
– Norm Usenkanov
CTO, Kodif
– Norm Usenkanov
CTO, Kodif
Introduction
Founded in 2021, US-based Kodif is a low-code platform for scalable CX automations, letting brands roll out efficient, delightful self-serve experiences without leaning on an army of engineers. As an AI and ML-enabled platform, Kodif recognizes that its value is best realized by brands of a bigger size and scale. “AI engines perform better with lots of data. Typically, mid-sized and large companies sit on a mountain of customer data. And we knew early on these businesses are likely to benefit most from using the platform, in terms of efficiency gains” notes Norm Usenkanov, CTO at Kodif.
Serving that segment set the bar for how the platform needed to present itself. To prime themselves for mid-market and enterprise success, Kodif decided to buff up the platform by aligning it to security compliances.
The Problem
The pattern showed up early in Kodif’s pipeline. “Early signals confirmed that to land a conversation with a large company, we need to prove compliance,” claims Norm. “Big companies need assurances,” he adds. To satisfy this sales motion, Kodif decided to pursue SOC 2 and HIPAA compliances, with one segment making the HIPAA case especially clear. “We saw some interest from healthcare-related companies but these would only share information once we were HIPAA compliant and could lawfully sign a Business Associate Contract (BAC) with them,” notes Norm.
Having dealt with compliance in his last role, Norm knew firsthand how complicated things could get, which shaped the timing of the decision. “We wanted to get it over with – we were small and figured we could handle the load better now than later,” he remarks. That same experience shaped what Kodif looked for in a compliance partner, where expertise and responsiveness were the key criteria. “We wanted someone who could come in with both technical and human expertise,” he notes. When referred by a peer, Norm explored Sprinto. “Technically, Sprinto felt on par with others. But what we liked most was the assurance of one-on-one support,” he remembers. “With compliance, there’s a lot to do. That’s what’s problematic. And with limited time and resources, it can feel like a lot of work. We wanted someone to handhold us and take us through the process. We needed good support. Sprinto met that mark,” says Norm.
The Solution
Kodif integrated with Sprinto and got started with the SOC 2 Type 2 compliance program. Once deployed, Sprinto pulled control information from Kodif’s systems through its integrations to be mapped to SOC 2 checks. On Kodif’s part, Norm, along with a member from DevOps and engineering, pulled their weight to close the gaps Sprinto identified. “Sprinto called out deficiencies and we would move to resolve them – from encrypting databases to deploying dependabot in GitHub. We spent about an hour a week completing such tasks,” notes Norm.
Once SOC 2 implementation was completed, Kodif moved toward enforcing HIPAA controls. Because SOC 2 controls significantly overlap with HIPAA’s, the marginal effort on Kodif’s part was less than 20%. “With HIPAA, Sprinto really helped us understand the law and navigate its requirements,” says Norm.
Kodif completed Type 2 implementation in a month and went into observation for roughly 4 months, receiving its SOC 2 Type report 4 weeks after. Implementation of HIPAA controls was organized and completed along with SOC 2, and Kodif’s HIPAA audit was completed in 3 weeks following evidence collection. Kodif received its HIPAA certificate along with its SOC 2 report.
Impact
Since achieving compliance, Kodif is no longer on its heels trying to figure out how to respond to enterprises. “Armed with compliance reports, we feel more confident entering into conversations with large companies,” notes Norm. Putting advantage on their side, Kodif has since unblocked a deal with a healthcare prospect that required them to be HIPAA compliant for scoping and solutioning. Kodif’s sales and marketing teams have also gone on to adopt the SOC 2 report to demonstrate product maturity and generate interest and demand for the platform.
With Sprinto’s continuous monitoring operating in the background, Kodif works with the assurance of continuous compliance, one it extends to its prospects and customers. “When compliance becomes a part of the day-to-day, it becomes a part of the larger culture,” says Norm. “Sprinto ensures best practices. It’s always up to date and lets us know exactly what we need to do to remain above the 95% compliance mark. It’s a bi-monthly effort and requires no more than 30 minutes on our part,” he adds.
Got questions? Talk to our experts!



CX automation / AI software
Under 50
USA




