How Turtlemint built security-aligned compliance management with Sprinto

Turtlemint is a full-stack fintech solution for distributing insurance products across categories like health, life, and motor. The company provides onboarding, certification, transaction processing, marketing tools, and commission management for agents and a SaaS-based distribution solution to the regulated finance sector.

turtlemint hero image
0 exceptions In SOC 2 audits
1500+ employees and devices Monitored 24×7 on Sprinto
~6 month SOC 2 Type 2 observation period with auto-collected evidence
Sprinto white-logo
Before Sprinto
After Sprinto
Turtlemint wanted a SOC 2 report to build trust with existing clients and unblock new deals, and it wanted equal confidence that its own house was in order across every security asset.
Turtlemint passed both its SOC 2 Type 1 and SOC 2 Type 2 audits across 3 TSCs without exceptions, coming out with a clean SOC 2 report and continuous monitoring behind every control.
With over 1500 employees working out of offices and in the field, all with different levels of access to data, setting the right boundaries meant securing infrastructure and access guardrails manually, a tedious and time-intensive job at that scale.
Turtlemint now monitors 1500+ employees and devices 24×7 on Sprinto, with native integrations across its people systems, cloud services, and critical systems, and Sprinto’s integrated MDM enforcing encryption, screen lock, and antivirus.
SOC 2 was a new mandate, so Turtlemint needed expert guidance on the way forward and a way to cut the effort spent coordinating compliance tasks and audit evidence.
Turtlemint worked with Sprinto’s certified experts to define scope and a path to audit readiness, and the platform auto-collected evidence through the ~6-month Type 2 observation period.
“We wanted to get SOC 2 compliant to build trust in our space. But getting our house in order was equally important to us. We wanted confidence that we’re doing things right”


– Swapnil Gawas
VP of Engineering, Turtlemint

“We’ve not just gotten better at managing compliance but we’re also more proactive about it now. The best practices we’ve instilled, supported by Sprinto, have made data security an integral part of how we do things.”


– Swapnil Gawas
VP of Engineering, Turtlemint

Introduction

As a leader in the fintech and insurtech spaces, Turtlemint was keen on demonstrating its security posture both to existing clients and to unblock new deals, which placed a SOC 2 audit high on its list of priorities. The company runs a full-stack insurance distribution business covering onboarding, certification, transaction processing, marketing tools, and commission management for agents, alongside a SaaS-based distribution solution for the regulated finance sector.

Turtlemint’s need for compliance, however, went beyond getting a SOC 2 report. Its key requirement was a proven compliance automation and monitoring solution to maintain SOC 2 compliance across security assets while reinforcing data security best practices.

“We wanted to get SOC 2 compliant to build trust in our space. But getting our house in order was equally important to us. We wanted confidence that we’re doing things right,” remarks Swapnil Gawas, VP of Engineering at Turtlemint.

The Problem

That confidence had to hold across a large and distributed workforce. With over 1500 employees working out of offices and in the field, all with different levels of access to data, Swapnil and the Turtlemint team knew they needed to set the right boundaries. Securing infrastructure and ensuring proper access guardrails at that scale would be tedious and time-intensive work, especially if done manually.

For this reason, Turtlemint decided to adopt a platform-centric approach to compliance management to streamline the monitoring of people, processes, and technology while reducing the effort spent coordinating compliance tasks and audit evidence. With SOC 2 being a new mandate, Turtlemint sought a proven solution supported by experts who could provide guidance on the best way forward.

“It was important to us that the compliance partner we chose could speak our language and simplify compliance so we could understand it in our context. That’s why we went with Sprinto,” says Swapnil.

The Solution

Turtlemint worked with Sprinto’s certified experts to define the compliance scope and create a path to SOC 2 (3 TSCs) audit readiness, tailored to its security and operational needs. Turtlemint then connected its various people systems, cloud services, and critical systems through Sprinto’s native integrations, centralizing all security assets for efficient control implementation and automated tracking.

From there, Turtlemint addressed compliance gaps in MFA, data encryption, backups, and access controls, and classified code repositories, implemented vulnerability scanners, and set up branch monitoring to secure data and meet SOC 2 requirements.

Given the broad people scope, technical considerations, and complex data perimeter, effective risk assessment was essential for SOC 2 audit readiness. Turtlemint used Sprinto’s risk register and vendor risk assessment module to identify risks, assign impact and likelihood scores, complete vendor due diligence, and link risks to continuously monitored mitigation controls for ongoing risk management.

Turtlemint’s final challenge was implementing policies, training, and device management for its large team. Turtlemint defined employee scope, started from Sprinto’s pre-built templates and built out its own policies and training from there, then closed the loop by nudging policy acknowledgments and training completion through Sprinto.

With Sprinto’s integrated MDM solution, Turtlemint ensured device compliance and enforced best practices like encryption, screen lock, and antivirus. After adding access controls and completing disaster recovery exercises, Turtlemint was ready for audits.

Turtlemint began with the SOC 2 Type 1 audit, completing control implementation within a year and passing the audit without exceptions. Turtlemint moved to the SOC 2 Type 2 audit right after, which involved a ~6 month observation period for ensuring controls were continuously performing as expected, during which the platform auto-collected evidence for various SOC 2 criteria.

Sprinto’s context-rich, automated alerts were crucial in helping Turtlemint keep SOC 2 controls in the green: steadily escalating alerts reached the relevant stakeholders when controls were in danger of failure so they could be fixed proactively, which played a crucial role in keeping Turtlemint audit-ready throughout the observation period.

Much like the Type 1 audit, Turtlemint’s SOC 2 Type 2 audit went through without exceptions and the organization came out with a clean SOC 2 report. “We were able to centrally manage all the aspects of our SOC 2 program, with everything being a few clicks away. The visibility made a real difference in our preparedness,” says Swapnil.

Impact

Having achieved its SOC 2 audit goals, Turtlemint could also observe a major shift in how compliance was embedded and managed against its security aspirations. Compliance now had an underlying logic of data security, complete with a structure and a set of tools to manage goals without disrupting day-to-day processes.

Turtlemint runs that program on Sprinto, monitoring data security risks continuously, seeing what needs fixing, and acting on it confidently, with 1500+ employees and devices monitored 24×7.

Now, Turtlemint has its sights on ISO 27001 and is leveraging Sprinto’s Common Controls Framework (CCF) to build on SOC 2 and achieve ISO 27001 compliance at nearly half the effort. Turtlemint is also simultaneously pursuing a SOC 2 audit for its sister entity.

“We’ve not just gotten better at managing compliance but we’re also more proactive about it now. The best practices we’ve instilled, supported by Sprinto, have made data security an integral part of how we do things,” says Swapnil Gawas, VP of Engineering at Turtlemint.

Got questions? Talk to our experts!

AI-CTA-bg
AI-CTA-bg
turtlemint logo
Industry Type

Fintech / Insurtech

Employees

1500+

Regions

India

Funding

Modules used
Native cloud integrations Continuous Monitoring Risk Register Vendor Risk Assessment
Frameworks used
SOC 2 Type II