
– Gourav Kumar
Director of Infosec, Happay
– Gourav Kumar
Director of Infosec, Happay
Introduction
Happay was already compliant with PCI-DSS and ISO 27001 standards when SOC 2 moved onto its agenda. The push came from the market: enterprise buyers in regions where SOC 2 is expected had begun treating a SOC 2 report as the baseline for opening a deal, which put direct commercial value on getting one. “Enterprises have a lot of faith in SOC controls,” notes Gourav Kumar, Director of Infosec at Happay.
To collect evidence against those requirements, Happay made a deliberate choice to lean on technology for the work. The harder part of the job was the coordination cost of proving controls across a large, fast-growing organization, and that is where Happay wanted the leverage.
The Problem
“Gathering compliance evidence in a company with over 450 employees is already challenging. Getting everyone to participate at the same time, with the same proficiency, is even more difficult,” notes Gourav. That coordination load was what drew Happay to compliance automation, with streamlining evidence gathering as the immediate goal.
Having worked on other security standards with consultants, Happay knew what it wanted this time: compliance that ran as a continuous process, responsive to requirements as they came up and able to keep pace with the company’s growth. “We needed a robust system that could respond to requirements as they came up, without disrupting the business,” notes Gourav.
That ambition turned a SOC 2 program into something larger than closing coordination and evidence gaps. It became an opportunity for Happay to get ahead of compliance altogether. “As an infosec leader, having a system that drives compliance, grows with the business, and helps meet reporting requirements is useful. If only to ensure nothing disrupts the business or derails compliance,” says Gourav. Happay placed its hopes on Sprinto to achieve both goals.
The Solution
Happay started by enabling the SOC 2 Type 2 audit readiness program on Sprinto. With its cloud stack tightly integrated with the platform, Happay moved a large part of the control implementation and monitoring activities onto Sprinto.
For the non-technical aspects of SOC 2, Gourav leaned on the PeopleOps function to drive compliance. “In the very first meeting, we scoped out all people-related activities and got the HR team onboarded. People, after all, have the biggest impact on compliance outcomes,” notes Gourav.
Orienting the organization towards SOC 2 also meant new policies. Happay expedited that work using Sprinto’s built-in policy templates and policy acknowledgment module, building its organizational policies and security training program out from those templates. “It was easy to publish and update policies in a single place, instead of creating multiple policy folders and sharing them with everyone over emails,” remarks Gourav. “Sprinto is an easy 8.5/10 in terms of usability and presence. It is familiar and interactive to the point that you can make a mind map easily and move forward with confidence,” he adds.
On the technical side, Happay used Sprinto’s built-in security tools to double down on its controls. Gourav notes that these embedded features were especially useful where they integrated with Sprinto’s SL scan, which gave deeper visibility into code bugs and vulnerabilities alongside Happay’s own efforts.
Continuous compliance monitoring and automated alerts proved the most useful levers of all. By tracking compliance drift automatically, Sprinto raised alerts to the right roles within the organization and triggered follow-ups that drove timely remediation, which kept the compliance function clear of administrative overhead. “If I post a device status reporting requirement today, I can immediately see who the requirement is sent to, who has completed it, and who is facing problems. The dashboard provides immediate visibility,” notes Gourav. He adds, “Technical aspects of compliance are easy. It’s the collaboration with people that is stressful. Initiating policies, granting access, training employees, reviewing policy changes, and ensuring everyone acknowledge the changes can be a lot of mundane work. Sprinto gives me the ability to launch and manage all of these tasks from one place, with just a few clicks.”
With SOC 2 controls in place, Happay moved on to GDPR. The technical groundwork was already covered by the SOC 2 implementation, so the remaining effort sat with the legal components, and Sprinto connected Happay with legal experts specializing in DPA as well as an EU representative. Happay then implemented the measures that uphold GDPR compliance and updated its policies to reflect them, which is what carried it from SOC 2 groundwork to GDPR compliance.
Impact
Happay reached SOC 2 Type 2 audit readiness in about 5 weeks and completed the audit following 4 months of observation, and it became GDPR compliant within the same period. Armed with the SOC 2 Type 2 audit report, Happay has successfully catalyzed sales and closed multiple enterprise deals.
Beyond the uptick in sales and renewals, Gourav has the lean and streamlined compliance practice he set out to build, supported by Sprinto’s technology and experts. “A large portion of security compliance involves operations and administrative work. Sprinto adds the most value by automating this process end-to-end,” notes Gourav. “The team behind Sprinto is equally commendable. They problem-solved with us every step of the way, going over and above some days. That gave me a lot of faith,” he adds.
Common control mapping now gives Happay an instant read on its readiness for other security standards, which is what makes each new framework cheap to take on. “Because you can see it, it is easy to act on it,” remarks Gourav.
“My job was to turn compliance from a project into a function that exists at all steps of Happay. Sprinto has helped to realize this,” says Gourav.
Got questions? Talk to our experts!



Expense & spend management software (fintech SaaS)
450+
India




