Skip to main content

#426 Building Trust: Starting Our SOC-2 Journey

Friday Ship #426 | January 17th, 2025

lock on laptop

This week we evaluated tools in prep for a SOC-2 audit.

In 2023 and 2024, we concentrated on migrating from Digital Ocean to Google Cloud , making our infrastructure more robust (All in on PostgresTwin databases, half the hassle) and improving our deployment process. As a result, we have a stable and reliable platform and our developers release new features whenever they want.

We have always built our infrastructure as safe as possible, following all best practices, but in the past years we have seen how customers request more and more for SaaS companies to be compliant with a framework such as ISO 27001, SOC-2 or others. Also, security is being established as the main focus for companies lately, as tools have access to more and more critical information.

In 2025, our focus is on additional security and compliance, to make sure our customers feel safe when using our platform and trust us with their data.

The Compliance Ocean

There are a lot of compliance frameworks out there: ISO 27001, ISO 27017, HIPAA, GDPR, HITRUST, SOC-2 and many more.

Parabol serves all types of companies around the world, but our main fishing ground is the United States of America. That is why, out of the many available compliance frameworks, we chose to start with SOC-2.

SOC-2 is a very known framework provided by the AICPA & CIMA, that verifies you comply with many security controls. Those controls are audited once a year and each company can decide between:

  • One-shot audit that produces a SOC-2 type I report. It shows that you have everything in place to be compliant, both on the technical side and on the documentation and procedures. But it doesn’t verify if you are truly respecting those procedures.
  • Three month audit that produces a SOC-2 type II report. The auditor verifies that the company not only is technically safe but that it respects the procedures.

Then, the certified company can share that report with their customers and they can safely trust everything is done correctly to ensure the safety of their data. As we want our customers to feel as safe as possible, we are going to pursue a SOC-2 type II report, with a three month audit.

Getting SOC-2 certified isn’t easy or fast, as it will require us to document all our processes, pass a number of technical checks to verify the security of our infrastructure, including a penetration test, and also implement management procedures related with on and off boarding of personnel and workstation checks. This can be a challenge for a startup of our size, but we are happy to face that challenge for the sake of our customers and to improve us as a company.

We are just starting the process, evaluating the available tools in the market to help us with it, and we are really excited to see what’s ahead of us.

Metrics

January 17 Metrics

We are still seeing the trailing effects of the slow holiday season in our monthly numbers, but good see our weekly meetings bouncing back as people return to their regular routines.

This week we…

โ€ฆopened our T3 Company Retro to gather reflections.

โ€ฆadded a new Retro Template – โ€œI like, I wish, I wonder.โ€

Next week we’ll

โ€ฆcontinue our progress on migrating to TipTap so we can add images and GIFs!

Rafael Romero Carmona

Rafael Romero Carmona

Rafa is a very curious and proactive person, who likes to learn about everything. He has been working as Cloud Architect and DevOps engineer for the last 7 years. He is really passionate about system architecture, AWS, GCP, Kubernetes, distributed data and processes. Rafa lives in Tenerife (Spain) an island in the middle of the Atlantic, but he spent the last 20 years between Huelva, Sevilla and Paris. He loves going to the forest, mountains and beaches with his dog and wife in his spare time.

All your agile meetings in one place

Run efficient meetings, get your team talking, and save time. Parabol is free for up to 2 teams.