Ternary

Customer demand for SOC 2 led to time-consuming security questionnaires

From the beginning, Joshua Kwan, Co-Founder and Chief Technology Officer (CTO) at Ternary, designed the platform with compliance as a core priority. However, as an agile startup, the company’s rapid development pace meant that not all policies and procedures were formally documented. 

As the business started to accelerate, the Ternary team spent an increasing amount of time responding to security questionnaires, and more customers in the sales cycle began expecting SOC 2 attestation.

That led Joshua to explore what it would take to achieve SOC 2 compliance. Joshua had experience with a traditional SOC 2 audit at a different company, leading him to believe the process would be painful. 

The Ternary team explored several automation platforms, preferring a self-service option to a consultant. 

Joshua explained, “while we believed that our security practices were strong from the start, we knew that the process of auditing could still be arduous and would require further documentation. Therefore, we were looking for a platform that could help automate the process as much as possible.”

Ternary demystifies audit work and streamlines SOC 2 with Thoropass’ automations and expert guidance

Ternary found that Thoropass had the best of both worlds: an easy-to-use automation platform and hands-on support to answer questions and streamline the process.

Some of Joshua’s favorite features were Thoropass’ project management capabilities. With guidance from his Customer Success Manager (CSM), he assigned upcoming tasks to himself and others on his team, prompting reminders. That helped them collect evidence on a regular basis instead of spending hours scrambling before an audit.

Touching on this, Joshua explained, “I get alerted by Thoropass when I have to upload my network security report. I just log into the site and do it right then, and I’m done for the quarter.”

For Joshua, the most difficult SOC 2 requirement was determining how to do risk assessments. His CSM helped distill it into a fill-in-the-blank process.

“Pick who you use for your application security scanning, pick who you use for your network security scanning, pick how you do your access reviews. There was a module for everything. Thoropass gave us a really good framework,” stated Joshua.

Thoropass’ all-in-one audit experience also exceeded his expectations, with prompt and helpful communication from the auditors.

Decreased questionnaire response times and award-winning teamwork

With all of their prep work and prompt follow-through, the Ternary team completed their SOC 2 Type 1 evidence collection in under one month. And their final report was issued just two days after the draft. 

In addition to the time efficiencies the Ternary team saw with their Type 1 report, once the initial work for their Type 1 was completed, the additional remediation work for their Type 2 was minimal. With just a few hours of work a week, Ternary was able to receive their SOC 2 Type 2 report quickly to meet the growing demand. Now, they can increase new customer confidence by checking “yes” on security questionnaires–and move the sales process along more quickly.

In honor of their impressive teamwork, the Thoropass team gave Ternary the Trailblazer Award, which recognized their relentless focus on getting things done efficiently without compromising on security.

In response to winning the Trailblazer Award, Joshua stated: “we’re honored to be recognized. Our team put in the work to follow all the instructions from Thoropass, and I’m pleasantly surprised that it worked out in such a phenomenal way. We were able to go through all the steps super quickly and remain responsive. It was a win for everyone involved.”

Product

SOC 2

Industry

FinOps

Company size

11-50

Location

California