
HubEngage’s customers keep employee addresses, social security numbers and financial account information on the platform, and HubEngage needed to offer them assurance that the data was handled safely.
HubEngage completed ISO 27001 implementation in 15 hours and now holds ISO 27001, GDPR, HIPAA and SOC 2, so that assurance is certified against four standards.
A compliance consultant’s methods felt 15-20 years old, and getting compliant their way called for a dedicated CISO and a team HubEngage did not have.
A 2-week plan from HubEngage’s Sprinto CSM, connected AWS and GitHub environments and automated workflows ran the program without a dedicated CISO or a third party.
Manual methods slowed progress and pulled engineering’s attention away from product development, when what the team wanted was a proactive approach with little-to-no overhead.
3000-4000 checks now run automatically against a 95% compliance mark, with tiered alerts, and overseeing the program takes about an hour a week.
– Sunil Sarda
Head of Engineering, HubEngage
– Sunil Sarda
Head of Engineering, HubEngage
Introduction
HubEngage is an experience-focused employee engagement platform that helps organizations connect, communicate, and coordinate with their employees. Organizations and institutions across healthcare, manufacturing, entertainment, hospitality, and automotive use HubEngage to run their employee engagement programs.
That means sensitive employee data sits on the platform: addresses, social security numbers, and financial account information. To offer its customers assurance of safe data handling and strong SecOps practice, HubEngage set out to earn ISO 27001 certification.
The Problem
HubEngage first brought in a compliance consultant. Coordinating the program that way proved inefficient, and working through the processes felt tedious, long and unproductive.
Sunil Sarda, Head of Engineering at HubEngage, oversaw the compliance program, and found the consultant’s methods dated. “Their process is like what I’d seen and used 15-20 years ago. It was tedious then and now,” he said. “You need a dedicated CISO and team to get compliant their way.”
The manual approach was also slowing the certification down. “We needed a proactive approach to security and compliance, instead of a reactive one,” notes Sunil.
What the team wanted was a solution carrying little-to-no overhead, one that demanded less attention from engineering. “This way we stay focused on product development,” adds Sunil.
HubEngage researched how similar companies handled security compliance, and found Sprinto. “Sprinto emerged as an exceptional out-of-the-box solution that immediately convinced us with its compliance workflow automation capabilities,” says Sunil.
The Solution
HubEngage integrated with Sprinto and began the ISO 27001 implementation. “During onboarding, our Sprinto CSM laid out a clear 2-week plan. We were excited to get started,” remembers Sunil.
One of the first steps was connecting HubEngage’s AWS and GitHub environments. Isolating and classifying resources as production and non-production let the team enforce compliance protocols efficiently, and with Dependabot supporting the GitHub integration, Sprinto identified vulnerabilities across repositories and alerted the team to them. “By integrating these environments with Sprinto we could stay on top of security anomalies and get granular with our attention,” remarks Sunil.
With its cloud services and apps connected, HubEngage had a comprehensive view of security risks and controls mapped against the ISO 27001 standard, and automated workflows kept the program moving through timely, tiered alerts. “With Sprinto, I don’t need to add reminders to my calendar,” notes Sunil. “Sprinto alerts me to checks that pass, are due, or fail. Now, whether onboarding or offboarding employees or ensuring a solid disaster recovery plan, we have compliant workflows for all, managed through Sprinto.”
Built-in policy templates and documentation took the drafting and filing work off the team. “Thanks to version control, the platform maintains an updated record of all policies. I do not have to store and manage any document separately on a Drive,” remarks Sunil.
That single view is what made the additional frameworks inexpensive to add. “Sprinto gives a single-shot view of compliance. Controls that are common to all standards can be seen at once and this helps manage them better. There’s no need to involve a third party or a new resource to manage compliance,” says Sunil.
Impact
HubEngage completed its ISO 27001 implementation in 15 hours. “It was quite click-and-go!” says Sunil.
At audit time, the team added their auditor to Sprinto and shared compliance evidence over a common dashboard. “Everything the auditor needed was already on the dashboard,” remembers Sunil. Against the process he had been through before, the difference was in the preparation. “Manual audits take an entire day and require everyone to be in the office,” he notes. “With a platform like Sprinto, we just have to give details over a dashboard and that’s it.”
Layering GDPR, HIPAA and SOC 2 on top of ISO 27001 took roughly 10% more effort, because the controls those frameworks share were already in place and already being monitored. HubEngage now holds all four.
The certifications changed how the product is received. “The product gets a lot more respect. The customers also give us a lot more consideration now that we are compliant with standards like ISO,” notes Sunil.
For the team, moving past the manual methods of compliance was the bigger win. “We care about being an advanced company,” states Sunil.
Sprinto’s dashboard is now where HubEngage monitors and improves its compliance posture, at about an hour a week. “When you know everything is connected, and 3000-4000 checks are happening automatically, hitting that 95% compliance mark is easy,” he notes. “Sprinto sends [compliance] alerts that go out on a regular basis and are managed on the platform. It is easy to see where we are succeeding and lacking. I think it’s a proactive approach to security and compliance,” Sunil adds.
“In essence, Sprinto is a ChatGPT for a CISO – it is automated up to the extent that human effort is negligible. This leaves me with more time to focus on the product instead of running behind compliance and security matters,” says Sunil.
Got questions? Talk to our experts!



Employee engagement platform (HR / SaaS)
<50
USA






