How Shipsy enforced security practices org-wide with Sprinto

Shipsy is an India-based logistics SaaS company that empowers organizations handling trade and logistics with an AI-enabled mobility management platform for data-driven decision-making, process visibility, and operational efficiency. Shipsy is a preferred partner for the logistics and supply chain arm of leading hyper-local businesses, courier services, manufacturing giants, and trade companies across the globe.

shipsy hero image
3 months Time to SOC2 Type 1 readiness
2 months Time to SOC2 Type 2 readiness
33% effort Marginal effort when layering on frameworks
Sprinto white-logo
Before Sprinto
After Sprinto
Shipsy wanted certifications that would evidence its security practices to Fortune 500s and publicly traded companies, which meant pursuing SOC 2, ISO 27001, and GDPR in sequence.
Shipsy reached SOC2 Type 1 readiness in 3 months and SOC2 Type 2 readiness in 2 months, completed the ISO 27001 implementation within a week, and closed out GDPR with ROPA as the only additional activity.
Shipsy could not run SOC 2 on spreadsheet-driven tracking across AWS, its HRMS, and other software at a growing company with hundreds of employees, and the cost of that complexity was significant.
Shipsy replaced spreadsheet-driven tracking with Sprinto’s integrations across AWS, its HRMS, and other software, so two people spent a few minutes each week closing the gaps the platform flagged.
Shipsy had no single place to review its compliance status, so surfacing gaps in its security posture and working the tasks that resolve them would have drawn heavy bandwidth from the team.
Shipsy now reviews its compliance status on Sprinto’s Compliance Dashboard, with continuous monitoring surfacing instances of non-compliance and prompting the tasks that resolve them.
“Stringent compliances like SOC2 cannot be accomplished over excels”


– Himanshu Gupta
Co-founder and CTO, Shipsy

“Sprinto added the most value through automation. The platform connects seamlessly with various applications and pulls the right data to determine compliance. Automation ensures we only need to step when the platform alerts us to an instance of non-compliance,”


– Himanshu Gupta
Co-founder and CTO, Shipsy

Introduction

Shipsy turns large streams of data into shipping solutions for supply chain functions across sectors. “Our platform relies on a lot of data and produces insights that impact every aspect of a logistics operation”, notes Himanshu Gupta, Co-founder and CTO at Shipsy. “Given its nature, it is only right on our part to give our customers the assurance that we are built solid and practice good security hygiene,” he adds.

The Problem

“Having good systems in place is one thing. Having certifications that prove it builds trust. Especially when you are dealing with Fortune 500s and publicly traded companies,” notes Himanshu. “To this end, we decided to pursue SOC2, ISO27001, and GDPR.”

Himanshu chose to operationalize those three frameworks on a platform that could support compliance management and improve business KPIs in a way a consultant could not. “Stringent compliances like SOC2 cannot be accomplished over excels”, Himanshu notes. “Especially when you are a growing company with hundreds of employees. The cost of complexity is significant,” he adds.

Himanshu’s shortlist came down to three requirements: a solution that could clear the path to SOC 2 compliance and the frameworks that would follow it, carry much of the heavy lifting without demanding much bandwidth from the team, and give Shipsy visibility into its security posture and the gaps within it. After evaluating multiple compliance automation platforms, Shipsy zeroed in on Sprinto. “What moved the needle was the assurance of agility – we were convinced Sprinto could accommodate our unique needs and help us meet our goals,” says Himanshu.

The Solution

Shipsy integrated with Sprinto to implement a SOC 2 program first. A comprehensive scoping and risk assessment exercise underscored gaps in systems and processes, and from there the team moved quickly to map controls to the SOC2 framework and deploy checks, automated and monitored, to track compliance status. “I liked how easy it was to integrate Sprinto with AWS, our HRMS, and other software. In a matter of clicks, data begins to flow into Sprinto,” says Himanshu. One representative from Shipsy’s InfraOps team and one from the PeopleOps team oversaw the implementation across hundreds of employees. “Between them, we spent a few minutes every week to fill the gaps the platform pointed out,” remarks Himanshu. Shipsy reached SOC2 Type 1 readiness in 3 months and SOC2 Type 2 readiness in 2 months.

With SOC 2 in place, Himanshu and his team pushed toward ISO27001. Cross-framework mapping carried most of the work over. “Because Sprinto already had controls mapped to SOC2, setting us up for ISO27001 was a matter of adding a few additional checks and policies. We completed the entire implementation within a week!” says Himanshu, with roughly 1 month of marginal effort to get ISO27001 in place after SOC2.

GDPR followed the same pattern. Shipsy obtained legal counsel through Sprinto to set up and verify various GDPR policies, including a GDPR-compliant privacy policy, a data processing agreement (DPA), and standard contractual clauses (SCC), on top of technical controls that were already live. “Completing ROPA was the only additional activity we needed to do. Technical controls were already mapped and monitored within Sprinto,” remarks Himanshu. That brought GDPR home in under 1 month of marginal effort after ISO27001, putting the effort of layering each additional framework onto the existing program at roughly 33%.

Running SOC2, ISO27001, and GDPR through one modular program kept every milestone in a single place. “With Sprinto, we did not have to go out of our way to organize these compliances. It was a one-stop experience!” says Himanshu.

Impact

Shipsy now runs SOC2, ISO27001, and GDPR-compliant operations off a single program, with cross-framework mapping, automation, and guided implementation holding the complexity down. “Sprinto added the most value through automation. The platform connects seamlessly with various applications and pulls the right data to determine compliance. Automation ensures we only need to step when the platform alerts us to an instance of non-compliance,” Himanshu adds.

Alongside the three frameworks, Shipsy also improved various process SOPs. “Going through the compliance journey opens your eyes to how things ‘should’ be done,” notes Himanshu. “Employee onboarding and offboarding, for example. We now have a well-defined, compliant process in place. Standard operating principles really help trim down complexities,” he adds.

Since implementation, Shipsy actively relies on Sprinto to keep a check on compliances and enforce policies org-wide. “A member from PeopleOps and InfraOps teams regularly checks the Sprinto dashboard to review our compliance status. They complete tasks that the platform prompts and make sure we are staying within boundaries of compliance,” says Himanshu.

Got questions? Talk to our experts!

AI-CTA-bg
AI-CTA-bg
shipsy logo
Industry Type

Logistics SaaS

Employees

Regions

Asia

Funding

Modules used
Continuous Monitoring Risk Assessment Policy Management Integrations
Frameworks used
SOC 2 Type II
ISO 27001
GDPR