How Sprinto helped Dassana launch a compliance program centered on visibility
Dassana is in the business of security observability. Focused on helping businesses make the most of their investment in various data security tools, their security data lake platform identifies missing tool coverage and provides centralized reporting on KPIs such as MTTR and SLAs to operationalize and optimize security programs. Large companies and enterprise businesses in sectors like retail, healthcare, and B2B SaaS use Dassana to drive visibility and fill vulnerability management chasms.

-

SOC 2
-

USA
-
3 sessions
Time to SOC 2 audit readiness using Sprinto
-
2 weeks
Time to complete audit post 3 months of SOC 2 observation
Ready to get
started?
Challenge
The increase in security misconfiguration incidents for cloud-hosted applications has led to a mounting need for cloud observability platforms. βEvery other week you hear about some breach. A poorly configured cloud resource or a vulnerability is often the culprit,β says Parth Shah, co-founder and head of product and engineering at Dassana. βWe decided to build a security data lake that solved for [system] visibility and drove efficiencies at scale.β
As soon as Dassanaβs product was market-ready, the team decided to bolster it with compliance reports and certifications.Β βThe moment we wanted to start working with customers, we realized the importance of demonstrating compliance β it was a key initiative,β notes Parth. βCompliance opens doors,β he adds.
In his previous role as founding engineer at RedLock, a cloud infrastructure compliance company later acquired by Palo Alto Networks, Parth focused on tracing paths to visibility. βWe had an API-first approach. Without it, it would be difficult to inspect systems, query them, and obtain data worth analyzing,β he notes. βWhen we discovered Sprinto, we found a similar approach at work,β Parth adds.
Having dealt with compliance in his previous role, Parth was wary of chasing down the traditional path again. He notes,
Traditional methods of compliance are rough. They are more expensive, time-consuming, and require more βpullβ than βpush.β You need to do the hard work of getting everyone to do their part.
Dassana chose Sprinto as its compliance automation partner due to its user-friendly design, affordability, and automated workflows. However, what appealed most was Sprintoβs continuous monitoring feature.Β βWe wanted a solution that wasnβt just a one-time fix,β notes Parth.
Compliance is a must-have β it keeps the lights on. To move fast, continuous compliance is essential.
Solution
Dassana plugged into Sprinto to launch a SOC 2 compliance program.
After integrating their tech stack, the team only needed to perform attribution work. Parth recalls, βBecause our team was small, assigning roles, responsibilities, and priorities were relatively easy.β
The implementation of the program was expedited by the fact that Dassana was already following compliant operational practices. Says Parth, βWe were well-versed in how to set up cloud infrastructure for security. This way we could do 4 weeksβ worth of work in just 1 session. Then we only had to work on streamlining policies.β
Dassana began setting up automated compliance workflows and alerts β a one-time configuration.Β βOnce activated, I received weekly alerts on issues, anomalies, and similar matters. Having these touchpoints was delightful,β Parth recounts.
Once set up, rest assured, Sprintoβs automation works.
Because Sprintoβs system is push-based, rather than pull-based, Parth felt assured that compliance tasks will be completed without him having to intervene constantly.Β βInstead of approaching people and asking for updates, which is the most manual part of compliance, a push-based system makes my life easy. I donβt have to take any action. The platform sends me status updates and triggers workflows for remediation on its own.β
The speed at which we were able to get to visibility, that instant gratification, nothing comes close to that.
To meet PEN testing requirements, Dassana picked a vendor from Sprintoβs partner network. βSprinto pointed us to vetted vendors that matched our pricing needs. Sprinto just became a one-stop shop for compliance,β notes Parth.
Results
Dassana was SOC 2 audit ready in 2 weeks.
To complete their SOC 2 audit, they added an auditor from Sprintoβs partner network to the audit dashboard. βIt was a smooth experience,β recounts Parth. βThe auditor got access to Sprinto, they did their own [evidence] verification within the platform and 2 follow-ups later we were done.β
Throughout the process, you are constantly saving time. Because so much is automated, and done by tech, so thereβs no scope for error or need for human verification.
Delighting in the consolidated nature of the platform, Parth underscores how Sprinto helps bridge trust between a business and its auditor. βWhen both you and your auditor know that the tech works, that there are no blind spots, it makes everyoneβs life easy.β
Parth also rejoices in the fact that there is now a heightened awareness around compliance across the company. βBy doing the training and given the fact that everyone is connected to Sprinto and can see compliance playing out org-wide, people have started to understand the why β why we are doing this, and how they play a role.β
With Sprinto owning and driving compliance visibility, Parth is confident in the organizationβs ability to continue moving fast and innovating. βIf a new GitHub repository is added, Sprintoβs protection rules kick in immediately. Thatβs the power of the platform. Compliance no longer gets in the way of our growth. We are growing in a compliant manner.β
Sprinto ensures overall visibility, making sure everyone is on top of compliance.

