How Kodif reached enterprise readiness through compliance with Sprinto

Founded in 2021, US-based Kodif is a low-code platform for scalable CX automations. Applied, the platform allows brands to roll out efficient, delightful self-serve experiences without leaning on an army of engineers.

kodif hero image
<20% effort Marginal effort to layer on compliances
1 hour /week Time spent on compliance tasks
100% improvement In overall enterprise readiness
Sprinto white-logo
Before Sprinto
After Sprinto
Mid-market and enterprise prospects would not open conversations without proof of security compliance.
Armed with compliance reports, Kodif enters conversations with large companies confidently, and its sales and marketing teams use the SOC 2 report to demonstrate product maturity and generate demand.
Healthcare prospects would only share information once Kodif was HIPAA compliant and could lawfully sign a Business Associate Contract (BAC).
Kodif unblocked a deal with a healthcare prospect that required HIPAA compliance for scoping and solutioning, receiving its HIPAA certificate along with its SOC 2 report.
With limited time and resources, the sheer volume of compliance work felt like a lot to handle, and Norm knew firsthand how complicated it could get.
Compliance tasks took about an hour a week during implementation, and ongoing upkeep is a bi-monthly effort of no more than 30 minutes.
“Early signals confirmed that to land a conversation with a large company, we need to prove compliance,”


– Norm Usenkanov
CTO, Kodif

“Armed with compliance reports, we feel more confident entering into conversations with large companies,”


– Norm Usenkanov
CTO, Kodif

Introduction

Founded in 2021, US-based Kodif is a low-code platform for scalable CX automations, letting brands roll out efficient, delightful self-serve experiences without leaning on an army of engineers. As an AI and ML-enabled platform, Kodif recognizes that its value is best realized by brands of a bigger size and scale. “AI engines perform better with lots of data. Typically, mid-sized and large companies sit on a mountain of customer data. And we knew early on these businesses are likely to benefit most from using the platform, in terms of efficiency gains” notes Norm Usenkanov, CTO at Kodif.

Serving that segment set the bar for how the platform needed to present itself. To prime themselves for mid-market and enterprise success, Kodif decided to buff up the platform by aligning it to security compliances.

The Problem

The pattern showed up early in Kodif’s pipeline. “Early signals confirmed that to land a conversation with a large company, we need to prove compliance,” claims Norm. “Big companies need assurances,” he adds. To satisfy this sales motion, Kodif decided to pursue SOC 2 and HIPAA compliances, with one segment making the HIPAA case especially clear. “We saw some interest from healthcare-related companies but these would only share information once we were HIPAA compliant and could lawfully sign a Business Associate Contract (BAC) with them,” notes Norm.

Having dealt with compliance in his last role, Norm knew firsthand how complicated things could get, which shaped the timing of the decision. “We wanted to get it over with – we were small and figured we could handle the load better now than later,” he remarks. That same experience shaped what Kodif looked for in a compliance partner, where expertise and responsiveness were the key criteria. “We wanted someone who could come in with both technical and human expertise,” he notes. When referred by a peer, Norm explored Sprinto. “Technically, Sprinto felt on par with others. But what we liked most was the assurance of one-on-one support,” he remembers. “With compliance, there’s a lot to do. That’s what’s problematic. And with limited time and resources, it can feel like a lot of work. We wanted someone to handhold us and take us through the process. We needed good support. Sprinto met that mark,” says Norm.

The Solution

Kodif integrated with Sprinto and got started with the SOC 2 Type 2 compliance program. Once deployed, Sprinto pulled control information from Kodif’s systems through its integrations to be mapped to SOC 2 checks. On Kodif’s part, Norm, along with a member from DevOps and engineering, pulled their weight to close the gaps Sprinto identified. “Sprinto called out deficiencies and we would move to resolve them – from encrypting databases to deploying dependabot in GitHub. We spent about an hour a week completing such tasks,” notes Norm.

Once SOC 2 implementation was completed, Kodif moved toward enforcing HIPAA controls. Because SOC 2 controls significantly overlap with HIPAA’s, the marginal effort on Kodif’s part was less than 20%. “With HIPAA, Sprinto really helped us understand the law and navigate its requirements,” says Norm.

Kodif completed Type 2 implementation in a month and went into observation for roughly 4 months, receiving its SOC 2 Type report 4 weeks after. Implementation of HIPAA controls was organized and completed along with SOC 2, and Kodif’s HIPAA audit was completed in 3 weeks following evidence collection. Kodif received its HIPAA certificate along with its SOC 2 report.

Impact

Since achieving compliance, Kodif is no longer on its heels trying to figure out how to respond to enterprises. “Armed with compliance reports, we feel more confident entering into conversations with large companies,” notes Norm. Putting advantage on their side, Kodif has since unblocked a deal with a healthcare prospect that required them to be HIPAA compliant for scoping and solutioning. Kodif’s sales and marketing teams have also gone on to adopt the SOC 2 report to demonstrate product maturity and generate interest and demand for the platform.

With Sprinto’s continuous monitoring operating in the background, Kodif works with the assurance of continuous compliance, one it extends to its prospects and customers. “When compliance becomes a part of the day-to-day, it becomes a part of the larger culture,” says Norm. “Sprinto ensures best practices. It’s always up to date and lets us know exactly what we need to do to remain above the 95% compliance mark. It’s a bi-monthly effort and requires no more than 30 minutes on our part,” he adds.

Got questions? Talk to our experts!

AI-CTA-bg
AI-CTA-bg
kodif logo
Industry Type

CX automation / AI software

Employees

Under 50

Regions

USA

Modules used
Continuous Monitoring Integrations Control Mapping Compliance Support
Frameworks used
SOC 2 Type II
HIPAA