Case Study: SoFi cuts mean time to remediation from 8 days to 10 minutes with Apiiro
Key results
The challenge
SoFi's application security team of 16 supported more than 2,000 developers across over 5,200 repositories, making manual review of every code change impossible. As a fintech balancing compliance requirements against development velocity, the team was spending hours on manual security design reviews and needed to reduce application risk without slowing developers down.
The solution
SoFi deployed Apiiro's ASPM platform to build a continuous inventory of its application technologies, components, APIs, open-source packages, secrets, and material code changes. Using Apiiro's policy engine, the team defined critical-risk criteria and triggered automated workflows—such as creating a security design review ticket—only when a risky material code change was detected.
“There's a lot of ASPMs out there. I don't think we have run across one that's doing code analysis the way Apiiro does and providing us the insights that Apiiro does.”
ZSZach SchulzeSr. Staff Application Security Engineer, SoFi
The results, in context
Apiiro reports SoFi reduced security design reviews from hours to 5–15 minutes and cut mean time to remediation from 8 days to 10 minutes by tying critical risks to their code owners. The time to identify, assess, and address new application risks fell from days to hours. These figures are quoted from Apiiro's SoFi case study and dated to that public source.