
– David Mason
Director of Security, Anaconda
– David Mason
Director of Security, Anaconda
Introduction
Anaconda is a unified AI platform built to advance AI with open source at scale, providing access to the foundational open-source Python packages used in modern AI, data science, and machine learning. With over 50 million users and 21 billion downloads, Anaconda is the gold standard for Python, data science and AI. Its products are a mix of open-source packages, distribution, and tooling to manage Python implementation, and its customers range from Fortune 100 companies and government agencies to small organizations, teams, and individuals who rely on Anaconda to source, secure, build and deploy AI with confidence.
For David Mason, Director of Security at Anaconda, the search for a compliance solution began with a mandate to increase the company’s compliance footprint. As a trusted platform serving 95% of Fortune 500 companies and processing over 21 billion downloads, Anaconda recognized that demonstrating security went well beyond internal controls: it was about maintaining the trust that millions of users place in the platform every day to deliver secure, verified open source packages for their AI initiatives. Securing attestation for a known framework would give Anaconda a strong baseline of controls across key security areas, moving the company past a risk-by-risk approach that often left gaps. It would also speed up sales cycles, reduce the burden on engineering, and provide customers with straightforward security assurance, without lengthy explanations of security practices.
The Problem
As Anaconda took on this charter, the security team found itself blocked in a key area: control implementation. “When we assessed our existing controls after performing a gap analysis, we found that a lot of these were either spottily applied or not at all. If there was a control for every time somebody was onboarded, it may or may not have been executed, and nobody was going back to check if the right processes were being followed. We didn’t have the maturity in our procedures to validate controls,” explains David Mason, Director of Security at Anaconda.
The compliance process in place also overlooked stakeholder communication and prioritization. “There was executive buy-in, but we hadn’t prioritized compliance at the same level,” shares David. “To fix control gaps, your stakeholders need to know just how blocked you are. That made us lean heavily into automation.”
Alongside that, Anaconda realized it may have set control expectations without ensuring full understanding of how to evidence them. “Everyone knows what to do; they just don’t know the right artifact to prove it,” says Amanda Parson, Compliance Program Manager at Anaconda. “We have a culture of high trust, high autonomy. You’re expected to manage and secure your processes with guidance from security teams and share artifacts if needed. Constantly spoon-feeding and following up would go against the grain of how we work.”
That pointed Anaconda toward automation as the way to hold the control environment together. “We were looking for a way to automate monitoring our control environment so that we didn’t have to poke around quite so much into everyone’s day-to-day because we just didn’t have the time. Sprinto was a good match for our use case,” says David.
The Solution
Anaconda wanted to start its journey to attestation with a relatively lightweight framework that would pave the way for stricter compliance standards in the future, and chose ISO 27001. On Sprinto, Anaconda got out-of-the-box compliance coverage with pre-mapped controls and automated checks, customizable to fit its needs.
Anaconda then connected its infrastructure to the relevant ISO controls through Sprinto’s cloud-native integrations, enabling the real-time control monitoring that was a key requirement. “The partnership from the Sprinto team was really important because, especially during platform implementation, the integrations had to match to have a high level of monitoring automation,” says David. “Sprinto was quite flexible and accommodated our integration requests.”
With monitoring wired up, Anaconda built out its risk programme on Sprinto’s risk register and used Sprinto’s customizable ISO policy templates as the base to write its own compliance documentation, tied to controls and risk scenarios. Anaconda then rolled those policies out directly for org-wide acknowledgment, paired with on-platform security training.
Sprinto’s expert-led support played a crucial role in getting Anaconda ISO-ready, helping align essential compliance and preferred security controls to Anaconda’s environment in a way that met both compliance and corporate security conditions. Change management was one area where Anaconda worked closely with Sprinto’s experts to define the right control conditions, ensuring zero gaps and a flexible control management system. “Sprinto, as opposed to some other partners in the space, has been very flexible from an implementation and account management perspective. It’s a true partnership where we solve problems together. That makes a big difference,” remarks David.
With ISO 27001 controls set up and automated testing in place, Anaconda gained a consolidated, real-time view of security assets, risks, policies, controls, and evidence, seeing exactly where it was sliding and scaling. Anaconda also cut manual compliance effort by routing context-rich alerts to designated control owners when controls were at risk, driving accountability across the organization. “The ideal situation to get to is real-time compliance. When everything’s hooked up on Sprinto, and if a control fails, you get an alert right away. You know exactly when you’re out of compliance and why. So that when we do go to the auditors, we know exactly where you stand,” says David.
Impact
Anaconda now runs compliance as a strategic, prioritized program. “We were able to land the compliance program last year in a minimal way and clearly demonstrate its value and the value of automated compliance,” says David.
That has changed how Anaconda’s customers buy. “We’ve seen a significant reduction in the complexity of our customers’ initial procurement of our software. Qualitatively, at least half of the volume of security questions is gone thanks to attestations. So far this year, I’ve only had to do six or eight questionnaires about our security. It was six or eight a month previously!” David explains.
Looking ahead, Anaconda used Sprinto’s compliance crosswalks to identify which other frameworks’ controls ISO 27001 already covered it for, making an informed decision about what to pursue next. “Earlier, we’d have to rely on multiple tools and spreadsheets to check if we could reuse controls and evidence across frameworks. With Sprinto, it’s seamless,” says David.
Got questions? Talk to our experts!



AI / Data Science Platform
USA



