Brightwave passes SOC 2 Type II on the first attempt
1/1 SOC 2 attempts to pass
Challenge
Brightwave handles health data and needed SOC 2 Type II to close enterprise deals. They had no dedicated security team and a three-month audit deadline.
Approach
We mapped controls to the SOC 2 framework, identified gaps, and prioritized automating repeatable controls so a small team could sustain them.
Solution
We deployed:
- Zero-trust: mTLS, least-privilege, audit logging
- Code and dependency scanning in CI
- Automated compliance evidence collection
Results
1/1
attempts
12 tuần
to audit
0
critical findings
HIPAA
roadmap ready
“We passed SOC 2 Type II on the first attempt thanks to their security and DevOps work. Responsive, rigorous, and genuinely invested.”
Tech stack
AWSTerraformVaultOPASplunk
Start a similar project
Tell us about your challenge — we'll bring the team.