Customer Stories / Cigo Tracker

Cigo Tracker develops SOC 2 policies in just 10% of the time

Cigo Tracker was conceived to solve a problem familiar to every online shopper: Not knowing when their order is being delivered. Often, transport companies have little insight once their drivers leave the warehouse. Cigo Tracker makes last-mile logistics more efficient, reliable, and transparent with its delivery management software.

Cigo Tracker
Cigo Tracker

CHALLENGE

Starting the SOC 2 journey from scratch felt overwhelming and intimidating

After six years in business, Cigo Tracker sought to expand to enterprise companies but hit a snag: Larger customers required SOC 2 compliance.

Compliance was a new challenge for Cyrille Delavenne, CTO. He wore multiple hats on his small, growing team and prioritized revenue-generating activities. Compliance hadn’t been front and center–but he knew that had to change.

The reality is, if your platform gets taken over by hackers because you were too sloppy about security,

forget about your ROI on everything.

Cyrille Delavenne

CTO

Cigo Tracker

Cyrille researched auditors and compliance vendors online. He was looking for a supportive, guiding hand to help his team achieve SOC 2 certification at a reasonable price. At first, he had several negative experiences meeting with providers. According to Cyrille, “I just felt like it was going to be this extremely complicated thing working with people that only use ‘audit speak.’ It’s like a foreign language to me.” His perception changed when he found Thoropass.

I felt like the Thoropass team was more willing to answer and quickly help, versus the other vendors that I had spoken with

There was a bit more of a human touch. We’re also a B2B SaaS product, and I’d rather build my relationships on trust than just the product.

Cyrille Delavenne

Cigo Tracker

SOLUTION

Partnering with Thoropass streamlined policy development by 90%

In addition to the positive relationships, Cyrille chose Thoropass because of its all-in-one experience for audit preparation: Expert guidance, in-house auditors, and an easy-to-use platform to streamline the process.  

His favorite feature was Thoropass’s policy templates. Cyrille estimated a 90% time savings versus writing policies from scratch.

Having templates that have been approved by auditors in the past gave us a level of reassurance.

All we had to do was modify it a little bit to make it work with our use case.

Cyrille Delavenne

Cigo Tracker

THE PENTEST ADVANTAGE

Communicative penetration testers enabled swift resolutions

Cigo Tracker needed to conduct penetration testing on its web application in order to fulfill compliance requirements and improve its security posture. Cyrille was considering renewing with pen testers he had used in the past, but when he learned Thoropass had its own in-house pen testing team at a competitive rate, he decided to give them a try.

He was pleasantly surprised. Cyrille’s previous pen testers identified problems without telling him how to reproduce or fix them.

“Usually you waste a lot of time going back and forth because the person isn’t telling you how to execute the attack that they were doing,” explains Cyrille.

He not only told us what the vulnerabilities are, but he was also very communicative when it came to how to reproduce the vulnerabilities.

I was able to reproduce the attacks myself and fix the problems, and that saved so much time.

Cyrille Delavenne

Cigo Tracker

RESULTS

Achieving SOC 2 certification unlocks new and exciting enterprise opportunities

As part of their successful SOC 2 audit, the Cigo Tracker team resolved several major vulnerabilities and developed their security policies. Thoropass helped them save valuable time in the process. “I think 90% of time saved writing policies is an understatement,” says Cyrille. With SOC 2 certification, Cigo Tracker has unlocked enterprise-level business opportunities and built confidence in its security posture.

Now, Cyrille and the Cigo Tracker team can sleep soundly. ”I think we just sleep better at night knowing that we are now doing some critical things that we should have been doing from the start.”

LOOKING AHEAD

Cigo Tracker plans to use Thoropass’ continuous compliance services to keep its SOC 2 certification up to date. The company has adopted best practices such as two-factor authentication, background checks, managing access to resources, and yearly penetration tests. Thoropass made the process easy to understand and a lot less intimidating than they originally thought.

Cyrille’s advice to other startups? Get compliant early.

If you have five people in your organization, it might seem premature to do SOC 2 compliance, but I’d argue it’s the best time to do it.

Don’t wait until you have a team of 20+ people. I’d rather scale processes and enforce them immediately on five people, rather than have to align a larger organization.

Cyrille Delavenne

Cigo Tracker

Cigo Tracker

Find your comprehensive compliance partner in Thoropass

Talk with one of our experts to build your custom path to compliance and take advantage of Thoropass’s thoughtful automation, expert guidance, and security audit experience.

Talk to an Expert

Location

Canada