Customer Stories / Elpha Secure
Elpha Secure achieves SOC 2 renewal with a 90% time savings


CHALLENGE
Unclear documentation leads to time-consuming, redundant work
Paul Schottland, CTO at Elpha Secure, is no stranger to compliance. With decades of experience engineering large-scale enterprise and security software products, he’s been through many certification processes: SOC 2, ISO 19001, ISO 21001, NIST Compliance Framework, FedRAMP, and more. And he knows how time-consuming compliance can be.
It feels a lot easier to go to the base camp of Everest than it does to demonstrate certification in some of these realms.
Paul Schottland
CTO
Elpha Secure
Paul had worked with many compliance platforms and consultants before joining Elpha Secure. Some of the most frustrating parts of the certification process were vague communication and documentation. Auditors producing ambiguous feedback or vague control requirements meant engineers spent redundant time researching how a control or requirement was previously met.
But when Paul was introduced to Thoropass, he was surprised at how efficient the process could be—and the functionality of the recurrent mapping for recertification.
SOLUTION
Partnering with Thoropass streamlines the SOC 2 renewal process
Elpha Secure had already achieved its initial SOC 2 certification using Thoropass when Paul joined as CTO. However, when Paul led the process for SOC 2 renewal, he was immediately impressed by the simplicity of Thoropass’s platform.
“It was very easy to follow the layout and the model in Thoropass, and the workflow attached to it. Having that trackability and traceability through the system is super helpful.” —Paul Schottland
The detailed documentation of the previous year’s audit and evidence made the SOC 2 renewal much more efficient.
The ability to read any of the controls or requirements and see a concrete example of last year’s, makes things go so much faster.
Paul Schottland
Elpha Secure
Paul also values that Thoropass maps requirements from one certification to another. Many of the controls are transferable, so when Elpha Secure was pursuing HIPAA compliance after SOC 2, his team didn’t need to do repeat work.
“If I’m interested in SOC 2 compliance, I’m probably going to be involved with GDPR or HIPAA compliance someday. Thoropass identifies those overlaps, so I can lean on the work we’ve done on certification X to save time with certification Y.” —Paul Schottland
Thoropass combines its easy-to-use software with a team of in-house compliance experts to guide customers through the certification process. Paul valued the straightforward communication from the Thoropass team, who asked pointed questions and provided actionable feedback.
I’ve had a fantastic time with the Thoropass team.
The team is very direct, to the point, and clear, and that is really important in compliance.
Paul Schottland
Elpha Secure
RESULTS
Achieving SOC 2 certification, 90% faster than average
Elpha Secure completed its SOC 2 renewal in just 10% of the time Paul expected.
I’m talking about taking hundreds of hours of multiple engineers’ time and reducing it into tens of hours.
Thoropass makes it much, much more efficient.
Paul Schottland
Elpha Secure
Recently, Elpha Secure completed its self-attestation for HIPAA. Next, Paul plans to tackle GDPR.
Achieving and maintaining its SOC 2 and other certifications enables Elpha Secure to acquire new customers and do business in the insurance industry.
“I would say that it is very difficult to do business without being able to demonstrate SOC 2 compliance, given that you’re handling security information and security data.” —Paul Schottland
Elpha Secure
Elpha Secure
Featured
Product
HIPAA,
SOC 2,
Industry
Insurtech
Company size
11-50
Location
New York
Related Customer Stories

Revamping social services: ThriveLink achieves compliance and efficiency with Axipro and Thoropass
SOC 2,

How TalkHealth.ai achieved HIPAA certification with Thoropass and Muscatek's expertise
HIPAA,