Customer Stories / Cigo Tracker
Cigo Tracker develops SOC 2 policies in just 10% of the time


CHALLENGE
Starting the SOC 2 journey from scratch felt overwhelming and intimidating
After six years in business, Cigo Tracker sought to expand to enterprise companies but hit a snag: Larger customers required SOC 2 compliance.
Compliance was a new challenge for Cyrille Delavenne, CTO. He wore multiple hats on his small, growing team and prioritized revenue-generating activities. Compliance hadn’t been front and center–but he knew that had to change.
The reality is, if your platform gets taken over by hackers because you were too sloppy about security,
forget about your ROI on everything.
Cyrille Delavenne
CTO
Cigo Tracker
Cyrille researched auditors and compliance vendors online. He was looking for a supportive, guiding hand to help his team achieve SOC 2 certification at a reasonable price. At first, he had several negative experiences meeting with providers. According to Cyrille, “I just felt like it was going to be this extremely complicated thing working with people that only use ‘audit speak.’ It’s like a foreign language to me.” His perception changed when he found Thoropass.
I felt like the Thoropass team was more willing to answer and quickly help, versus the other vendors that I had spoken with
There was a bit more of a human touch. We’re also a B2B SaaS product, and I’d rather build my relationships on trust than just the product.
Cyrille Delavenne
Cigo Tracker
SOLUTION
Partnering with Thoropass streamlined policy development by 90%
In addition to the positive relationships, Cyrille chose Thoropass because of its all-in-one experience for audit preparation: Expert guidance, in-house auditors, and an easy-to-use platform to streamline the process.
His favorite feature was Thoropass’s policy templates. Cyrille estimated a 90% time savings versus writing policies from scratch.
Having templates that have been approved by auditors in the past gave us a level of reassurance.
All we had to do was modify it a little bit to make it work with our use case.
Cyrille Delavenne
Cigo Tracker
THE PENTEST ADVANTAGE
Communicative penetration testers enabled swift resolutions
Cigo Tracker needed to conduct penetration testing on its web application in order to fulfill compliance requirements and improve its security posture. Cyrille was considering renewing with pen testers he had used in the past, but when he learned Thoropass had its own in-house pen testing team at a competitive rate, he decided to give them a try.
He was pleasantly surprised. Cyrille’s previous pen testers identified problems without telling him how to reproduce or fix them.
“Usually you waste a lot of time going back and forth because the person isn’t telling you how to execute the attack that they were doing,” explains Cyrille.
He not only told us what the vulnerabilities are, but he was also very communicative when it came to how to reproduce the vulnerabilities.
I was able to reproduce the attacks myself and fix the problems, and that saved so much time.
Cyrille Delavenne
Cigo Tracker
RESULTS
Achieving SOC 2 certification unlocks new and exciting enterprise opportunities
As part of their successful SOC 2 audit, the Cigo Tracker team resolved several major vulnerabilities and developed their security policies. Thoropass helped them save valuable time in the process. “I think 90% of time saved writing policies is an understatement,” says Cyrille. With SOC 2 certification, Cigo Tracker has unlocked enterprise-level business opportunities and built confidence in its security posture.
Now, Cyrille and the Cigo Tracker team can sleep soundly. ”I think we just sleep better at night knowing that we are now doing some critical things that we should have been doing from the start.”
LOOKING AHEAD
Cigo Tracker plans to use Thoropass’ continuous compliance services to keep its SOC 2 certification up to date. The company has adopted best practices such as two-factor authentication, background checks, managing access to resources, and yearly penetration tests. Thoropass made the process easy to understand and a lot less intimidating than they originally thought.
Cyrille’s advice to other startups? Get compliant early.
If you have five people in your organization, it might seem premature to do SOC 2 compliance, but I’d argue it’s the best time to do it.
Don’t wait until you have a team of 20+ people. I’d rather scale processes and enforce them immediately on five people, rather than have to align a larger organization.
Cyrille Delavenne
Cigo Tracker
Cigo Tracker
Featured
Product
Penetration Testing,
SOC 2,
Industry
Logistics
Company size
11-50
Location
Canada
Related Customer Stories

MedCall achieved effortless SOC 2 attestation and ongoing security excellence with a strategic partnership
SOC 2,

Harnessing mult-framework power: HalcyonFT achieves SOC 2 attestation and ISO in one-third of the time
ISO 27001,
SOC 2,