How Fyle cut time to compliance from 6 months to 3 weeks with Sprinto

Founded in 2016, Delaware-based Fyle is an expense management software company on a mission to create the most user-friendly expense management experience on the market. Its AI-powered solution empowers employees to submit expenses instantaneously using apps they already use, enabling businesses to automate expense reporting and easily track corporate expenses.

fyle hero image
3 weeks To receive SOC 2 (Type 1) report
8X improvement In time-to-SOC2 readiness
60% readiness Automatically unlocked for other compliances
Sprinto white-logo
Before Sprinto
After Sprinto
Fyle wanted third-party validation of the data security it had always prioritized, because the enterprises and partners it met as it moved upmarket preferred SOC 2 compliant technology providers.
Fyle received its SOC 2 (Type 1) report within three weeks of starting with Sprinto, giving it the third-party validation it needed to work with larger enterprise organizations and partners.
Running SOC 2 readiness with a security consultant meant Fyle maintaining a massive checklist by hand and collecting evidence manually, which ate into hours of the team’s time, with no clear view of who needed to do what across the organization and no assurance that Fyle would still be compliant after 6 months.
Fyle now has its checklists and entities monitored continuously through Sprinto, with a dashboard that pinpoints who needs to do what across the organization.
Three months into the consultant engagement Fyle was still at gap analysis, and it had already committed timelines to customers and partners that a delay would put at risk.
Fyle achieved an 8X improvement in time-to-SOC 2 readiness and is over 60% audit ready for PCI DSS, saving months of CTO bandwidth and making new frameworks a matter of days.
“We had a massive checklist and ensuring that it was maintained on a regular basis was a humongous task in itself. We were burdened with manual evidence collection, eating into hours of our time and effort. But what seemed less than ideal was that there was no guarantee that Fyle would stay compliant after 6 months!”


– Siva Narayanan
Co-founder & CTO, Fyle

“What I love about Sprinto is that it presents information and evidence the way an auditor expects to see it. Getting our SOC 2 – Type 1 compliance certification gives us a competitive advantage to work with larger enterprise organizations and partners. It also helps us build trust with our existing customers by showcasing our investment to achieve and maintain the highest level of security and compliance.”


– Siva Narayanan
Co-founder & CTO, Fyle

Introduction

Since launching in the US in 2020, Fyle has significantly grown its customers and partner network. As IT expanded its operations and the company moved upmarket, Fyle increasingly came across enterprises and partners that preferred SOC 2 compliant technology providers.

That made the real ask for SOC 2 a commercial one, coming directly from customers and partners. “We realized that while data security has always been a top priority, getting 3rd party validation would position us better with large corporations and partners. Getting SOC 2 compliant seemed like the obvious next step for us,” adds Siva Narayanan, Co-founder & CTO at Fyle.

The Problem

Fyle first approached SOC 2 by partnering with a security consultant, and soon ran into a host of challenges. “We had a massive checklist and ensuring that it was maintained on a regular basis was a humongous task in itself. We were burdened with manual evidence collection, eating into hours of our time and effort. But what seemed less than ideal was that there was no guarantee that Fyle would stay compliant after 6 months!” explains Siva.

Fyle had already promised certain timelines to customers and partners, so delaying SOC 2 compliance would derail growth and cost the company thousands of dollars. Siva recalls, “The team was burdened with massive spreadsheets, and manual evidence collection, and spent hours of back and forth with the auditor. 3 months into the engagement, we were still lingering at gap analysis.”

The Solution

Siva and his colleagues at Fyle started looking for compliance automation tools and discovered Sprinto. What appealed most to Siva was Sprinto’s focus on technology and automation to run checklist verification, which addressed his biggest fear of key compliance checks getting missed and gave him the confidence to partner with Sprinto.

“Switching to Sprinto has been an absolute lifesaver! In the past, when we tried working with a security consultant, the process was suboptimal,” says Siva.

Championing their ethos of putting customer security first, Fyle started its SOC 2 (Type 1) compliance process with a 10-day 1:1 onboarding session. Working with Sprinto’s compliance experts through those sessions, Fyle set up Sprinto and got the entire Fyle team using it, then downloaded and deployed Dr. Sprinto, Sprinto’s inbuilt MDM tool.

From there, Fyle chose owners against each responsibility and checklist and completed information security training covering password management, best email practices, and how to avoid phishing scams.

With responsibilities assigned and the team trained, Fyle assessed its security gaps and risks, put the measures for SOC 2 in place, and accepted the policies essential for SOC 2 in Sprinto to reflect them. Fyle then picked an auditor from Sprinto’s pre-vetted network, and within three weeks Fyle received its SOC 2 (Type 1) report, with the evidence laid out where the auditor could work through it.

“What I love about Sprinto is that it presents information and evidence the way an auditor expects to see it. Getting our SOC 2 – Type 1 compliance certification gives us a competitive advantage to work with larger enterprise organizations and partners. It also helps us build trust with our existing customers by showcasing our investment to achieve and maintain the highest level of security and compliance,” adds Siva.

Impact

Fyle is currently undergoing its SOC 2 Type 2 process with Sprinto, and Siva and his colleagues are anticipating a lot of growth this year and are excited about the opportunities that lie ahead. Up next for Fyle is PCI DSS compliance, and because Fyle’s checklists and entities are automatically monitored in Sprinto, the company is already over 60% audit ready for PCI DSS.

That saves months of CTO bandwidth and gives Fyle a head start on its next compliance journey, with the ability to scale across frameworks in days.

“Moving to Sprinto was our most rewarding decision. The team at Sprinto helped us get SOC 2 compliant much ahead of time as compared to our expectations. The attention to detail in the platform is remarkable, making it easy and enjoyable to use,” says Siva. “The dashboard is great at pinpointing who needs to do what within the organization and proves to be effective in keeping us compliant,” he adds.

Got questions? Talk to our experts!

AI-CTA-bg
AI-CTA-bg
fyle logo
Industry Type

Expense Management Software

Employees

110 employees

Regions

USA

Modules used
Continuous Monitoring Dr. Sprinto (MDM) Policy Management Security Training
Frameworks used
SOC 2 Type I