Case Study: Phyllo earns SOC 2 Type 2 within six months of starting with Sprinto
Key results
The challenge
Phyllo builds a universal API for collecting and normalizing creator data, providing infrastructure for influencer-marketing and creator-economy apps. As a data interface, it regularly faced customer questions about the conditions and security of data exchange. Phyllo decided to undergo a SOC 2 audit and chose a compliance-automation tool over a tedious manual approach.
The solution
Phyllo integrated Sprinto to organize and manage controls against SOC 2 Trust Service Criteria. The team spent the first few weeks configuring systems to meet baseline criteria, using Sprinto's automated policy management and integrations to bridge functions across the organization.
“We did 4-5 demos with various compliance automation providers. In the end, Sprinto emerged as the best choice for its evident efficiency and support.”
MMMasroor P MohamedCompliance and Governance Lead, Phyllo
The results, in context
Phyllo completed a SOC 2 Type 1 audit first and received its SOC 2 Type 2 report within six months of starting the process, using Sprinto's auditor dashboard to run the audit. Following the attestation, Phyllo reports increased customer confidence in its platform's security.