
– Bhargava M N N
Engineering Lead, Zipy
– Bhargava M N N
Engineering Lead, Zipy
Introduction
Zipy builds a unified observability platform that scans production systems in depth, tracing infrastructure, code, and system logs to help engineering teams resolve issues faster. Given the sensitivity of the data it handles, the company has practiced rigorous security from Day 1.
Yet strong internal practices only go so far without external validation. “We practice security in all the ways software is expected to. But it is one thing to say you are following good practices, and another to actually have proof,” notes Bhargava M N N, Engineering Lead at Zipy. As customer conversations increasingly turned toward third-party verification, the team recognized it was time to formalize its security posture through SOC 2 compliance.
The Problem
Customer demand made the case clear. “At some point, our customers started asking that we get auditors to review and verify our policies and practices. Especially for SOC2 – that was primary, especially in North America,” Bhargava adds. The team also saw a strategic advantage: SOC 2’s comprehensive scope meant other frameworks would be easier to pursue afterward.
Organizing the program internally, however, proved difficult. “We looked at what we needed to do and across which aspects of the business. We figured out the controls and implemented a few of them, but managing them with the right set of information and updating them periodically were lacking. This is where Sprinto became a need,” remarks Bhargava.
Controls existed, but without a central system to track, update, and evidence them, the program lacked the structure required to move toward an audit with confidence.
The Solution
On a peer’s recommendation, Bhargava chose Sprinto. The platform scoped out the entire program, timelines, and ownership in detail, giving the team a precise view of what needed to happen, by when, and by whom. “Honestly, we did not feel the need to look at anyone else. We were sure we will have a smooth ride with Sprinto,” Bhargava says.
Zipy integrated with Sprinto to operationalize a SOC 2 Type 1 compliance program first. Bhargava was joined by members from senior leadership, the security team, DevOps, and engineering to collect and map controls to the framework, including policies. “Because Sprinto showed us a clear path we knew exactly what to look into, the gaps to fill, and controls to regulate. It was very straightforward,” he adds.
Bhargava spent between four and six hours a week implementing the platform, organizing SOC 2 controls, enforcing measures, rolling out security training, and getting the dashboard up and running. “Thereafter, the platform told us what needs to be done – whether it was regarding onboarding, code repository, or infrastructure changes. It was simply a matter of responding promptly to Sprinto’s alerts. Tracking progress was easy.”
“The Sprinto dashboard clearly showed how compliant we were. Seeing that was a moment of great validation!” Bhargava says.
Impact
Zipy completed SOC 2 Type 1 implementation in 16 weeks after resolving migration efforts at their end and moved to a point-in-time audit immediately after, receiving the Type 1 report four weeks later. The team then entered the SOC 2 Type 2 observation period for three months and completed that audit at the end of it. Across both reviews, there were zero instances of non-compliance.
The commercial impact was immediate. “Even before we had the Type 1 report, we started seeing the interest go up as soon as we started saying we are undergoing SOC2 audit. Compliance clearly builds confidence in the business and the platform,” Bhargava notes.
Beyond sales conversations, compliance reshaped how the entire company operates. “From the way we set up our infrastructure to workflows related to onboarding and offboarding of employees – the way we operate is now fundamentally more streamlined. And the entire organization sees and appreciates this,” explains Bhargava. “Everyone knows that if something breaks there is a process in place to fix it in a way that ensures security and compliance. We have clear steps for everything. And we started seeing this change during the monitoring period itself,” he continues.
“Where Sprinto added the most value was in building our confidence around the way we do security,” notes Bhargava. “Going into compliance, we knew what we needed to do. But Sprinto ensured it was smooth sailing. Everything was defined and organized – the platform and the people moved us forward without hassle,” he adds. “Sprinto is our go-to person for compliance. Anytime anything new happens – new roles are added or infra – we default to compliance. How new things impact compliance is our default way of thinking now,” Bhargava says.
Got questions? Talk to our experts!



Observability / Developer Tools
11-50
North America, India




