra with:

  • Ability to confidently achieve SOC 2 compliance with a collaborative team and automated platform. 
  • Robust AWS integration that consolidated evidence collection across seven regions. 
  • Responsive and knowledgeable customer support team with a significant amount of audit experience. 
  • Recommendations for pen testers and auditors helped build a network of trusted third parties.
highlights

Results

  • Completed SOC 2 Type 1 fast to showcase their strong security posture. 
  • Saved 10 hours a month monitoring their AWS environment. 
  • Able to move deals forward that required SOC 2. 
  • Opened new business opportunities. 
  • Gained the confidence to easily provide evidence and present it to auditors to meet the requirements.

Challenges

Inflectra needed compliance automation and expertise to efficiently collect AWS evidence.

Inflectra is a market leader in the software test management, test automation, application lifecycle management, and enterprise portfolio management space. Its methodology-agnostic software tools are used in regulated industries where portfolio management, requirements traceability, release planning, resource management, document workflow, baselining, and enterprise risk analysis are required.

As an organization that provides services for regulated enterprise businesses, Inflectra wanted a way to better demonstrate its strong security posture. They knew that obtaining SOC 2 compliance would help meet customer requirements while providing external validation of their strong focus on security.

quote

“We knew we had what it takes to get our SOC 2 but we needed help taking the proper steps to get it done,” says Simon Bor, CTO of Inflectra. 

Inflectra initially began their SOC 2 journey on their own but quickly became overwhelmed with the extensive pillars and rules associated with SOC 2 guidance. That’s when Bor started to search for products and services that could provide expertise to help him understand what he needed to prioritize for a successful SOC 2 audit.

quote

“It was difficult to understand our priorities for SOC 2 and where to focus our time. We didn’t know what we didn’t know.”

Bor and his team knew they needed a platform that provided automation to save them time collecting compliance evidence across their AWS environments and internal systems.

quote

“We had processes set up for reviewing our AWS environments but the lack of automation made the process very time-consuming and performing these reviews manually made it easy for things to fall through the cracks.”

More importantly, they needed to work with a vendor they could trust. They wanted a vendor that would act as a partner to educate them on compliance best practices and guide them through the audit process.

Solutions

Secureframe’s automated platform streamlined AWS monitoring across seven regions.

After evaluating his options, Bor realized an automated compliance platform was the most cost-effective solution that still provided the level of support they were looking for. 

quote

“We had two options: either engage an audit firm that would cost $50,000+ or work with a vendor like Secureframe to help us on our journey to streamline the compliance process.”

Bor and his team engaged in a short trial with Secureframe to put the platform and the team to the test. During the trial, Bor worked closely with Secureframe’s customer success team and found them to be both responsive and knowledgeable. The team helped him understand why controls were failing, where the data did not satisfy SOC 2 requirements, and which documents to upload, without feeling like he was just being pushed through the motions. 

quote

“Your experts helped us understand what we needed to do and where to stop based on the scope of our audit. We had access to people with a significant amount of audit experience that helped provide advice as we worked towards achieving SOC 2 compliance.”

The Secureframe team delivered a standout level of compliance and audit expertise. Bor knew this was the level of collaboration he was looking for to aid his organization in building a strong compliance program. 

The benefits of the Secureframe platform also stood out as Bor realized how he could consolidate a lot of the work he and his team were doing manually. The task that consumed most of their time was monitoring and reviewing their seven AWS regions. By connecting each AWS region to the Secureframe platform, they were able to monitor and review every region at once and eliminate the need to do each task seven different times in AWS.  

quote

“We have seven AWS regions. Being able to consolidate our AWS environments into one platform, particularly across regions, made it easier to identify what is right and what is wrong based on the compliance requirements.”

Bor also liked how easy Secureframe’s in-platform security training was to manage. He could easily onboard and segment his team inside the platform to ensure each person was completing their ongoing training as well as other compliance tasks, including policy acceptance. 

Inflectra and Secureframe quickly built a strong relationship. The trust in the relationship extended to Secureframe’s network of third-party partners. Bor knew he could trust the pen testers and auditors recommended by Secureframe while also managing the costs associated with these partners.

quote

“Our level of trust with Secureframe extended to third-party services and also helped us manage our costs.”

Results

Inflectra saved 10 hours a month monitoring its AWS environments to maintain SOC 2 compliance.

Working with Secureframe gave Inflectra the ability to streamline compliance tasks with added confidence as they went into their SOC 2 Type 1 audit. The Secureframe team provided expert guidance around SOC 2 best practices so Bor and his team knew how to evidence items and present them to auditors in an easy fashion.

quote

“Secureframe gave us the expertise in knowing what compliance looks like and confidence in best practices to maintain a strong security posture.”

Inflectra achieved their SOC 2 Type 1 audit which has improved their sales cycle and moved deals forwarded that required SOC 2. Having their SOC 2 has also opened new opportunities for Inflectra. 

quote

“At Inflectra, we recognize that Secureframe plays a significant role in maintaining the highest standards of security and regulatory compliance across our operations. It is often the final piece that gives our customers peace of mind and confidence in the quality of our software solutions.”

Secureframe’s automation, training, and AWS monitoring saved Bor’s team 10 hours a month so they could spend more time focusing on supporting the business’s growth. 

Ultimately, Inflectra built their confidence to get SOC 2 fast and showcase their strong security compliance posture to their customers.