
– Georgi Petrov
CEO, NitroPack
– Georgi Petrov
CEO, NitroPack
Introduction
NitroPack is the leading site speed and performance optimization solution used by digital businesses worldwide, an automatic SaaS product popular among startups and SMEs looking to improve website performance and conversion rates. As interest from mid-sized companies and large businesses grew, NitroPack needed to demonstrate compliance with leading security standards to serve them.
NitroPack has operated with security-first principles and followed GDPR practices from the start, but that practice was neither formalized nor validated by a third party, and that was proving to be an impediment. “Although we had security practices in place, we needed someone to help organize, review, and identify gaps in our practices and help us fix them,” recalls Georgi Petrov, CEO of NitroPack.
The Problem
To close that gap, NitroPack set out to undergo a SOC 2 Type 2 and ISO 27001 audit and considered hiring a local consultant or one of the Big 4s, but evaluating them was proving time-consuming and effort-heavy. “Some even suggested spending time in our office reviewing our infrastructure, which seemed unnecessary,” says Georgi.
With strict timelines for achieving SOC 2 Type 2 and ISO 27001 compliance, NitroPack preferred to work with a technology partner that had innate [compliance] expertise. “With Sprinto, we felt assured we’d be able to meet our timelines!” says Georgi.
The Solution
Evaluating compliance automation platforms, NitroPack found that Sprinto stood out for its organization and automation. Georgi remembers, “Sprinto felt organized enough to organize us. The platform and the implementation plan were clear and well structured,” and he adds, “Investigating Sprinto, we felt assured that it could integrate with our systems and automate everything. This way is more accurate and less time-consuming.”
Once NitroPack plugged in its cloud systems with Sprinto, it moved through SOC 2 and ISO 27001 program implementation, guided by Sprinto’s compliance experts. “We followed the plan to the T,” remarks Georgi. With Sprinto activated, NitroPack could detect noncompliance risks, misconfigurations, and security anomalies almost right away. “The system alerted us to the need to update some underlying infrastructure in Kubernetes. We realized that while it was production-ready, it was not compliance-ready,” he remarks.
NitroPack also caught vulnerabilities in its vendor management practices through Sprinto and remediated them in keeping with new security criteria. “Sprinto gave us a systematic way to quantify risks from vendors. We even parted ways with a vendor who did not meet the security criteria,” says Georgi.
Running automated checks across its cloud, NitroPack gained granular telemetry and tracked compliance with a high level of accuracy. “The most functional and valuable part of Sprinto is its continuous security and compliance checks,” says Georgi. “Every time there is a change, Sprinto alerts us and reminds us to check if security is intact. This is how security should be – continuous, not periodic. Sprinto assures us that everything is happening safely and securely.”
While tracking SOC 2 and ISO 27001 compliance, NitroPack also leveraged Sprinto to check readiness against GDPR and decided to refresh its GDPR practice to align better with its other security programs. “We value security and want to keep ourselves up to date,” notes Georgi. “The incremental effort to take on multiple compliances was next to none,” he adds.
Impact
NitroPack completed the implementation, observation, and audit of its SOC 2 Type 2 and ISO 27001 programs within 6 months. “The auditor dashboard played a major role. It gave our auditor organized data and this was helpful,” shared Georgi.
With the audit behind it, NitroPack has doubled down on its efforts to engage mid-market prospects, backed by a security practice that is now verified, streamlined, and stronger than before. “Managing security, especially with distributed teams across the world, can be challenging,” notes Georgi. “But automation monitors security and maintains compliance, making it easy.”
That automation is where Georgi places the greatest value: “Automation allows for continuous security checks, which is its single biggest value. Because Sprinto is responsive, alerts are prompt, delays are minimal, and security is maintained.” Using Sprinto, he can immediately grasp what needs to be done to secure systems and ensure compliance. “I get a bird’s eye view of what is working and what is not, and this saves me time because I get to focus on the important tasks,” says Georgi.
Got questions? Talk to our experts!



SaaS — site speed and performance optimization
11-50
Singapore





