Cardo AI

Expansion to the US market required SOC 2

Cardo AI first built a commercial footprint in Europe through acquisition of customers in Italy, the UK, the Netherlands and Luxembourg. At the end of 2022, Rubin Haxhiymeri, Revenue Operations Lead at Cardo AI, was tasked to determine a security compliance solution to be rolled out as the company kept hitting roadblocks in terms of further expansion when it came to security questionnaires, especially because US customers had different security requirements.

After internal analysis and evaluation, we saw SOC 2 as the most attainable, simple, and fastest route towards meeting the requirements of our US customers.” — Rubin Haxhiymeri, Revenue Operations Lead, Cardo AI

Rubin began a search for a vendor to help Cardo AI achieve SOC 2 certification. He was looking for a compliance partner to help with the process of putting all the controls in place, conducting gap analyses, and collecting evidence in a single repository.

For Rubin’s small team, which was stretched across multiple initiatives, cost and usability were also critical factors. After evaluating several vendors, they selected Thoropass.

Expert customer support and a transparent evidence collection process helped Cardo AI achieve SOC 2 certification in half the time

From the very beginning, Thoropass’ support and guidance helped to streamline the process. In addition to providing resources like how-to guides, training modules, and policy templates, Cardo AI’s dedicated Customer Success Manager (CSM) was available to answer questions.

“Our onboarding experience was fantastic. Our CSM did a terrific job being there for us, making sure that we understood the task at hand, and helping us meet our timeline.”  — Rubin Haxhiymeri

After onboarding, the Cardo AI team began the evidence collection process for the required SOC 2 controls. Thoropass’ platform made it easy to understand the controls, track progress, and stay aligned.

“The Thoropass platform facilitated a lot of the work by making it visible and transparent. Evidence was collected into one single space, serving as a single source of truth. This made it easy to distribute the work across the organization.” — Rubin Haxhiymeri

As a result, Cardo AI passed its SOC 2 Type 1 audit in six months and Type 2 audit in eight months—half the time Rubin expected. 

SOC 2 helped Cardo AI increase US customers by 400% and close a $15M Series A round

With their SOC 2 certification, Cardo AI was able to increase their US presence by 400% in just one year. 

“Thoropass had an immediate commercial impact for us. Whenever you bring up the fact that you’re SOC 2 certified, it erases a lot of doubts in the eyes of customers.” — Rubin Haxhiymeri

Its improved security posture impressed not only customers, but investors as well.

Cardo AI plans to use Thoropass’ ongoing compliance services to keep its SOC 2 certification up to date, ensuring both the highest level of security and customer confidence.

Choose a compliance vendor who will be a true partner

Rubin began the SOC 2 process as a team of one, later increasing to a team of two. No matter the size, he recommends choosing a vendor like Thoropass that provides customized support every step of the way.

Product

SOC 2

Industry

Fintech

Company size

50-200

Location

United States